%% You should probably cite draft-ietf-anima-brski-prm-12 instead of this revision. @techreport{ietf-anima-brski-prm-07, number = {draft-ietf-anima-brski-prm-07}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/07/}, author = {Steffen Fries and Thomas Werner and Eliot Lear and Michael Richardson}, title = {{BRSKI with Pledge in Responder Mode (BRSKI-PRM)}}, pagetotal = 83, year = 2023, month = feb, day = 21, abstract = {This document defines enhancements to bootstrapping a remote secure key infrastructure (BRSKI, RFC8995) to facilitate bootstrapping in domains featuring no or only time limited connectivity between a pledge and the domain registrar. It specifically targets situations in which the interaction model changes from a pledge-initiated-mode, as used in BRSKI, to a pledge-responding-mode as described in this document. To support the pledge-responding mode, BRSKI-PRM introduces a new component, the registrar-agent, which facilitates the communication between pledge and registrar during the bootstrapping phase. To establish the trust relation between pledge and domain registrar, BRSKI-PRM relies on object security rather than transport security. The approach defined here is agnostic with respect to the underlying enrollment protocol which connects the pledge and the domain registrar to the Domain CA.}, }