RFC 9883
An Attribute for Statement of Possession of a Private Key, October 2025
- File formats:

- Also available: XML file for editing
- Status:
- PROPOSED STANDARD
- Author:
- R. Housley
- Stream:
- IETF
- Source:
- lamps (sec)
Cite this RFC: TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC9883
Discuss this RFC: Send questions or comments to the mailing list spasm@ietf.org
Other actions: Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 9883
Abstract
This document specifies an attribute for a statement of possession of a private key by a certificate subject. As part of X.509 certificate enrollment, a Certification Authority (CA) typically demands proof that the subject possesses the private key that corresponds to the to-be-certified public key. In some cases, a CA might accept a signed statement from the certificate subject. For example, when a certificate subject needs separate certificates for signature and key establishment, a statement that can be validated with the previously issued signature certificate for the same subject might be adequate for subsequent issuance of the key establishment certificate.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.