Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile
RFC 5280, “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile”, is a Proposed Standard document published in May 2008 by D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, W. Polk. It obsoletes RFC 3280, RFC 4325, RFC 4630. It has since been updated by RFC 6818, RFC 8398, RFC 8399, RFC 9549, RFC 9598, RFC 9608, RFC 9618, RFC 9925. The canonical text is published by the RFC Editor.
Abstract
This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5280 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5279 A Uniform Resource Name Namespace for the 3rd Generation Partnership Project
- RFC 5281 Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0
- RFC 5278 IANA Registration of Enumservices for Voice and Video Messaging
- RFC 5282 Using Authenticated Encryption Algorithms with the Encrypted Payload of the Internet Key Exchange version 2 Protocol
- RFC 5277 NETCONF Event Notifications
- RFC 5283 LDP Extension for Inter-Area Label Switched Paths
- RFC 5276 Using the Server-Based Certificate Validation Protocol to Convey Long-Term Evidence Records
- RFC 5284 User-Defined Errors for RSVP