A Profile for Resource Public Key Infrastructure Trust Anchor Keys
RFC 9691, “A Profile for Resource Public Key Infrastructure Trust Anchor Keys”, is a Proposed Standard document published in December 2024 by C. Martinez, G. Michaelson, T. Harrison, T. Bruijnzeels, R. Austein. The canonical text is published by the RFC Editor.
Abstract
A Trust Anchor Locator (TAL) is used by Relying Parties (RPs) in the Resource Public Key Infrastructure (RPKI) to locate and validate a Trust Anchor (TA) Certification Authority (CA) certificate used in RPKI validation. This document defines an RPKI signed object for a Trust Anchor Key (TAK). A TAK object can be used by a TA to signal to RPs the location(s) of the accompanying CA certificate for the current public key, as well as the successor public key and the location(s) of its CA certificate. This object helps to support planned key rollovers without impacting RPKI validation.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9691 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9689 Use Cases for a PCE as a Central Controller
- RFC 9688 Use of the SHA3 One-Way Hash Functions in the Cryptographic Message Syntax
- RFC 9687 Border Gateway Protocol 4 Send Hold Timer
- RFC 9686 Registering Self-Generated IPv6 Addresses Using DHCPv6
- RFC 9685 Listener Subscription for IPv6 Neighbor Discovery Multicast and Anycast Addresses
- RFC 9697 Detecting RPKI Repository Delta Protocol Session Desynchronization
- RFC 9684 A YANG Data Model for Challenge-Response-Based Remote Attestation Procedures Using Trusted Platform Modules
- RFC 9683 Remote Integrity Verification of Network Devices Containing Trusted Platform Modules