Internet X.509 Public Key Infrastructure Operational Protocols: Certificate Store Access via HTTP
RFC 4387, “Internet X.509 Public Key Infrastructure Operational Protocols: Certificate Store Access via HTTP”, is a Proposed Standard document published in February 2006 by P. Gutmann. It has since been updated by RFC 8553. The canonical text is published by the RFC Editor.
Abstract
The protocol conventions described in this document satisfy some of the operational requirements of the Internet Public Key Infrastructure (PKI). This document specifies the conventions for using the Hypertext Transfer Protocol (HTTP/HTTPS) as an interface mechanism to obtain certificates and certificate revocation lists (CRLs) from PKI repositories. Additional mechanisms addressing PKIX operational requirements are specified in separate documents. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4387 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4386 Internet X.509 Public Key Infrastructure Repository Locator Service
- RFC 4388 Dynamic Host Configuration Protocol Leasequery
- RFC 4385 Pseudowire Emulation Edge-to-Edge Control Word for Use over an MPLS PSN
- RFC 4389 Neighbor Discovery Proxies
- RFC 4384 BGP Communities for Data Collection
- RFC 4390 Dynamic Host Configuration Protocol over InfiniBand
- RFC 4383 The Use of Timed Efficient Stream Loss-Tolerant Authentication in the Secure Real-time Transport Protocol
- RFC 4391 Transmission of IP over InfiniBand