An Attribute for Statement of Possession of a Private Key
RFC 9883, “An Attribute for Statement of Possession of a Private Key”, is a Proposed Standard document published in October 2025 by R. Housley. The canonical text is published by the RFC Editor.
Abstract
This document specifies an attribute for a statement of possession of a private key by a certificate subject. As part of X.509 certificate enrollment, a Certification Authority (CA) typically demands proof that the subject possesses the private key that corresponds to the to-be-certified public key. In some cases, a CA might accept a signed statement from the certificate subject. For example, when a certificate subject needs separate certificates for signature and key establishment, a statement that can be validated with the previously issued signature certificate for the same subject might be adequate for subsequent issuance of the key establishment certificate.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9883 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9882 Use of the ML-DSA Signature Algorithm in the Cryptographic Message Syntax
- RFC 9884 Label Switched Path Ping for Segment Routing Path Segment Identifier with MPLS Data Plane
- RFC 9881 Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Module-Lattice-Based Digital Signature Algorithm
- RFC 9885 Multi-Part TLVs in IS-IS
- RFC 9886 DRIP Entity Tags in the Domain Name System
- RFC 9879 Use of Password-Based Message Authentication Code 1 in PKCS #12 Syntax
- RFC 9887 Terminal Access Controller Access-Control System Plus over TLS 1.3
- RFC 9878 Updates to Private Header Extension Usage in Session Initiation Protocol Requests and Responses