RFC 9608: No Revocation Available for X.509 Public Key Certificates
In plain English — editorial summary, not part of the RFC
X.509v3 public key certificates are profiled in RFC 5280. Short-lived certificates are seeing greater use in the Internet. The Certification Authority (CA) that issues these short-lived certificates do not publish revocation information because the certificate lifespan that is shorter than the time needed to detect, report, and distribute revocation information. Some long-lived X.509v3 public key certificates never expire, and they are never revoked. This specification defines the noRevAvail certificate extension so that a relying party can readily determine that the CA does not publish revocation information for the certificate, and it updates the certification path validation algorithm defined in RFC 5280 so that revocation checking is skipped when the noRevAvail certificate extension is present.
Document record
- Document ID
- RFC9608
- Published
- June 2024
- Authors
- R. Housley; T. Okubo; J. Mandel
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 10
- Also known as
- —
- Updates:
- RFC 5280
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9611Internet Key Exchange Protocol Version 2 (IKEv2) Support for Per-Resource Child Security Associations (SAs)Current
July 2024
- RFC 9598Internationalized Email Addresses in X.509 CertificatesCurrent
May 2024
- RFC 9618Updates to X.509 Policy ValidationCurrent
August 2024
- RFC 9597CBOR Web Token (CWT) Claims in COSE HeadersCurrent
June 2024
- RFC 9596CBOR Object Signing and Encryption (COSE) "typ" (type) Header ParameterCurrent
June 2024
- RFC 9594Key Provisioning for Group Communication Using Authentication and Authorization for Constrained Environments (ACE)Current
September 2024
- RFC 9593Announcing Supported Authentication Methods in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
July 2024
- RFC 9588Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authenticationCurrent
August 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?