RFC 9286: Manifests for the Resource Public Key Infrastructure (RPKI)
In plain English — editorial summary, not part of the RFC
This document defines a "manifest" for use in the Resource Public Key Infrastructure (RPKI). A manifest is a signed object (file) that contains a listing of all the signed objects (files) in the repository publication point (directory) associated with an authority responsible for publishing in the repository. For each certificate, Certificate Revocation List (CRL), or other type of signed objects issued by the authority that are published at this repository publication point, the manifest contains both the name of the file containing the object and a hash of the file content. Manifests are intended to enable a relying party (RP) to detect certain forms of attacks against a repository. Specifically, if an RP checks a manifest's contents against the signed objects retrieved from a repository publication point, then the RP can detect replay attacks, and unauthorized in-flight modification or deletion of signed objects. This document obsoletes RFC 6486.
Document record
- Document ID
- RFC9286
- Published
- June 2022
- Authors
- R. Austein; G. Huston; S. Kent; M. Lepinski
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 16
- Also known as
- —
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9288Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers at Transit RoutersCurrent
August 2022
- RFC 9291A YANG Network Data Model for Layer 2 VPNsCurrent
September 2022
- RFC 9276Guidance for NSEC3 Parameter SettingsCurrent
August 2022
- RFC 9275An Extension for Application-Layer Traffic Optimization (ALTO): Path VectorCurrent
September 2022
- RFC 9274A Cost Mode Registry for the Application-Layer Traffic Optimization (ALTO) ProtocolCurrent
July 2022
- RFC 9313Pros and Cons of IPv6 Transition Technologies for IPv4-as-a-Service (IPv4aaS)Current
October 2022
- RFC 9255The 'I' in RPKI Does Not Stand for IdentityCurrent
June 2022
- RFC 9317Operational Considerations for Streaming MediaCurrent
October 2022
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?