RFC 9883: An Attribute for Statement of Possession of a Private Key
Recent RFCs 2025-10-13
Summary:
This document specifies an attribute for a statement of possession of
a private key by a certificate subject. As part of X.509 certificate
enrollment, a Certification Authority (CA) typically demands proof
that the subject possesses the private key that corresponds to the
to-be-certified public key. In some cases, a CA might accept a
signed statement from the certificate subject. For example, when a
certificate subject needs separate certificates for signature and key
establishment, a statement that can be validated with the previously
issued signature certificate for the same subject might be adequate
for subsequent issuance of the key establishment certificate.