X.509

X.509 is the ITU-T standard, profiled by IETF in RFC 5280, for the digital certificates that bind a public key to a verified identity. It defines the certificate structure (subject, issuer, validity, extensions), revocation mechanisms (CRL and OCSP), and the chain of trust from a root CA down through intermediates. X.509 underpins TLS/HTTPS, S/MIME email, code signing, mTLS for 5G inter-NF authentication, and SEPP-to-SEPP authentication on the N32 interface.

Categories: SignalingRoaming and InterconnectIdentity and Subscriber

X.509 in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Roaming and interconnect are where two operators exchange signaling and user-plane traffic. Trust boundaries here are the primary attack surface for location tracking, SMS interception and fraud, which is why GSMA now mandates SEPP with PRINS on 5G interconnect.

To place X.509 in the wider telecom-security picture, review Behavioral Signaling Detection, FS.11, GRE, Roaming, Roaming Interconnect Security and Roaming Security Assessment — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.