Enrollment over Secure Transport
RFC 7030, “Enrollment over Secure Transport”, is a Proposed Standard document published in October 2013 by M. Pritikin, P. Yee, D. Harkins. It has since been updated by RFC 8951, RFC 8996, RFC 9908. The canonical text is published by the RFC Editor.
Abstract
This document profiles certificate enrollment for clients using Certificate Management over CMS (CMC) messages over a secure transport. This profile, called Enrollment over Secure Transport (EST), describes a simple, yet functional, certificate management protocol targeting Public Key Infrastructure (PKI) clients that need to acquire client certificates and associated Certification Authority (CA) certificates. It also supports client-generated public/private key pairs as well as key pairs generated by the CA.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7030 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7029 Extensible Authentication Protocol Mutual Cryptographic Binding
- RFC 7031 DHCPv6 Failover Requirements
- RFC 7028 Multicast Mobility Routing Optimizations for Proxy Mobile IPv6
- RFC 7032 LDP Downstream-on-Demand in Seamless MPLS
- RFC 7027 Elliptic Curve Cryptography Brainpool Curves for Transport Layer Security
- RFC 7033 WebFinger
- RFC 7026 Retiring TLVs from the Associated Channel Header of the MPLS Generic Associated Channel
- RFC 7034 HTTP Header Field X-Frame-Options