CurrentPROPOSED STANDARDIETF stream

RFC 9336: X.509 Certificate General-Purpose Extended Key Usage (EKU) for Document Signing

In plain English — editorial summary, not part of the RFC

RFC 5280 specifies several extended key purpose identifiers (KeyPurposeIds) for X.509 certificates. This document defines a general-purpose Document-Signing KeyPurposeId for inclusion in the Extended Key Usage (EKU) extension of X.509 public key certificates. Document-Signing applications may require that the EKU extension be present and that a Document-Signing KeyPurposeId be indicated in order for the certificate to be acceptable to that Document-Signing application.

Document record

Document ID
RFC9336
Published
December 2022
Authors
T. Ito; T. Okubo; S. Turner
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
8
Also known as

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9336-x-509-certificate-general-purpose-extended-key-usage-eku-for-document-signing