RFC 5280 is the IETF standard that defines the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) profile. It specifies the structure, encoding, and processing rules for X.509 v3 certificates and v2 CRLs, including the required and optional extensions and the certification path validation algorithm. The document is the normative reference that governs how PKI implementations issue, encode, and validate certificates on the public Internet.

Overview

  • RFC 5280 supersedes earlier profiles (RFC 3280 and RFC 2459) and is the normative reference for X.509 v3 certificates and X.509 v2 CRLs as used on the public Internet.
  • It defines the mandatory and optional certificate fields, the set of standard extensions (such as Basic Constraints, Key Usage, Extended Key Usage, Subject Alternative Name, and Authority/Subject Key Identifier), and their criticality semantics.
  • A central contribution is the certification path validation algorithm, which describes how a relying party verifies a chain from an end-entity certificate up to a trusted root, checking signatures, validity periods, name constraints, and revocation status.
  • By precisely specifying encoding and processing, RFC 5280 enables interoperability across heterogeneous PKI implementations and is the basis on which the Web PKI and TLS trust model rest.

Key aspects

  • Certificate profile: required fields, version, serial number, issuer/subject, validity, and the public key.
  • Extension profile: standard X.509 v3 extensions and rules for handling unknown critical extensions.
  • CRL profile: structure of v2 CRLs, revocation entries, and CRL extensions.
  • Path validation: the algorithm for building and checking a certification path against trust anchors and policy constraints.
  • Encoding: use of ASN.1 with DER for unambiguous, canonical serialisation.

Applications

Provenance