RFC 9118 · PROPOSED STANDARD · 2021

Enhanced JSON Web Token Claim Constraints for Secure Telephone Identity Revisited Certificates

Overview

RFC 9118, “Enhanced JSON Web Token Claim Constraints for Secure Telephone Identity Revisited Certificates”, is a Proposed Standard document published in August 2021 by R. Housley. It updates RFC 8226. The canonical text is published by the RFC Editor.

Abstract

RFC 8226 specifies the use of certificates for Secure Telephone Identity Credentials; these certificates are often called "Secure Telephone Identity Revisited (STIR) Certificates". RFC 8226 provides a certificate extension to constrain the JSON Web Token (JWT) claims that can be included in the Personal Assertion Token (PASSporT), as defined in RFC 8225. If the PASSporT signer includes a JWT claim outside the constraint boundaries, then the PASSporT recipient will reject the entire PASSporT. This document updates RFC 8226; it provides all of the capabilities available in the original certificate extension as well as an additional way to constrain the allowable JWT claims. The enhanced extension can also provide a list of claims that are not allowed to be included in the PASSporT.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9118 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 8226
Other RFCs from 2021

Who Is Online

In total there are 34 users online: 0 registered, 29 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 354