RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
In plain English — editorial summary, not part of the RFC
This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5280
- Published
- May 2008
- Authors
- D. Cooper; S. Santesson; S. Farrell; S. Boeyen; R. Housley; W. Polk
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 151
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 5 RFCs, each formally replacing the one before it.
- RFC 2459 (1999)
- RFC 3280 (2002)
- RFC 4325 (2005)
- RFC 4630 (2006)
- RFC 5280 (2008)
Referenced by
9 later RFCs formally update or obsolete part of this document.
- RFC 6818Updates to the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) ProfileCurrent
January 2013
- RFC 8398Internationalized Email Addresses in X.509 CertificatesObsoleted
May 2018
- RFC 8399Internationalization Updates to RFC 5280Obsoleted
May 2018
- RFC 9549Internationalization Updates to RFC 5280Current
March 2024
- RFC 9598Internationalized Email Addresses in X.509 CertificatesCurrent
May 2024
- RFC 9608No Revocation Available for X.509 Public Key CertificatesCurrent
June 2024
- RFC 9618Updates to X.509 Policy ValidationCurrent
August 2024
- RFC 9925Unsigned X.509 CertificatesCurrent
February 2026
- RFC 10007Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) ValidationCurrent
June 2026
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9908Clarification and Enhancement of the CSR Attributes Definition in RFC 7030Current
January 2026
- RFC 5275CMS Symmetric Key Management and DistributionCurrent
June 2008
- RFC 5274Certificate Management Messages over CMS (CMC): Compliance RequirementsObsoleted
June 2008
- RFC 5273Certificate Management over CMS (CMC): Transport ProtocolsObsoleted
June 2008
- RFC 5272Certificate Management over CMS (CMC)Obsoleted
June 2008
- RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLSUpdated
August 2008
- RFC 5289TLS Elliptic Curve Cipher Suites with SHA-256/384 and AES Galois Counter Mode (GCM)Updated
August 2008
- RFC 5295Specification for the Derivation of Root Keys from an Extended Master Session Key (EMSK)Current
August 2008
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?