The NSA Certificate Extension
RFC 7169, “The NSA Certificate Extension”, is an Informational document published in April 2014 by S. Turner. The canonical text is published by the RFC Editor.
Abstract
This document defines the NSA (No Secrecy Afforded) certificate extension appropriate for use in certain PKIX (X.509 Pubic Key Certificates) digital certificates. Historically, clients and servers strived to maintain the privacy of their keys; however, the secrecy of their private keys cannot always be maintained. In certain circumstances, a client or a server might feel that they will be compelled in the future to share their keys with a third party. Some clients and servers also have been compelled to share their keys and wish to indicate to relying parties upon certificate renewal that their keys have in fact been shared with a third party.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 7169 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7168 The Hyper Text Coffee Pot Control Protocol for Tea Efflux Appliances
- RFC 7170 Tunnel Extensible Authentication Protocol Version 1
- RFC 7171 PT-EAP: Posture Transport Protocol for Extensible Authentication Protocol Tunnel Methods
- RFC 7167 A Framework for Point-to-Multipoint MPLS in Transport Networks
- RFC 7172 Transparent Interconnection of Lots of Links : Fine-Grained Labeling
- RFC 7166 Supporting Authentication Trailer for OSPFv3
- RFC 7173 Transparent Interconnection of Lots of Links Transport Using Pseudowires
- RFC 7165 Use Cases and Requirements for JSON Object Signing and Encryption