Skip to content

CMC Design

Endi S. Dewata edited this page Nov 26, 2025 · 12 revisions

Design

For 10.4, the CMC certificate request mechanism has been updated to conform to RFC 5272 with update from RFC 6402. It does so by adding the following CMC features.

Proof of Origin, Proof of Possession, and Id-POP linking for non-agent users

New (CMC UserSigned / SelfSigned) Authentication Plugin

New Enrollment/Renewal Profiles and corresponding URIs

10.5 update

Configuration

Client changes

Revocation

Shared Secret

Notes

A couple notes:

  • Auditing have been added (not finalized - TBD)

  • CMC controls not mentioned should continue to function as was before

Clone this wiki locally