%% You should probably cite rfc9733 instead of this I-D. @techreport{ietf-anima-brski-ae-10, number = {draft-ietf-anima-brski-ae-10}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-anima-brski-ae/10/}, author = {David von Oheimb and Steffen Fries and Hendrik Brockhaus}, title = {{BRSKI-AE: Alternative Enrollment Protocols in BRSKI}}, pagetotal = 41, year = 2024, month = mar, day = 1, abstract = {This document defines an enhancement of Bootstrapping Remote Secure Key Infrastructure (BRSKI, RFC 8995). It supports alternative certificate enrollment protocols, such as CMP, that use authenticated self-contained signed objects for certification messages. This offers the following advantages. The origin of requests and responses can be authenticated independently of message transfer. This supports end-to-end authentication (proof of origin) also over multiple hops, as well as asynchronous operation of certificate enrollment. This in turn provides architectural flexibility where and when to ultimately authenticate and authorize certification requests while retaining full-strength integrity and authenticity of certification requests.}, }