RFC 9966 · PROPOSED STANDARD · 2026

Bootstrapped TLS Authentication with Proof of Knowledge

Overview

RFC 9966, “Bootstrapped TLS Authentication with Proof of Knowledge”, is a Proposed Standard document published in May 2026 by O. Friel, D. Harkins. The canonical text is published by the RFC Editor.

Abstract

This document defines a mechanism that enables a bootstrapping device to establish trust and mutually authenticate against a TLS server. Bootstrapping devices have a public/private key pair; this mechanism enables a TLS server to prove to the device that it knows the public key and enables the device to prove to the TLS server that it knows the private key. The mechanism leverages existing Device Provisioning Profile (DPP) and TLS standards and can be used in an Extensible Authentication Protocol (EAP) exchange with an EAP server.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9966 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2026

Who Is Online

In total there are 74 users online: 0 registered, 66 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 372