Skip to main content

attributeSigning extendedKeyUsage value
draft-patterson-pkix-attribute-signing-eku-00

Document Type Expired Internet-Draft (individual)
Expired & archived
Author Patrick Patterson
Last updated 2011-03-28
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document specifies a value for the extendedKeyUsage X.509 extension that may be used to create a certificate that would be used to sign attribute assertions. This allows the differentiation of certificates used to identify a particular server (which would have a serverAuth EKU), from the certificate used by that server to sign attribute assertions, and would easily allow a policy to be developed for issuance of such a certificate to an identity provider.

Authors

Patrick Patterson

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)