@misc{rfc10007, series = {Request for Comments}, number = 10007, howpublished = {RFC 10007}, publisher = {RFC Editor}, doi = {10.17487/RFC10007}, url = {https://www.rfc-editor.org/info/rfc10007}, author = {}, title = {{Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) Validation}}, pagetotal = 6, year = 2026, month = jun, abstract = {RFC 5280 defines the profile of X.509 certificates and Certificate Revocation Lists (CRLs) for use in the Internet. Section 4.2.1.3 of RFC 5280 requires CRL issuer certificates to contain the keyUsage extension with the cRLSign bit asserted. However, the CRL validation algorithm specified in Section 6.3 of RFC 5280 does not explicitly include a corresponding check for the presence of the keyUsage certificate extension. This document updates RFC 5280 to require that check.}, }