RFC 9589 · PROPOSED STANDARD · 2024

On the Use of the Cryptographic Message Syntax Signing-Time Attribute in Resource Public Key Infrastructure Signed Objects

Overview

RFC 9589, “On the Use of the Cryptographic Message Syntax Signing-Time Attribute in Resource Public Key Infrastructure Signed Objects”, is a Proposed Standard document published in May 2024 by J. Snijders, T. Harrison. It updates RFC 6488. The canonical text is published by the RFC Editor.

Abstract

In the Resource Public Key Infrastructure (RPKI), Signed Objects are defined as Cryptographic Message Syntax (CMS) protected content types. A Signed Object contains a signing-time attribute, representing the purported time at which the object was signed by its issuer. RPKI repositories are accessible using the rsync and RPKI Repository Delta protocols, allowing Relying Parties (RPs) to synchronize a local copy of the RPKI repository used for validation with the remote repositories. This document describes how the CMS signing-time attribute can be used to avoid needless retransfers of data when switching between different synchronization protocols. This document updates RFC 6488 by mandating the presence of the CMS signing-time attribute and disallowing the use of the binary-signing-time attribute.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9589 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 6488
Other RFCs from 2024

Who Is Online

In total there are 179 users online: 0 registered, 171 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372