CurrentPROPOSED STANDARDIETF stream

RFC 9618: Updates to X.509 Policy Validation

In plain English — editorial summary, not part of the RFC

This document updates RFC 5280 to replace the algorithm for X.509 policy validation with an equivalent, more efficient algorithm. The original algorithm built a structure that scaled exponentially in the worst case, leaving implementations vulnerable to denial-of-service attacks.

Document record

Document ID
RFC9618
Published
August 2024
Authors
D. Benjamin
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
19
Also known as
Updates:
RFC 5280

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9618-updates-to-x-509-policy-validation