RFC 4043: Internet X.509 Public Key Infrastructure Permanent Identifier
In plain English — editorial summary, not part of the RFC
This document defines a new form of name, called permanent identifier, that may be included in the subjectAltName extension of a public key certificate issued to an entity. The permanent identifier is an optional feature that may be used by a CA to indicate that two or more certificates relate to the same entity, even if they contain different subject name (DNs) or different names in the subjectAltName extension, or if the name or the affiliation of that entity stored in the subject or another name form in the subjectAltName extension has changed. The subject name, carried in the subject field, is only unique for each subject entity certified by the one CA as defined by the issuer name field. However, the new name form can carry a name that is unique for each subject entity certified by a CA. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4043
- Published
- May 2005
- Authors
- D. Pinkas; T. Gindin
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 15
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4046Multicast Security (MSEC) Group Key Management ArchitectureCurrent
May 2005
- RFC 4055Additional Algorithms and Identifiers for RSA Cryptography for use in the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) ProfileUpdated
June 2005
- RFC 4056Use of the RSASSA-PSS Signature Algorithm in Cryptographic Message Syntax (CMS)Current
June 2005
- RFC 4059Internet X.509 Public Key Infrastructure Warranty Certificate ExtensionCurrent
May 2005
- RFC 4025A Method for Storing IPsec Keying Material in DNSCurrent
March 2005
- RFC 4013SASLprep: Stringprep Profile for User Names and PasswordsObsoleted
March 2005
- RFC 4010Use of the SEED Encryption Algorithm in Cryptographic Message Syntax (CMS)Current
February 2005
- RFC 4082Timed Efficient Stream Loss-Tolerant Authentication (TESLA): Multicast Source Authentication Transform IntroductionCurrent
June 2005
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?