Network Working Group L. Liao Internet-Draft NIO Intended status: Standards Track 19 July 2026 Expires: 20 January 2027 EST for C509 Certificates draft-liao-ace-est-c509-03 Abstract This document defines Enrollment over Secure Transport (EST) protocol operations over HTTPS and secure CoAP for use with C509 certificates. The operations specified in this document support CA certificate distribution, C509 certificate enrollment, C509 certificate re- enrollment, and server-side key generation using C509 certificates. This document also defines operations for Certificate Revocation List (CRL) distribution. About This Document This note is to be removed before publishing as an RFC. Status information for this document may be found at https://datatracker.ietf.org/doc/draft-liao-ace-est-c509/. Discussion of this document takes place on the Authentication and Authorization for Constrained Environments Working Group mailing list (mailto:ace@ietf.org), which is archived at https://mailarchive.ietf.org/arch/browse/ace/. Subscribe at https://www.ietf.org/mailman/listinfo/ace/. Source for this draft and an issue tracker can be found at https://github.com/ace-wg/xxx. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Liao Expires 20 January 2027 [Page 1] Internet-Draft EST-C509 July 2026 Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 20 January 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 4 2. Conventions and Definitions . . . . . . . . . . . . . . . . . 7 3. Protocol Design . . . . . . . . . . . . . . . . . . . . . . . 8 3.1. Client Authentication . . . . . . . . . . . . . . . . . . 8 3.2. Discovery and URIs . . . . . . . . . . . . . . . . . . . 8 3.3. EST URL Structure and Path Components . . . . . . . . . . 9 3.4. Channel Binding . . . . . . . . . . . . . . . . . . . . . 9 3.5. Message Binding . . . . . . . . . . . . . . . . . . . . . 9 3.6. Message Fragmentation . . . . . . . . . . . . . . . . . . 9 3.7. Delayed Responses . . . . . . . . . . . . . . . . . . . . 10 3.8. Response Cache . . . . . . . . . . . . . . . . . . . . . 10 3.9. CBOR Transfer . . . . . . . . . . . . . . . . . . . . . . 10 4. C509 Certification Request (C509 CSR) . . . . . . . . . . . . 11 4.1. empty-publickey Algorithm . . . . . . . . . . . . . . . . 12 4.2. CRAttribute C509ChangeSubjectName . . . . . . . . . . . . 12 4.3. Proof of Possession . . . . . . . . . . . . . . . . . . . 13 4.3.1. C509PublicKey . . . . . . . . . . . . . . . . . . . . 13 4.3.2. Proof of Possession for KEM Private Keys . . . . . . 13 5. EST Operations for Server Capability Discovery . . . . . . . 15 5.1. caps . . . . . . . . . . . . . . . . . . . . . . . . . . 15 5.1.1. Request . . . . . . . . . . . . . . . . . . . . . . . 15 5.1.2. Response . . . . . . . . . . . . . . . . . . . . . . 15 5.2. csrattrs / att . . . . . . . . . . . . . . . . . . . . . 16 5.2.1. Request . . . . . . . . . . . . . . . . . . . . . . . 17 5.2.2. Response . . . . . . . . . . . . . . . . . . . . . . 17 Liao Expires 20 January 2027 [Page 2] Internet-Draft EST-C509 July 2026 6. EST Operations for Distribution of CA Certificates . . . . . 17 6.1. cacerts / crts . . . . . . . . . . . . . . . . . . . . . 17 6.1.1. Request . . . . . . . . . . . . . . . . . . . . . . . 18 6.1.2. Response . . . . . . . . . . . . . . . . . . . . . . 18 7. EST Operations for Distribution of C509 CRLs . . . . . . . . 19 7.1. crli . . . . . . . . . . . . . . . . . . . . . . . . . . 19 7.1.1. Request . . . . . . . . . . . . . . . . . . . . . . . 19 7.1.2. Response . . . . . . . . . . . . . . . . . . . . . . 20 7.2. crl . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 7.2.1. Request . . . . . . . . . . . . . . . . . . . . . . . 20 7.2.2. Response . . . . . . . . . . . . . . . . . . . . . . 21 8. EST Operations for Certificate Enrollment . . . . . . . . . . 21 8.1. kemc . . . . . . . . . . . . . . . . . . . . . . . . . . 21 8.1.1. Request . . . . . . . . . . . . . . . . . . . . . . . 21 8.1.2. Response . . . . . . . . . . . . . . . . . . . . . . 21 8.2. simpleenroll / sen . . . . . . . . . . . . . . . . . . . 22 8.2.1. Request . . . . . . . . . . . . . . . . . . . . . . . 22 8.2.2. Response . . . . . . . . . . . . . . . . . . . . . . 22 8.3. simplereenroll / sren . . . . . . . . . . . . . . . . . . 22 8.3.1. Request . . . . . . . . . . . . . . . . . . . . . . . 23 8.3.2. Response . . . . . . . . . . . . . . . . . . . . . . 23 8.4. serverkeygen / skc . . . . . . . . . . . . . . . . . . . 23 8.4.1. Request . . . . . . . . . . . . . . . . . . . . . . . 24 8.4.2. Response . . . . . . . . . . . . . . . . . . . . . . 24 9. Security Considerations . . . . . . . . . . . . . . . . . . . 24 9.1. Transport Security . . . . . . . . . . . . . . . . . . . 24 9.1.1. TLS Certificate Type Negotiation . . . . . . . . . . 25 9.1.2. Client Authentication . . . . . . . . . . . . . . . . 25 9.2. Server Key Generation . . . . . . . . . . . . . . . . . . 25 9.3. C509 Certificate Validation . . . . . . . . . . . . . . . 25 10. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 25 10.1. C509 Public Key Algorithms Registry . . . . . . . . . . 26 10.2. C509 Signature Algorithms Registry . . . . . . . . . . . 26 10.3. C509 CR Attributes Registry . . . . . . . . . . . . . . 27 10.3.1. Media Type application/c509-pubkey+cbor . . . . . . 27 10.3.2. Media Type application/c509-kemchall+cbor . . . . . 28 10.4. CoAP Content-Formats Registry . . . . . . . . . . . . . 29 11. References . . . . . . . . . . . . . . . . . . . . . . . . . 30 11.1. Normative References . . . . . . . . . . . . . . . . . . 30 11.2. Informative References . . . . . . . . . . . . . . . . . 32 Appendix A. Message Flow Diagrams of EST over HTTPS Operations . . . . . . . . . . . . . . . . . . . . . . . 32 A.1. caps . . . . . . . . . . . . . . . . . . . . . . . . . . 32 A.2. cacerts for single CA certificate . . . . . . . . . . . . 32 A.3. cacerts for CA certificate set . . . . . . . . . . . . . 33 A.4. cacerts for CA certificate chain . . . . . . . . . . . . 33 A.5. crli . . . . . . . . . . . . . . . . . . . . . . . . . . 33 A.6. crl . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 Liao Expires 20 January 2027 [Page 3] Internet-Draft EST-C509 July 2026 A.7. kemc . . . . . . . . . . . . . . . . . . . . . . . . . . 34 A.8. simpleenroll . . . . . . . . . . . . . . . . . . . . . . 35 A.9. simplereenroll . . . . . . . . . . . . . . . . . . . . . 35 A.10. serverkeygen . . . . . . . . . . . . . . . . . . . . . . 36 Appendix B. Message Flow Diagrams of EST over CoAP/DTLS Operations . . . . . . . . . . . . . . . . . . . . . . . 37 B.1. cacerts for single CA certificate . . . . . . . . . . . . 37 B.2. cacerts for CA certificate set . . . . . . . . . . . . . 37 B.3. cacerts for CA certificate chain . . . . . . . . . . . . 37 B.4. crli . . . . . . . . . . . . . . . . . . . . . . . . . . 38 B.5. crl . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 B.6. kemc . . . . . . . . . . . . . . . . . . . . . . . . . . 38 B.7. sen . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 B.8. sren . . . . . . . . . . . . . . . . . . . . . . . . . . 39 B.9. skc . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 Acknowledgements . . . . . . . . . . . . . . . . . . . . . . . . 40 Change log . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 Since draft-liao-ace-est-c509-02 . . . . . . . . . . . . . . . 40 Since draft-liao-ace-est-c509-01 . . . . . . . . . . . . . . . 41 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 41 1. Introduction Enrollment over Secure Transport (EST) [RFC7030] defines HTTPS-based operations for X.509 [RFC5280] certificate enrollment and CA certificate distribution. Payloads are DER-encoded and wrapped in CMS (Cryptographic Message Syntax, [RFC5652]) structures. C509 [I-D.ietf-cose-cbor-encoded-cert] defines a compact, CBOR-encoded alternative to DER X.509 certificates. C509 certificates are substantially smaller. Although C509 was developed with constrained devices in mind, its benefits extend to unconstrained devices operating over low-bandwidth links and to large-scale deployments. Smaller, CBOR-encoded certificates reduce bandwidth and storage requirements, accelerate TLS handshakes, and lower parsing and serialization overhead even on powerful endpoints; because C509 does not use ASN.1/DER, implementations can avoid complex ASN.1 parsing code, which reduces code size and complexity and lowers the attack surface for certificate parsing libraries. In complex systems (for example, connected cars) that contain diverse device classes—microcontrollers, sensor chips, and SoCs—using a common certificate format wherever practical simplifies integration and provisioning. Using C509 consistently across device classes simplifies provisioning, interoperability, and over-the-air updates, and can reduce overall operational costs and latency. Liao Expires 20 January 2027 [Page 4] Internet-Draft EST-C509 July 2026 This document defines EST operations that carry C509 objects in place of DER X.509 objects, following the same secure transport and URI path structure as [RFC7030] and [RFC9148]. A key property of this design is that EST clients do not require a CBOR parser or generator: * For non-KEM-only key types, the C509 CSR is typically pre- provisioned as an opaque binary blob by the device manufacturer or a provisioning tool; the EST client sends it verbatim as the POST body of simpleenroll / sen or simplereenroll / sren without interpreting its contents. * For KEM-only key types, the EST client needs to communicate with the key device to get the public key (C509PublicKey) and the certification request (C509CertificationRequest) after receiving the KEM challenge object (C509KemChall) from the EST server; in this case, the EST client considers the C509PublicKey, C509KemChall, and C509CertificationRequest opaque binary blobs. * For all key types, the C509 certificate (and private key in the operation serverkeygen / skc) returned in the response is stored directly to persistent memory without parsing. This property makes the EST client implementation extremely lightweight. This document uses C509CertificationRequest as defined in [I-D.ietf-cose-cbor-encoded-cert] as the C509 Certificate Signing Request (C509 CSR) format. An EST client uses a C509 CSR to request issuance of a C509 certificate from an EST server. The operations for EST over HTTPS used in this document are (those wit new marked are new operations defined in this document) in Figure 1, and for EST over CoAP in Figure 2. Liao Expires 20 January 2027 [Page 5] Internet-Draft EST-C509 July 2026 +==========+===+=============+==============+===================+ | Opera- | M | Description | Request | Response | | tion | / | | Media Type | Media Type | | | O | | | | +==========+===+=============+==============+===================+ | caps | M | Capability | (none) | text/plain; | | (new) | | discovery | | charset=utf-8 | +----------+---+-------------+--------------+-------------------+ | cacerts | M | CA | (none) | - application/ | | | | certificate | | cose-c509+cbor | | | | retrieval | | - application/ | | | | | | cose-c509+cbor, | | | | | | usage=chain | | | | | | - cose-c509-cert | | | | | | +cbor | +----------+---+-------------+--------------+-------------------+ | crli | O | CRL | (none) | application/ | | (new) | | metadata | | c509-crlinfo+cbor | | | | retrieval | | | +----------+---+-------------+--------------+-------------------+ | crl | O | CRL | (none) | application/ | | (new) | | retrieval | | c509-crl+cbor | +----------+---+-------------+--------------+-------------------+ | csr | O | CSR | (none) | application/ | | attrs | | attributes | | cose-c509- | | | | retrieval | | crtemplate+cbor | +----------+---+-------------+--------------+-------------------+ | kemc | O | KEM | application/ | application/ | | (new) | | challenge | c509-pubkey | c509-kemchall | | | | issuance | +cbor | +cbor | +----------+---+-------------+--------------+-------------------+ | simple | M | Certificate | application/ | application/ | | enroll | | enrollment | cose-c509- | cose-c509- | | | | | pkcs10+cbor | cert+cbor | +----------+---+-------------+--------------+-------------------+ | simple | M | Certificate | application/ | application/ | | reenroll | | reenroll- | cose-c509- | cose-c509- | | | | ment | pkcs10+cbor | cert+cbor | +----------+---+-------------+--------------+-------------------+ | server | O | Server-side | application/ | application/ | | keygen | | key | cose-c509- | cose-c509- | | | | generation | pkcs10+cbor | pem+cbor | +----------+---+-------------+--------------+-------------------+ Figure 1: Operations for EST over CoAP/DTLS Used in This Document (M/O: MANDDATORY / OPTIONAL) Liao Expires 20 January 2027 [Page 6] Internet-Draft EST-C509 July 2026 +===============+================+=====+==========+==========+ | EST over | Corresponding | M/O | Request | Response | | CoAP/DTLS | EST over HTTPS | | Content- | Content- | | Operation | Operation | | Format | Format | +===============+================+=====+==========+==========+ | (Not Related) | | | | | +---------------+----------------+-----+----------+----------+ | crts | cacerts | M | (none) | - TBD | | | | | | - TBD | | | | | | - TBD | +---------------+----------------+-----+----------+----------+ | crli (new) | crli | O | (none) | TBD | +---------------+----------------+-----+----------+----------+ | crl (new) | crl | O | (none) | TBD | +---------------+----------------+-----+----------+----------+ | attr | csrattrs | O | (none) | TBD | +---------------+----------------+-----+----------+----------+ | kemc (new) | kemc | O | TBD | TBD | +---------------+----------------+-----+----------+----------+ | sen | simpleenroll | M | TBD | TBD | +---------------+----------------+-----+----------+----------+ | sren | simplereenroll | M | TBD | TBD | +---------------+----------------+-----+----------+----------+ | skc | serverkeygen | O | TBD | TBD | +---------------+----------------+-----+----------+----------+ Figure 2: Operations for EST over CoAP/DTLS Used in This Document (M/O: MANDDATORY / OPTIONAL) 2. Conventions and Definitions The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. The following terms are used in this document: EST client: The entity that contacts the EST server to obtain certificates or CA information, as defined in [RFC7030], Section 1. EST server: The entity that processes EST requests, typically acting as an RA between the EST client and the CA, as defined in [RFC7030], Section 1. CA: Certification Authority. The entity that issues C509 Liao Expires 20 January 2027 [Page 7] Internet-Draft EST-C509 July 2026 certificates. C509 CSR: C509 Certification Request. A CBOR-encoded certification request used by an EST client to request issuance of a C509 certificate. PoP: Proof of Possession. Verification that the requester holds the private key corresponding to the public key in the C509 CSR. 3. Protocol Design 3.1. Client Authentication While [RFC7030] permits a number of the EST functions to be used without authentication, this document requires that the client MUST be authenticated for all functions, as in [RFC9148]. This document require the use of EST to support certificate-based client authentication only, neither HTTP Basic nor Digest authentication (as described in Section 3.2.3 of [RFC7030]) is supported, as in [RFC9148]. 3.2. Discovery and URIs In EST over HTTPS, the capabilities of EST server is retrieved by using the operation caps. In EST over CoAP/DTLS, the capabilities is retrieved by sending a GET method to the EST server (as in Section 4.1 of [RFC9148]) (TODO: the TBD will be replaced with the real value once the Content-Formats are assigned in [I-D.ietf-cose-cbor-encoded-cert] and [I-D.liao-cose-c509-revocation]). Linefeeds are included only for readability. REQ: GET /.well-known/core?rt=ace.est* RES: 2.05 Content ;rt="ace.est.crts";ct="TBD TBD TBD", ;rt="ace.est.sen";ct=TBD, ;rt="ace.est.sren";ct=TBD, ;rt="ace.est.att";ct=TBD, ;rt="ace.est.skc";ct=TBD, ;rt="ace.est.crli";ct=TBD, ;rt="ace.est.crl";ct=TBD, ;rt="ace.est.kemc";ct=TBD7 Liao Expires 20 January 2027 [Page 8] Internet-Draft EST-C509 July 2026 3.3. EST URL Structure and Path Components The operations in this document follow the same URI path structure defined in [RFC7030], Section 3.2.2 for HTTPS and the corresponding secure CoAP mapping defined in [RFC9148]. Retrieval operations caps, cacerts / crts, csrattrs / att, crli, and crl use GET method. Method: GET Request target: /.well-known/est/ Request target: /.well-known/est/