RFC 5280 is the IETF standard that defines the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) profile. It specifies the structure, encoding, and processing rules for X.509 v3 certificates and v2 CRLs, including the required and optional extensions and the certification path validation algorithm. The document is the normative reference that governs how PKI implementations issue, encode, and validate certificates on the public Internet.
- RFC 5280 is the IETF document defining the Internet X.509 Certificate and Certificate Revocation List profile for Public Key Infrastructure.
- It specifies how a Certificate Authority structures, encodes, and validates certificates, and standardises the certification-path validation algorithm.
- It uses Public-Key Cryptography and Digital Signature primitives to bind identities to keys in an interoperable way.
Overview
- RFC 5280 supersedes earlier profiles (RFC 3280 and RFC 2459) and is the normative reference for X.509 v3 certificates and X.509 v2 CRLs as used on the public Internet.
- It defines the mandatory and optional certificate fields, the set of standard extensions (such as Basic Constraints, Key Usage, Extended Key Usage, Subject Alternative Name, and Authority/Subject Key Identifier), and their criticality semantics.
- A central contribution is the certification path validation algorithm, which describes how a relying party verifies a chain from an end-entity certificate up to a trusted root, checking signatures, validity periods, name constraints, and revocation status.
- By precisely specifying encoding and processing, RFC 5280 enables interoperability across heterogeneous PKI implementations and is the basis on which the Web PKI and TLS trust model rest.
Key aspects
- Certificate profile: required fields, version, serial number, issuer/subject, validity, and the public key.
- Extension profile: standard X.509 v3 extensions and rules for handling unknown critical extensions.
- CRL profile: structure of v2 CRLs, revocation entries, and CRL extensions.
- Path validation: the algorithm for building and checking a certification path against trust anchors and policy constraints.
- Encoding: use of ASN.1 with DER for unambiguous, canonical serialisation.
Applications
- TLS server and client certificate validation underpinning HTTPS.
- Enterprise Public Key Infrastructure for code signing, email (S/MIME), and device identity.
- Government and regulated identity schemes relying on X.509 Certificate chains.
- Validation of revocation status against a Certificate Revocation List or, as an alternative, OCSP.