@techreport{erb-lurk-rsalg-01, number = {draft-erb-lurk-rsalg-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-erb-lurk-rsalg/01/}, author = {Samuel Erb and Rich Salz}, title = {{A PFS-preserving protocol for LURK}}, pagetotal = 10, year = 2016, month = may, day = 28, abstract = {This document defines a protocol between a content provider and an external key owner that enables the provider to act as a TLS termination end-point for the key owner, without having the key actually being provisioned at the provider. The protocol between the two preserves forward secrecy, and is also designed to prevent the use of the key owner as a general-purpose signing oracle which would make it complicit in attacks against uses of the very keys it is trying to protect.}, }