%% You should probably cite draft-ietf-acme-authority-token-jwtclaimcon instead of this I-D. @techreport{wendt-acme-authority-token-jwtclaimcon-03, number = {draft-wendt-acme-authority-token-jwtclaimcon-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-wendt-acme-authority-token-jwtclaimcon/03/}, author = {Chris Wendt and David Hancock}, title = {{JWTClaimConstraints profile of ACME Authority Token}}, pagetotal = 21, year = 2025, month = jul, day = 7, abstract = {This document defines an authority token profile for handling the validation of JWTClaimConstraints and EnhancedJWTClaimConstraints. This profile follows the model established in Authority Token for the validation of TNAuthList but is specifically tailored for the JWTClaimConstraints certificate extensions. The profile enables validation and challenge processes necessary to support certificates containing both TNAuthList and JWTClaimConstraints, particularly in the context of Secure Telephone Identity (STI).}, }