Expect-CT Extension for HTTP
RFC 9163, “Expect-CT Extension for HTTP”, is an Experimental document published in June 2022 by E. Stark. The canonical text is published by the RFC Editor.
Abstract
This document defines a new HTTP header field named "Expect-CT", which allows web host operators to instruct user agents (UAs) to expect valid Signed Certificate Timestamps (SCTs) to be served on connections to these hosts. Expect-CT allows web host operators to discover misconfigurations in their Certificate Transparency (CT) deployments. Further, web host operators can use Expect-CT to ensure that if a UA that supports Expect-CT accepts a misissued certificate, that certificate will be discoverable in Certificate Transparency logs.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 9163 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9161 Operational Aspects of Proxy ARP/ND in Ethernet Virtual Private Networks
- RFC 9166 A YANG Data Model for Internet Group Management Protocol and Multicast Listener Discovery Snooping
- RFC 9168 Path Computation Element Communication Protocol Extension for Flow Specification
- RFC 9171 Bundle Protocol Version 7
- RFC 9172 Bundle Protocol Security
- RFC 9153 Drone Remote Identification Protocol Requirements and Terminology
- RFC 9173 Default Security Contexts for Bundle Protocol Security
- RFC 9152 Secure Object Delivery Protocol Server Interfaces: NSA's Profile for Delivery of Certificates, Certificate Revocation Lists , and Symmetric Keys to Clients