Host Identity Protocol Certificates
RFC 6253

Document Type RFC - Experimental (May 2011; No errata)
Obsoleted by RFC 8002
Updates RFC 5201
Last updated 2015-10-14
Replaces draft-varjonen-hip-cert
Stream IETF
Formats plain text pdf html bibtex
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state RFC 6253 (Experimental)
Consensus Boilerplate Unknown
Telechat date
Responsible AD Ralph Droms
IESG note Gonzalo Camarillo ( is the document shepherd.
Send notices to (None)
Internet Engineering Task Force (IETF)                           T. Heer
Request for Comments: 6253                COMSYS, RWTH Aachen University
Updates: 5201                                                S. Varjonen
Category: Experimental     Helsinki Institute for Information Technology
ISSN: 2070-1721                                                 May 2011

                  Host Identity Protocol Certificates


   The Certificate (CERT) parameter is a container for digital
   certificates.  It is used for carrying these certificates in Host
   Identity Protocol (HIP) control packets.  This document specifies the
   CERT parameter and the error signaling in case of a failed
   verification.  Additionally, this document specifies the
   representations of Host Identity Tags in X.509 version 3 (v3) and
   Simple Public Key Infrastructure (SPKI) certificates.

   The concrete use of certificates, including how certificates are
   obtained, requested, and which actions are taken upon successful or
   failed verification, is specific to the scenario in which the
   certificates are used.  Hence, the definition of these scenario-
   specific aspects is left to the documents that use the CERT

   This document updates RFC 5201.

1.  Introduction

   Digital certificates bind pieces of information to a public key by
   means of a digital signature and thus enable the holder of a private
   key to generate cryptographically verifiable statements.  The Host
   Identity Protocol (HIP) [RFC5201] defines a new cryptographic
   namespace based on asymmetric cryptography.  The identity of each
   host is derived from a public key, allowing hosts to digitally sign
   data and issue certificates with their private key.  This document
   specifies the CERT parameter, which is used to transmit digital
   certificates in HIP.  It fills the placeholder specified in
   Section 5.2 of [RFC5201] and thus updates [RFC5201].

1.1.  Requirements Language

   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "OPTIONAL" in this document are to be interpreted as described in
   RFC 2119 [RFC2119].

