[Anima] I-D Action: draft-ietf-anima-brski-prm-17.txt

internet-drafts@ietf.org Wed, 15 January 2025 15:49 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: anima@ietf.org
Delivered-To: anima@ietfa.amsl.com
Received: from [] (unknown []) by ietfa.amsl.com (Postfix) with ESMTP id 95001C1DC7F5; Wed, 15 Jan 2025 07:49:45 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.32.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <173695618517.802001.14909057366204966305@dt-datatracker-57c4c68d9c-p9khg>
Date: Wed, 15 Jan 2025 07:49:45 -0800
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-anima.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: anima@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: anima@ietf.org
Subject: [Anima] I-D Action: draft-ietf-anima-brski-prm-17.txt
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/0uQR1YfawdMULWWrJTR-AZh0cKM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Owner: <mailto:anima-owner@ietf.org>
List-Post: <mailto:anima@ietf.org>
List-Subscribe: <mailto:anima-join@ietf.org>
List-Unsubscribe: <mailto:anima-leave@ietf.org>

Internet-Draft draft-ietf-anima-brski-prm-17.txt is now available. It is a
work item of the Autonomic Networking Integrated Model and Approach (ANIMA) WG
of the IETF.

   Title:   BRSKI with Pledge in Responder Mode (BRSKI-PRM)
   Authors: Steffen Fries
            Thomas Werner
            Eliot Lear
            Michael C. Richardson
   Name:    draft-ietf-anima-brski-prm-17.txt
   Pages:   116
   Dates:   2025-01-15


   This document defines enhancements to Bootstrapping a Remote Secure
   Key Infrastructure (BRSKI, RFC8995) to enable bootstrapping in
   domains featuring no or only limited connectivity between a pledge
   and the domain registrar.  It specifically changes the interaction
   model from a pledge-initiated mode, as used in BRSKI, to a pledge-
   responding mode, where the pledge is in server role.  For this, BRSKI
   with Pledge in Responder Mode (BRSKI-PRM) introduces new endpoints
   for the Domain Registrar and pledge, and a new component, the
   Registrar-Agent, which facilitates the communication between pledge
   and registrar during the bootstrapping phase.  To establish the trust
   relation between pledge and registrar, BRSKI-PRM relies on object
   security rather than transport security.  The approach defined here
   is agnostic to the enrollment protocol that connects the domain
   registrar to the Key Infrastructure (e.g., domain CA).

The IETF datatracker status page for this Internet-Draft is:

There is also an HTML version available at:

A diff from the previous version is available at:

Internet-Drafts are also available by rsync at: