RFC 8209: A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests
In plain English — editorial summary, not part of the RFC
This document defines a standard profile for X.509 certificates used to enable validation of Autonomous System (AS) paths in the Border Gateway Protocol (BGP), as part of an extension to that protocol known as BGPsec. BGP is the standard for inter-domain routing in the Internet; it is the "glue" that holds the Internet together. BGPsec is being developed as one component of a solution that addresses the requirement to provide security for BGP. The goal of BGPsec is to provide full AS path validation based on the use of strong cryptographic primitives. The end entity (EE) certificates specified by this profile are issued to routers within an AS. Each of these certificates is issued under a Resource Public Key Infrastructure (RPKI) Certification Authority (CA) certificate. These CA certificates and EE certificates both contain the AS Resource extension. An EE certificate of this type asserts that the router or routers holding the corresponding private key are authorized to emit secure route advertisements on behalf of the AS(es) specified in the certificate. This document also profiles the format of certification requests and specifies Relying Party (RP) certificate path validation procedures for these EE certificates. This document extends the RPKI; therefore, this document updates the RPKI Resource Certificates Profile (RFC 6487).
Document record
- Document ID
- RFC8209
- Published
- September 2017
- Authors
- M. Reynolds; S. Turner; S. Kent
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- rtg
- Pages
- 15
- Also known as
- —
- Updates:
- RFC 6487
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8210The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1Current
September 2017
- RFC 8208BGPsec Algorithms, Key Formats, and Signature FormatsObsoleted
September 2017
- RFC 8207BGPsec Operational ConsiderationsCurrent
September 2017
- RFC 8211Adverse Actions by a Certification Authority (CA) or Repository Manager in the Resource Public Key Infrastructure (RPKI)Current
September 2017
- RFC 8206BGPsec Considerations for Autonomous System (AS) MigrationCurrent
September 2017
- RFC 8205BGPsec Protocol SpecificationUpdated
September 2017
- RFC 8214Virtual Private Wire Service Support in Ethernet VPNCurrent
August 2017
- RFC 8203BGP Administrative Shutdown CommunicationObsoleted
July 2017
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?