Hello all, After the Lightweight WGLC ended last week, we incorporated the comments from Brian as already discussed last week. The issue is tracked on the BRSKI-PRM anima git as issue #134to improve the references to BRSKI discovery.
With that the draft is ready for AD review as discussed during IETF 120. Best regards Steffen -----Original Message----- From: [email protected] <[email protected]> Sent: Monday, August 26, 2024 1:43 PM To: Michael C. Richardson <[email protected]>; Eliot Lear <[email protected]>; Michael Richardson <[email protected]>; Fries, Steffen (T CST) <[email protected]>; Werner, Thomas (T CST SEA-DE) <[email protected]> Subject: New Version Notification for draft-ietf-anima-brski-prm-15.txt A new version of Internet-Draft draft-ietf-anima-brski-prm-15.txt has been successfully submitted by Steffen Fries and posted to the IETF repository. Name: draft-ietf-anima-brski-prm Revision: 15 Title: BRSKI with Pledge in Responder Mode (BRSKI-PRM) Date: 2024-08-26 Group: anima Pages: 113 URL: https://www.ietf.org/archive/id/draft-ietf-anima-brski-prm-15.txt Status: https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/ HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-prm Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-anima-brski-prm-15 Abstract: This document defines enhancements to Bootstrapping a Remote Secure Key Infrastructure (BRSKI, RFC8995) to enable bootstrapping in domains featuring no or only limited connectivity between a pledge and the domain registrar. It specifically changes the interaction model from a pledge-initiated mode, as used in BRSKI, to a pledge- responding mode, where the pledge is in server role. For this, BRSKI with Pledge in Responder Mode (BRSKI-PRM) introduces new endpoints for the Domain Registrar and pledge, and a new component, the Registrar-Agent, which facilitates the communication between pledge and registrar during the bootstrapping phase. To establish the trust relation between pledge and registrar, BRSKI-PRM relies on object security rather than transport security. The approach defined here is agnostic to the enrollment protocol that connects the domain registrar to the Key Infrastructure (e.g., domain CA). The IETF Secretariat _______________________________________________ Anima mailing list -- [email protected] To unsubscribe send an email to [email protected]
