On the Use of the Cryptographic Message Syntax Signing-Time Attribute in Resource Public Key Infrastructure Signed Objects
RFC 9589, “On the Use of the Cryptographic Message Syntax Signing-Time Attribute in Resource Public Key Infrastructure Signed Objects”, is a Proposed Standard document published in May 2024 by J. Snijders, T. Harrison. It updates RFC 6488. The canonical text is published by the RFC Editor.
Abstract
In the Resource Public Key Infrastructure (RPKI), Signed Objects are defined as Cryptographic Message Syntax (CMS) protected content types. A Signed Object contains a signing-time attribute, representing the purported time at which the object was signed by its issuer. RPKI repositories are accessible using the rsync and RPKI Repository Delta protocols, allowing Relying Parties (RPs) to synchronize a local copy of the RPKI repository used for validation with the remote repositories. This document describes how the CMS signing-time attribute can be used to avoid needless retransfers of data when switching between different synchronization protocols. This document updates RFC 6488 by mandating the presence of the CMS signing-time attribute and disallowing the use of the binary-signing-time attribute.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9589 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9588 Kerberos Simple Password-Authenticated Key Exchange Pre- authentication
- RFC 9590 IMAP Extension for Returning Mailbox METADATA in Extended LIS
- RFC 9587 YANG Data Model for OSPFv3 Extended Link State Advertisements
- RFC 9591 The Flexible Round-Optimized Schnorr Threshold Protocol for Two-Round Schnorr Signatures
- RFC 9586 IMAP Extension for Using and Returning Unique Identifiers Only
- RFC 9592 Retiring the Tao of the IETF
- RFC 9585 IMAP Response Code for Command Progress Notifications
- RFC 9593 Announcing Supported Authentication Methods in the Internet Key Exchange Protocol Version 2