RFC 2797:Certificate Management Messages over CMS
RFC-Ref

CMC


Click on the red underlined text to get to the source

... subject may be encoded as NULL, but MUST be present. - In general, when both CRMF and CMC controls exist with equivalent functionality, the CMC control SHOULD be used. The CMC ...
... CRMF and CMC controls exist with equivalent functionality, the CMC control SHOULD be used. The CMC control MUST override any CRMF ...
... CMC controls exist with equivalent functionality, the CMC control SHOULD be used. The CMC control MUST override any CRMF control. ...
... CMC compliant implementations MUST support section 5 of [DH-POP]. ...
... CMC compliant implementations MAY support section 4 of [DH-POP]. ...
... PKIResponse object. Body Part Identifiers can be duplicated in different layers (for example a CMC message embedded within another). The Body Part Id of zero is reserved to designate the current PKIData object. This value is used in control attributes such as the Add ...
... request in the current PKIData object. Some control attribute, such as the CMC Status Info attribute, will also use Body Part Identifiers to refer to elements ...


... CMC Status Info Control Attribute ...
... The CMC status info control is used in full PKI Response messages to return information on a client request ...
... return information on a client request. Servers MAY emit multiple CMC status info controls referring to a single body part. Clients MUST be able to deal with multiple CMC ...
... CMC status info controls referring to a single body part. Clients MUST be able to deal with multiple CMC status info controls in a response message. This statement uses the following ASN.1 definition ...
... queried about the status of the request. If the cMCStatus field is success, the CMC Status Info Control MAY be omitted unless it is only item in the response message. If no status ...
... identity proof. CMC provides one method of proving the client's identity ...
... available. The CMC method starts with an out-of-band ...
... certificate request. CMC defines two different attributes. The first deals with the encrypted challenge sent from the server to the user in step 2. The ...


... content-type application/pkcs7-mime. The smime-type parameter MUST be included with a value of "CMC-enroll". A file name with the ".p7m" extension MUST be specified as part of the content-type or content-disposition ...
... content-type application/pkcs7-mime. The smime-type parameter MUST be included with a value of "CMC-response." A file name with the ".p7m" extensions MUST be specified as part of the content-type or content- ...
... PKI request) application/pkcs7-mime .p7m CMC-request (full PKI request) ...
... PKI response) application/pkcs7-mime .p7m CMC-response (full PKI response) ...


... CMC clients and servers MUST be capable of producing and processing message signatures ...
... PKIXCERT]). CMC clients and servers MUST be capable of protecting and accessing message encryption ...
... A minimally compliant CMC server: a) MUST accept a Full PKI ...
... Enrollment Response whenever possible.) A minimally-complaint CMC client: ...


... attack is provided in [X942]. CMC implementations ought to be aware of this attack when doing parameter validations ...


... id-cmc OBJECT IDENTIFIER ::= {id-pkix 7} -- CMC controls id-cct OBJECT IDENTIFIER ::= {id-pkix 12} -- CMC ...
... CMC controls id-cct OBJECT IDENTIFIER ::= {id-pkix 12} -- CMC content types ...



Google
Web
RFC-Ref