RFC 8747: Proof-of-Possession Key Semantics for CBOR Web Tokens (CWTs)
In plain English — editorial summary, not part of the RFC
This specification describes how to declare in a CBOR Web Token (CWT) (which is defined by RFC 8392) that the presenter of the CWT possesses a particular proof-of-possession key. Being able to prove possession of a key is also sometimes described as being the holder-of-key. This specification provides equivalent functionality to "Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)" (RFC 7800) but using Concise Binary Object Representation (CBOR) and CWTs rather than JavaScript Object Notation (JSON) and JSON Web Tokens (JWTs).
Document record
- Document ID
- RFC8747
- Published
- March 2020
- Authors
- M. Jones; L. Seitz; G. Selander; S. Erdtman; H. Tschofenig
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8705OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access TokensCurrent
February 2020
- RFC 7800Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)Current
April 2016
- RFC 8750Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)Current
March 2020
- RFC 8744Issues and Requirements for Server Name Identification (SNI) Encryption in TLSCurrent
July 2020
- RFC 8739Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)Current
March 2020
- RFC 8738Automated Certificate Management Environment (ACME) IP Identifier Validation ExtensionCurrent
February 2020
- RFC 8737Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge ExtensionCurrent
February 2020
- RFC 8758Deprecating RC4 in Secure Shell (SSH)Current
April 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?