Hello all, As announced two weeks ago, we submitted with version 13 (not a lucky number) an intermediate version of BRSKI-PRM, which did not include all of the Changes resulting from the Shepherd review. Due to the two week period in which no updates could be submitted, we submitted the updated the draft to version 14 with the following changes:
- Update of the examples in Appendix A to align with the defined prototypes - Changes incorporated based on Shepherd review PR #133: - Terminology alignment and clarification throughout the document to use terms more consistently - Restructuring of Section 7 for protocol steps to align to the general approach: Overview, data description, CDDL description (if necessary), JWS Header an Signature. This lead to some movement of text between existing and new subsections. - Inclusion of new section on logging hints Section 8 to give recommendations on which events to be logged for auditing - Alignment of pledge status response data across Section 7.6.2.1, Section 7.8.2.1, and Section 7.11.2.1. - Included MASA component in description of affected components in Section 6 - Moved host header field handling from Appendix B to Section 6.2 as generally applicable - Updated status artifacts (vStatus, eStatus, pStatus) to align with BRSKI CDDL definition, but made reason-context mandatory to have distinguishable objects for the registrar-agent - Correction of terminology of local host name vs. service instance name in Section 6.1.2 - Update of informative references and nits This will be the version for discussion in the ANIMA WG session on Friday. Best regards Steffen -----Original Message----- From: [email protected] <[email protected]> Sent: Monday, July 22, 2024 7:40 AM To: Michael C. Richardson <[email protected]>; Eliot Lear <[email protected]>; Michael Richardson <[email protected]>; Fries, Steffen (T CST) <[email protected]>; Werner, Thomas (T CST SEA-DE) <[email protected]> Subject: New Version Notification for draft-ietf-anima-brski-prm-14.txt A new version of Internet-Draft draft-ietf-anima-brski-prm-14.txt has been successfully submitted by Steffen Fries and posted to the IETF repository. Name: draft-ietf-anima-brski-prm Revision: 14 Title: BRSKI with Pledge in Responder Mode (BRSKI-PRM) Date: 2024-07-21 Group: anima Pages: 113 URL: https://www.ietf.org/archive/id/draft-ietf-anima-brski-prm-14.txt Status: https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/ HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-prm Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-anima-brski-prm-14 Abstract: This document defines enhancements to Bootstrapping a Remote Secure Key Infrastructure (BRSKI, RFC8995) to enable bootstrapping in domains featuring no or only limited connectivity between a pledge and the domain registrar. It specifically changes the interaction model from a pledge-initiated mode, as used in BRSKI, to a pledge- responding mode, where the pledge is in server role. For this, BRSKI with Pledge in Responder Mode (BRSKI-PRM) introduces new endpoints for the Domain Registrar and pledge, and a new component, the Registrar-Agent, which facilitates the communication between pledge and registrar during the bootstrapping phase. To establish the trust relation between pledge and registrar, BRSKI-PRM relies on object security rather than transport security. The approach defined here is agnostic to the enrollment protocol that connects the domain registrar to the Key Infrastructure (e.g., domain CA). The IETF Secretariat _______________________________________________ Anima mailing list -- [email protected] To unsubscribe send an email to [email protected]
