[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-160302-en":3,"doc-seo-160302-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},160302,7971461740886,"Theodore","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",6,"Technology","RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile","This memo profiles the X.509 v3 certificate and the X.509 v2 certificate revocation list (CRL) for use in the Internet. It introduces an overview and model for this approach, then specifies the v3 certificate format in detail, including guidance on Internet name forms. It defines standard certificate extensions and two Internet-specific extensions, lists required extensions, and describes v2 CRL structures. It also specifies certification path validation and includes an ASN.1 module and examples in the appendices.","Network Working Group D . Cooper  \nRequest for Comments: 5280 NIST  \nObsoletes: 3280, 4325, 4630 S . Santesson  \nCategory: Standards Track Microsoft  \nS . Farrell Trinity College Dublin  \nS . Boeyen Entrust  \nR . Housley Vigil Security  \nW . Polk NIST  \nMay 2008  \nInternet X .509 Public Key Infrastructure Certificate  \nand Certificate Revocation List (CRL) Profile  \nStatus of This Memo  \nThis document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the \"Internet Official Protocol Standards\" (STD 1) for the standardization state and status of this protocol . Distribution of this memo is unlimited.  \nAbstract  \nThis memo profiles the X .509 v3 certificate and X .509 v2 certificate revocation list (CRL) for use in the Internet . An overview of this approach and model is provided as an introduction. The X .509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms . Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X .509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X .509 certification path validation is described. An ASN .1 module and examples are provided in the appendices.  \nCooper, et al . Standards Track [Page 1]  \nRFC 5280 PKIX Certificate and CRL Profile May 2008  \nTable of Contents  \n1. Introduction ....................................................4  \n2. Requirements and Assumptions ....................................6  \n2.1. Communication and Topology .................................7  \n2.2. Acceptability Criteria .....................................7  \n2.3. User Expectations ..........................................7  \n2.4. Administrator Expectations .................................8  \n3. Overview of Approach ............................................8  \n3.1. X .509 Version 3 Certificate ................................9  \n3.2. Certification Paths and Trust .............................10  \n3.3. Revocation ................................................13  \n3.4. Operational Protocols .....................................14  \n3.5. Management Protocols ......................................14  \n4. Certificate and Certificate Extensions Profile .................16  \n4.1. Basic Certificate Fields ..................................16  \n4.1.1. Certificate Fields .................................17  \n4.1.1.1 . tbsCertificate ............................18  \n4.1.1.2 . signatureAlgorithm ........................18  \n4.1.1.3 . signatureValue ............................18  \n4.1.2. TBSCertificate .....................................18  \n4.1.2.1 . Version ...................................19  \n4.1.2.2 . Serial Number .............................19  \n4.1.2.3 . Signature .................................19  \n4.1.2.4 . Issuer ....................................20  \n4.1.2.5 . Validity ..................................22  \n4.1.2.5.1. UTCTime ........................23  \n4.1.2.5.2. GeneralizedTime ................23  \n4.1.2.6 . Subject ...................................23  \n4.1.2.7 . Subject Public Key Info ...................25  \n4.1.2.8 . Unique Identifiers ........................25  \n4.1.2.9 . Extensions ................................26  \n4.2. Certificate Extensions ....................................26  \n4.2.1. Standard Extensions ................................27  \n4.2.1.1 . Authority Key Identifier ..................27  \n4.2.1.2 . Subject Key Identifier ....................28  \n4.2.1.3 . Key Usage .................................29  \n4.2.1.4 . Certificate Policies ......................32  \n4.2.1.5 . Policy Mappings ...........................35  \n4.2.1.6 . Subject Alternative Name ..................35  \n4.2.1.7 . Issuer Alternative Name .........","cbCaiqw8DGwaOLqf","https://ap.wps.com/l/cbCaiqw8DGwaOLqf","pdf",208032,1,152,"English","en",105,"# 1. Introduction\n# 2. Requirements and Assumptions\n# 3. Overview of Approach\n# 4. Certificate and Certificate Extensions Profile\n# 5. CRL and CRL Extensions Profile","[{\"question\":\"What does RFC 5280 define for Internet public key infrastructure?\",\"answer\":\"RFC 5280 specifies the X.509 v3 certificate and the X.509 v2 certificate revocation list (CRL) profiles for Internet use, including required extensions and formats.\"},{\"question\":\"How does RFC 5280 handle certificate extensions?\",\"answer\":\"It describes standard certificate extensions and defines two Internet-specific extensions, along with a set of required certificate extensions.\"},{\"question\":\"Does RFC 5280 include guidance beyond certificate and CRL formats?\",\"answer\":\"Yes. It also describes an algorithm for X.509 certification path validation and provides an ASN.1 module and examples in the appendices.\"}]","RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile | PDF",1788053678,383,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"rfc-5280-internet-x509-public-key-infrastructure-certificate-and-certificate-revocation-list-crl-profile","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/rfc-5280-internet-x509-public-key-infrastructure-certificate-and-certificate-revocation-list-crl-profile/160302/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-30",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does RFC 5280 define for Internet public key infrastructure?","Question",{"text":75,"@type":76},"RFC 5280 specifies the X.509 v3 certificate and the X.509 v2 certificate revocation list (CRL) profiles for Internet use, including required extensions and formats.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does RFC 5280 handle certificate extensions?",{"text":80,"@type":76},"It describes standard certificate extensions and defines two Internet-specific extensions, along with a set of required certificate extensions.",{"name":82,"@type":73,"acceptedAnswer":83},"Does RFC 5280 include guidance beyond certificate and CRL formats?",{"text":84,"@type":76},"Yes. It also describes an algorithm for X.509 certification path validation and provides an ASN.1 module and examples in the appendices.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]