Certificate Management Protocol Updates
RFC 9480, “Certificate Management Protocol Updates”, is a Proposed Standard document published in November 2023 by H. Brockhaus, D. von Oheimb, J. Gray. It updates RFC 4210, RFC 5912, RFC 6712. It has been obsoleted by RFC 9810, RFC 9811 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document contains a set of updates to the syntax of Certificate Management Protocol (CMP) version 2 and its HTTP transfer mechanism. This document updates RFCs 4210, 5912, and 6712.
The aspects of CMP updated in this document are using EnvelopedData instead of EncryptedValue, clarifying the handling of p10cr messages, improving the crypto agility, as well as adding new general message types, extended key usages to identify certificates for use with CMP, and well-known URI path segments.
CMP version 3 is introduced to enable signaling support of EnvelopedData instead of EncryptedValue and signal the use of an explicit hash AlgorithmIdentifier in certConf messages, as far as needed.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9480 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9479 IS-IS Application-Specific Link Attributes
- RFC 9481 Certificate Management Protocol Algorithms
- RFC 9478 Labeled IPsec Traffic Selector Support for the Internet Key Exchange Protocol Version 2
- RFC 9482 Constrained Application Protocol Transfer for the Certificate Management Protocol
- RFC 9477 Complaint Feedback Loop Address Header
- RFC 9483 Lightweight Certificate Management Protocol Profile
- RFC 9476 The .alt Special-Use Top-Level Domain
- RFC 9484 Proxying IP in HTTP