RFC 9999: Remote ATtestation procedureS (RATS) Conceptual Message Wrapper (CMW)
In plain English — editorial summary, not part of the RFC
The conceptual messages introduced by the Remote ATtestation procedureS (RATS) architecture (RFC 9334) are protocol-agnostic data units that are conveyed between RATS roles during RATS interactions. Conceptual messages describe the meaning and function of such data units within RATS data flows without specifying a wire format, encoding, transport mechanism, or processing details. The initial set of conceptual messages is defined in Section 8 of RFC 9334 and includes Evidence, Attestation Results, Endorsements, Reference Values, and Appraisal Policies. This document introduces the Conceptual Message Wrapper (CMW) that provides a common structure to encapsulate these messages. It defines a dedicated Concise Binary Object Representation (CBOR) tag, corresponding JSON Web Token (JWT) and CBOR Web Token (CWT) claims, and an X.509 extension. Together, these mechanisms allow CMWs to be used in CBOR-based protocols, web APIs using JWTs and CWTs, and PKIX artifacts such as X.509 certificates. Additionally, this document defines media types and CoAP Content-Formats that may be used to identify CMWs when transported over protocols such as HTTP, MIME, and CoAP. The goal is to improve the interoperability and flexibility of remote attestation protocols. Introducing a shared message format such as CMW enables consistent support for different attestation message types, enables the evolution of message serialization formats without breaking compatibility, and avoids the need to redefine how messages are handled within each protocol.
Document record
- Document ID
- RFC9999
- Published
- July 2026
- Authors
- H. Birkholz; N. Smith; T. Fossati; H. Tschofenig
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 35
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9334Remote ATtestation procedureS (RATS) ArchitectureCurrent
January 2023
- RFC 6283Extensible Markup Language Evidence Record Syntax (XMLERS)Current
July 2011
- RFC 10002Certificate Management over CMS (CMC)Current
July 2026
- RFC 10003Certificate Management over CMS (CMC): Transport ProtocolsCurrent
July 2026
- RFC 9995CBOR Object Signing and Encryption (COSE) Hash EnvelopeCurrent
July 2026
- RFC 10004Certificate Management over CMS (CMC): Compliance RequirementsCurrent
July 2026
- RFC 10007Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) ValidationCurrent
June 2026
- RFC 9987Secure Shell (SSH) Agent ProtocolCurrent
May 2026
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?