RFC 10002: Certificate Management over CMS (CMC)
In plain English — editorial summary, not part of the RFC
This document defines the base syntax for CMC, a Certificate Management protocol using the Cryptographic Message Syntax (CMS). This protocol addresses two immediate needs within the Internet Public Key Infrastructure (PKI) community: CMC also requires the use of the transport document (RFC 10003) and the requirements usage document (RFC 10004) along with this document for a full definition. This document obsoletes RFCs 5272 and 6402.
Document record
- Document ID
- RFC10002
- Published
- July 2026
- Authors
- J. Mandel; S. Turner
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 91
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 8 RFCs, each formally replacing the one before it.
- RFC 2797 (2000)
- RFC 5272 (2008)
- RFC 5273 (2008)
- RFC 5274 (2008)
- RFC 6402 (2011)
- RFC 10002 (2026)
- RFC 10003 (2026)
- RFC 10004 (2026) ✓
Read the full history of Certificate Management over CMS (CMC): Compliance Requirements →
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 10003Certificate Management over CMS (CMC): Transport ProtocolsCurrent
July 2026
- RFC 10004Certificate Management over CMS (CMC): Compliance RequirementsCurrent
July 2026
- RFC 10007Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) ValidationCurrent
June 2026
- RFC 9811Internet X.509 Public Key Infrastructure -- HTTP Transfer for the Certificate Management Protocol (CMP)Current
July 2025
- RFC 9810Internet X.509 Public Key Infrastructure -- Certificate Management Protocol (CMP)Current
July 2025
- RFC 9399Internet X.509 Public Key Infrastructure: Logotypes in X.509 CertificatesCurrent
May 2023
- RFC 5275CMS Symmetric Key Management and DistributionCurrent
June 2008
- RFC 5274Certificate Management Messages over CMS (CMC): Compliance RequirementsObsoleted
June 2008
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?