%% You should probably cite draft-ietf-anima-brski-prm-12 instead of this revision. @techreport{ietf-anima-brski-prm-00, number = {draft-ietf-anima-brski-prm-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/00/}, author = {Steffen Fries and Thomas Werner and Eliot Lear and Michael Richardson}, title = {{BRSKI with Pledge in Responder Mode (BRSKI-PRM)}}, pagetotal = 46, year = 2021, month = oct, day = 25, abstract = {This document defines enhancements to the bootstrapping a remote secure key infrastructure (BRSKI, {[}RFC8995{]} ) to facilitate bootstrapping in domains featuring no or only timely limited connectivity between a pledge and the domain registrar. This specifically targets situations, in which the interaction model changes from a pledge-initiator-mode as in BRSKI to a pledge- responder-mode as desribed here. To support this functionality BRSKI-PRM introduces a new registrar-agent component, which facilitates the communication between pledge and registrar during the bootstrapping phase. To support the establishment of a trust relation between a pledge and the domain registrar, BRSKI-PRM relies on the exchange of authenticated self-contained objects (signature- wrapped objects). The defined approach is agnostic regarding the utilized enrollment protocol, deployed by the registrar to communicate with the Domain CA.}, }