RFC 8649: Hash Of Root Key Certificate Extension
In plain English — editorial summary, not part of the RFC
This document specifies the Hash Of Root Key certificate extension. This certificate extension is carried in the self-signed certificate for a trust anchor, which is often called a Root Certification Authority (CA) certificate. This certificate extension unambiguously identifies the next public key that will be used at some point in the future as the next Root CA certificate, eventually replacing the current one.
Document record
- Document ID
- RFC8649
- Published
- August 2019
- Authors
- R. Housley
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 10
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9397Trusted Execution Environment Provisioning (TEEP) ArchitectureCurrent
July 2023
- RFC 8145Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)Updated
April 2017
- RFC 7344Automating DNSSEC Delegation Trust MaintenanceUpdated
September 2014
- RFC 6010Cryptographic Message Syntax (CMS) Content Constraints ExtensionCurrent
September 2010
- RFC 8657Certification Authority Authorization (CAA) Record Extensions for Account URI and Automatic Certificate Management Environment (ACME) Method BindingCurrent
November 2019
- RFC 8659DNS Certification Authority Authorization (CAA) Resource RecordCurrent
November 2019
- RFC 8636Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Algorithm AgilityCurrent
July 2019
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?