Hello all,

We just posted an updated version of BRSKI-PRM.
The draft  includes several changes resulting specifically from the last part 
of the detailed Shepherd review (big thanks to Matthias), which improved 
structure and readability.

Here is the list of main changes from IETF draft 12 -> IETF draft 13:
- Deleted figure in Section "Request Artifact: Pledge Voucher-Request Trigger 
(tPVR)" for JSON representation of tPVR, as it has been replaced by CDDL
- Updated reason-content description in status response messages 
(enroll-status, voucher-status, and status-response.
- Updated CDDL source code integration to allow for automatic verification
- Reordered description in Section 7.3 and in Section 7.2 to better match the 
order of communication and artifact processing.
- Updated CDDL for the request-enroll trigger in Figure 13 according to the 
outcome of the interim ANIMA WG meeting discussions on April 19, 2024
- Included statement in Section 7.2.2 for using the advanced created-on time 
from the agent-signed-data also for the PER, when the pledge has no 
synchronized clock
- updates examples in Annex 1, 2, 4 to match prototypes
- updated RVR to contain idevid-issuer as described in RFC 8995 in Section 7.3.2

We will provide a status update during the ANIMA WG session of the upcoming 
IETF meeting.

Best regards
Steffen


-----Original Message-----
From: [email protected] <[email protected]>
Sent: Friday, July 5, 2024 1:54 PM
To: Michael C. Richardson <[email protected]>; Eliot Lear <[email protected]>; 
Michael Richardson <[email protected]>; Fries, Steffen (T CST) 
<[email protected]>; Werner, Thomas (T CST SEA-DE) 
<[email protected]>
Subject: New Version Notification for draft-ietf-anima-brski-prm-13.txt

A new version of Internet-Draft draft-ietf-anima-brski-prm-13.txt has been 
successfully submitted by Steffen Fries and posted to the IETF repository.

Name:     draft-ietf-anima-brski-prm
Revision: 13
Title:    BRSKI with Pledge in Responder Mode (BRSKI-PRM)
Date:     2024-07-05
Group:    anima
Pages:    103
URL:      https://www.ietf.org/archive/id/draft-ietf-anima-brski-prm-13.txt
Status:   https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/
HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-prm
Diff:     
https://author-tools.ietf.org/iddiff?url2=draft-ietf-anima-brski-prm-13

Abstract:

   This document defines enhancements to Bootstrapping a Remote Secure
   Key Infrastructure (BRSKI, RFC8995) to enable bootstrapping in
   domains featuring no or only limited connectivity between a pledge
   and the domain registrar.  It specifically changes the interaction
   model from a pledge-initiated mode, as used in BRSKI, to a pledge-
   responding mode, where the pledge is in server role.  For this, BRSKI
   with Pledge in Responder Mode (BRSKI-PRM) introduces a new component,
   the Registrar-Agent, which facilitates the communication between
   pledge and registrar during the bootstrapping phase.  To establish
   the trust relation between pledge and registrar, BRSKI-PRM relies on
   object security rather than transport security.  The approach defined
   here is agnostic to the enrollment protocol that connects the domain
   registrar to the domain CA.



The IETF Secretariat


_______________________________________________
Anima mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to