Internet X.509 Public Key Infrastructure -- Certificate Management Protocol
RFC 9810, “Internet X.509 Public Key Infrastructure -- Certificate Management Protocol”, is a Proposed Standard document published in July 2025 by H. Brockhaus, D. von Oheimb, M. Ounsworth, J. Gray. It updates RFC 5912. It obsoletes RFC 4210, RFC 9480. The canonical text is published by the RFC Editor.
Abstract
This document describes the Internet X.509 Public Key Infrastructure (PKI) Certificate Management Protocol (CMP). Protocol messages are defined for X.509v3 certificate creation and management. CMP provides interactions between client systems and PKI components such as a Registration Authority (RA) and a Certification Authority (CA).
This document adds support for management of certificates containing a Key Encapsulation Mechanism (KEM) public key and uses EnvelopedData instead of EncryptedValue. This document also includes the updates specified in Section 2 and Appendix A.2 of RFC 9480.
This document obsoletes RFC 4210, and together with RFC 9811, it also obsoletes RFC 9480. Appendix F of this document updates Section 9 of RFC 5912.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9810 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9809 X.509 Certificate Extended Key Usage for Configuration, Updates, and Safety-Critical Communication
- RFC 9811 Internet X.509 Public Key Infrastructure -- HTTP Transfer for the Certificate Management Protocol
- RFC 9808 Content Delivery Network Interconnection Capacity Capability Advertisement Extensions
- RFC 9812 Clarification of IPv6 Address Allocation Policy
- RFC 9807 The OPAQUE Augmented Password-Authenticated Key Exchange Protocol
- RFC 9813 Operational Considerations for Using TLS Pre-Shared Keys with RADIUS
- RFC 9806 Updates to SIP-Based Media Recording to Correct Metadata Media Type
- RFC 9814 Use of the SLH-DSA Signature Algorithm in the Cryptographic Message Syntax