%% You should probably cite draft-truskovsky-lamps-pq-hybrid-x509-02 instead of this revision. @techreport{truskovsky-lamps-pq-hybrid-x509-01, number = {draft-truskovsky-lamps-pq-hybrid-x509-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-truskovsky-lamps-pq-hybrid-x509/01/}, author = {Alexander Truskovsky and Daniel Van Geest and Scott Fluhrer and Panos Kampanakis and Mike Ounsworth and Serge Mister}, title = {{Multiple Public-Key Algorithm X.509 Certificates}}, pagetotal = 24, year = 2018, month = aug, day = 29, abstract = {This document describes a method of embedding alternative sets of cryptographic materials into X.509v3 digital certificates, X.509v2 Certificate Revocation Lists (CRLs), and PKCS \#10 Certificate Signing Requests (CSRs). The embedded alternative cryptographic materials allow a Public Key Infrastructure (PKI) to use multiple cryptographic algorithms in a single object, and allow it to transition to the new cryptographic algorithms while maintaining backwards compatibility with systems using the existing algorithms. Three X.509 extensions and three PKCS \#10 attributes are defined, and the signing and verification procedures for the alternative cryptographic material contained in the extensions and attributes are detailed.}, }