From d79b39a306b857fac5587ddd24ec88d685214e02 Mon Sep 17 00:00:00 2001 From: "Dr. David von Oheimb" Date: Tue, 17 Sep 2024 13:11:16 +0200 Subject: [PATCH] version 13 - CI - ietf-draft-files (xml, txt, html, pdf) updated --- draft-ietf-anima-brski-ae.html | 34 +- draft-ietf-anima-brski-ae.txt | 204 +++--- draft-ietf-anima-brski-ae.xml | 1196 ++++++++++++++++---------------- 3 files changed, 723 insertions(+), 711 deletions(-) diff --git a/draft-ietf-anima-brski-ae.html b/draft-ietf-anima-brski-ae.html index 2cd1ae7..f309241 100644 --- a/draft-ietf-anima-brski-ae.html +++ b/draft-ietf-anima-brski-ae.html @@ -1224,7 +1224,7 @@ von Oheimb, et al. -Expires 16 March 2025 +Expires 21 March 2025 [Page] @@ -1237,12 +1237,12 @@
draft-ietf-anima-brski-ae-13
Published:
- +
Intended Status:
Standards Track
Expires:
-
+
Authors:
@@ -1312,7 +1312,7 @@

time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

- This Internet-Draft will expire on 16 March 2025.

+ This Internet-Draft will expire on 21 March 2025.

-
[draft-ietf-anima-brski-discovery]
+
[I-D.ietf-anima-brski-discovery]
-Eckert, T. and E. Dijk, "Discovery for BRSKI variations", Work in Progress, Internet-Draft, draft-ietf-anima-brski-discovery-04 , , <https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04>.
+Eckert, T. T. and E. Dijk, "Discovery for BRSKI variations", Work in Progress, Internet-Draft, draft-ietf-anima-brski-discovery-04, , <https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04>.
[I-D.ietf-anima-constrained-voucher]
@@ -3153,8 +3153,8 @@

Meral Shirazipour (Gen-ART reviewer)

  • -

    Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke -(IESG reviewers)

    +

    Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, +and Éric Vyncke (IESG reviewers)

  • Michael Richardson (ANIMA design team)

    @@ -3198,7 +3198,7 @@

  • Address Roman Danyliw's comments by updating reference
    -I-D.eckert-anima-brski-discovery to draft-ietf-anima-brski-discovery
    and +I-D.eckert-anima-brski-discovery to I-D.ietf-anima-brski-discovery
    and adding Section 8, which refers to the BRSKI privacy considerations.

  • diff --git a/draft-ietf-anima-brski-ae.txt b/draft-ietf-anima-brski-ae.txt index 9d50d91..440019a 100644 --- a/draft-ietf-anima-brski-ae.txt +++ b/draft-ietf-anima-brski-ae.txt @@ -5,8 +5,8 @@ ANIMA WG D. von Oheimb, Ed. Internet-Draft S. Fries Intended status: Standards Track H. Brockhaus -Expires: 16 March 2025 Siemens - 12 September 2024 +Expires: 21 March 2025 Siemens + 17 September 2024 BRSKI-AE: Alternative Enrollment Protocols in BRSKI @@ -53,7 +53,7 @@ Status of This Memo -von Oheimb, et al. Expires 16 March 2025 [Page 1] +von Oheimb, et al. Expires 21 March 2025 [Page 1] Internet-Draft BRSKI-AE September 2024 @@ -68,7 +68,7 @@ Internet-Draft BRSKI-AE September 2024 time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." - This Internet-Draft will expire on 16 March 2025. + This Internet-Draft will expire on 21 March 2025. Copyright Notice @@ -109,7 +109,7 @@ Table of Contents -von Oheimb, et al. Expires 16 March 2025 [Page 2] +von Oheimb, et al. Expires 21 March 2025 [Page 2] Internet-Draft BRSKI-AE September 2024 @@ -144,7 +144,7 @@ Internet-Draft BRSKI-AE September 2024 authentication of the origin of requests and responses independently of message transfer mechanisms. This capability facilitates end-to- end authentication (i.e., end-to-end proof of origin) across multiple - hops and supports the asynchronous operation of certificate + transport hops and supports the asynchronous operation of certificate enrollment. Consequently, this provides architectural flexibility in determining the location and timing for the ultimate authentication and authorization of certification requests, while ensuring that the @@ -165,7 +165,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 3] +von Oheimb, et al. Expires 21 March 2025 [Page 3] Internet-Draft BRSKI-AE September 2024 @@ -185,7 +185,7 @@ Internet-Draft BRSKI-AE September 2024 certificate enrollment through the use of an alternative protocol to EST that: - * Supports end-to-end authentication over multiple hops. + * Supports end-to-end authentication over multiple transport hops. * Facilitates secure message exchange over any type of transfer mechanism, including asynchronous delivery. @@ -221,7 +221,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 4] +von Oheimb, et al. Expires 21 March 2025 [Page 4] Internet-Draft BRSKI-AE September 2024 @@ -247,7 +247,7 @@ Internet-Draft BRSKI-AE September 2024 - The Registration Authority (RA) is not co-located with the registrar and requires end-to-end authentication of requesters, - which EST does not support over multiple hops. + which EST does not support over multiple transport hops. - The RA or Certification Authority (CA) operator mandates auditable proof of origin for Certificate Signing Requests @@ -277,7 +277,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 5] +von Oheimb, et al. Expires 21 March 2025 [Page 5] Internet-Draft BRSKI-AE September 2024 @@ -333,7 +333,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 6] +von Oheimb, et al. Expires 21 March 2025 [Page 6] Internet-Draft BRSKI-AE September 2024 @@ -358,7 +358,7 @@ Internet-Draft BRSKI-AE September 2024 certification response: message providing the answer to a certification request - CMP: Certificate Management Protocol [RFC9480] + CMP: Certificate Management Protocol [RFC4210] [RFC9480] CSR: Certificate Signing Request @@ -389,7 +389,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 7] +von Oheimb, et al. Expires 21 March 2025 [Page 7] Internet-Draft BRSKI-AE September 2024 @@ -414,8 +414,8 @@ Internet-Draft BRSKI-AE September 2024 PKI component is deployed. The target domain may have multiple sites. - synchronous: time-wise uninterrupted delivery of messages, - here between a pledge and a registrar or backend system (e.g., the + synchronous: time-wise uninterrupted delivery of messages, here + between a pledge and a registrar or backend system (e.g., the MASA) target domain: the domain that a pledge is going to be bootstrapped @@ -445,7 +445,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 8] +von Oheimb, et al. Expires 21 March 2025 [Page 8] Internet-Draft BRSKI-AE September 2024 @@ -501,7 +501,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 9] +von Oheimb, et al. Expires 21 March 2025 [Page 9] Internet-Draft BRSKI-AE September 2024 @@ -557,7 +557,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 10] +von Oheimb, et al. Expires 21 March 2025 [Page 10] Internet-Draft BRSKI-AE September 2024 @@ -613,7 +613,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 11] +von Oheimb, et al. Expires 21 March 2025 [Page 11] Internet-Draft BRSKI-AE September 2024 @@ -669,7 +669,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 12] +von Oheimb, et al. Expires 21 March 2025 [Page 12] Internet-Draft BRSKI-AE September 2024 @@ -725,7 +725,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 13] +von Oheimb, et al. Expires 21 March 2025 [Page 13] Internet-Draft BRSKI-AE September 2024 @@ -781,7 +781,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 14] +von Oheimb, et al. Expires 21 March 2025 [Page 14] Internet-Draft BRSKI-AE September 2024 @@ -818,8 +818,8 @@ Internet-Draft BRSKI-AE September 2024 As a more general solution, the BRSKI discovery mechanism can be extended to provide up-front information on the capabilities of - registrars. Future work such as [draft-ietf-anima-brski-discovery] - may provide this. + registrars. For further discussion, see + [I-D.ietf-anima-brski-discovery]. In the absence of such a generally applicable solution, BRSKI-AE deployments may use their particular way of doing discovery. @@ -837,7 +837,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 15] +von Oheimb, et al. Expires 21 March 2025 [Page 15] Internet-Draft BRSKI-AE September 2024 @@ -893,7 +893,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 16] +von Oheimb, et al. Expires 21 March 2025 [Page 16] Internet-Draft BRSKI-AE September 2024 @@ -949,7 +949,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 17] +von Oheimb, et al. Expires 21 March 2025 [Page 17] Internet-Draft BRSKI-AE September 2024 @@ -1005,7 +1005,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 18] +von Oheimb, et al. Expires 21 March 2025 [Page 18] Internet-Draft BRSKI-AE September 2024 @@ -1061,7 +1061,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 19] +von Oheimb, et al. Expires 21 March 2025 [Page 19] Internet-Draft BRSKI-AE September 2024 @@ -1117,7 +1117,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 20] +von Oheimb, et al. Expires 21 March 2025 [Page 20] Internet-Draft BRSKI-AE September 2024 @@ -1173,7 +1173,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 21] +von Oheimb, et al. Expires 21 March 2025 [Page 21] Internet-Draft BRSKI-AE September 2024 @@ -1229,7 +1229,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 22] +von Oheimb, et al. Expires 21 March 2025 [Page 22] Internet-Draft BRSKI-AE September 2024 @@ -1285,7 +1285,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 23] +von Oheimb, et al. Expires 21 March 2025 [Page 23] Internet-Draft BRSKI-AE September 2024 @@ -1341,7 +1341,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 24] +von Oheimb, et al. Expires 21 March 2025 [Page 24] Internet-Draft BRSKI-AE September 2024 @@ -1397,7 +1397,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 25] +von Oheimb, et al. Expires 21 March 2025 [Page 25] Internet-Draft BRSKI-AE September 2024 @@ -1437,10 +1437,10 @@ Internet-Draft BRSKI-AE September 2024 enrollment-protocols-in-brski-00>. Graphics on slide 4 of the status update on the BRSKI-AE draft 04 at IETF 116. - [draft-ietf-anima-brski-discovery] - Eckert, T. and E. Dijk, "Discovery for BRSKI variations", - Work in Progress, Internet-Draft, draft-ietf-anima-brski- - discovery-04 , July 2024, + [I-D.ietf-anima-brski-discovery] + Eckert, T. T. and E. Dijk, "Discovery for BRSKI + variations", Work in Progress, Internet-Draft, draft-ietf- + anima-brski-discovery-04, 25 July 2024, . @@ -1453,7 +1453,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 26] +von Oheimb, et al. Expires 21 March 2025 [Page 26] Internet-Draft BRSKI-AE September 2024 @@ -1509,7 +1509,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 27] +von Oheimb, et al. Expires 21 March 2025 [Page 27] Internet-Draft BRSKI-AE September 2024 @@ -1565,7 +1565,7 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 28] +von Oheimb, et al. Expires 21 March 2025 [Page 28] Internet-Draft BRSKI-AE September 2024 @@ -1621,7 +1621,7 @@ A.2. Building Automation -von Oheimb, et al. Expires 16 March 2025 [Page 29] +von Oheimb, et al. Expires 21 March 2025 [Page 29] Internet-Draft BRSKI-AE September 2024 @@ -1677,7 +1677,7 @@ A.4. Electric Vehicle Charging Infrastructure -von Oheimb, et al. Expires 16 March 2025 [Page 30] +von Oheimb, et al. Expires 21 March 2025 [Page 30] Internet-Draft BRSKI-AE September 2024 @@ -1733,7 +1733,7 @@ Appendix B. History of Changes TBD RFC Editor: please delete -von Oheimb, et al. Expires 16 March 2025 [Page 31] +von Oheimb, et al. Expires 21 March 2025 [Page 31] Internet-Draft BRSKI-AE September 2024 @@ -1772,8 +1772,7 @@ Internet-Draft BRSKI-AE September 2024 communication' and 'synchronous communication' * Address Roman Danyliw's comments by updating reference - I-D.eckert-anima-brski-discovery to draft-ietf-anima-brski- - discovery + I-D.eckert-anima-brski-discovery to I-D.ietf-anima-brski-discovery and adding Section 8, which refers to the BRSKI privacy considerations. @@ -1786,16 +1785,15 @@ Internet-Draft BRSKI-AE September 2024 review, including nits spotted in the Gen-ART review by Meral Shirazipour + IETF draft ae-10 -> ae-11: -von Oheimb, et al. Expires 16 March 2025 [Page 32] +von Oheimb, et al. Expires 21 March 2025 [Page 32] Internet-Draft BRSKI-AE September 2024 - IETF draft ae-10 -> ae-11: - * In response to AD review by Mahesh Jethanandani, - replace most occurrences of 'Note:' by 'Note that' or the like @@ -1842,17 +1840,16 @@ Internet-Draft BRSKI-AE September 2024 * In response to review by Toerless, + - tweak abstract to make meaning of 'alternative enrollment' more + clear -von Oheimb, et al. Expires 16 March 2025 [Page 33] +von Oheimb, et al. Expires 21 March 2025 [Page 33] Internet-Draft BRSKI-AE September 2024 - - tweak abstract to make meaning of 'alternative enrollment' more - clear - - expand on first use not "well-known" abbreviations, such as 'EST', adding also a references on their first use @@ -1897,18 +1894,18 @@ Internet-Draft BRSKI-AE September 2024 * Tweak use of the terms IDevID and LDevID and replace PKI RA/CA by RA/CA + * Add the abbreviation 'LCMPP' for Lightweight CMP Profile to the + terminology section + -von Oheimb, et al. Expires 16 March 2025 [Page 34] +von Oheimb, et al. Expires 21 March 2025 [Page 34] Internet-Draft BRSKI-AE September 2024 - * Add the abbreviation 'LCMPP' for Lightweight CMP Profile to the - terminology section - * State clearly in Section 5.1 that LCMPP is mandatory when using CMP @@ -1953,18 +1950,18 @@ Internet-Draft BRSKI-AE September 2024 - sort out asynchronous vs. offline transfer, off-site vs. backend components + - improve description of CSRs and proof of possession vs. proof + of origin + -von Oheimb, et al. Expires 16 March 2025 [Page 35] +von Oheimb, et al. Expires 21 March 2025 [Page 35] Internet-Draft BRSKI-AE September 2024 - - improve description of CSRs and proof of possession vs. proof - of origin - - clarify that the channel between pledge and registrar is not restricted to TLS, but in connection with constrained BRSKI may also be DTLS. Also move the references to Constrained BRSKI @@ -2009,20 +2006,18 @@ Internet-Draft BRSKI-AE September 2024 offline vs. synchronous message transfer and enrollment, and better differentiation of RA flavors. + - clarify that for transporting certificate enrollment messages + between pledge and registrar, the TLS channel established + between these two (via the join proxy) is used and the + enrollment protocol MUST support this. - -von Oheimb, et al. Expires 16 March 2025 [Page 36] +von Oheimb, et al. Expires 21 March 2025 [Page 36] Internet-Draft BRSKI-AE September 2024 - - clarify that for transporting certificate enrollment messages - between pledge and registrar, the TLS channel established - between these two (via the join proxy) is used and the - enrollment protocol MUST support this. - - clarify that the enrollment protocol chosen between pledge and registrar MUST also be used for the upstream enrollment exchange with the PKI. @@ -2065,21 +2060,20 @@ Internet-Draft BRSKI-AE September 2024 IETF draft ae-01 -> ae-02: + * Architecture: clarify registrar role including RA/LRA/enrollment + proxy + + * CMP: add reference to CoAP Transport for CMPV2 and Constrained + BRSKI -von Oheimb, et al. Expires 16 March 2025 [Page 37] +von Oheimb, et al. Expires 21 March 2025 [Page 37] Internet-Draft BRSKI-AE September 2024 - * Architecture: clarify registrar role including RA/LRA/enrollment - proxy - - * CMP: add reference to CoAP Transport for CMPV2 and Constrained - BRSKI - * Include venue information From IETF draft 05 -> IETF draft ae-01: @@ -2123,17 +2117,18 @@ Internet-Draft BRSKI-AE September 2024 * Added David von Oheimb as co-author. + From IETF draft 02 -> IETF draft 03: + * Housekeeping, deleted open issue regarding YANG voucher-request in + UC2 as voucher-request was enhanced with additional leaf. -von Oheimb, et al. Expires 16 March 2025 [Page 38] - -Internet-Draft BRSKI-AE September 2024 - From IETF draft 02 -> IETF draft 03: - * Housekeeping, deleted open issue regarding YANG voucher-request in - UC2 as voucher-request was enhanced with additional leaf. +von Oheimb, et al. Expires 21 March 2025 [Page 38] + +Internet-Draft BRSKI-AE September 2024 + * Included open issues in YANG model in UC2 regarding assertion value agent-proximity and CSR encapsulation using SZTP sub @@ -2179,16 +2174,18 @@ Internet-Draft BRSKI-AE September 2024 From IETF draft 00 -> IETF draft 01: + * Update of scope in Section 1.1 to include in which the pledge acts + as a server. This is one main motivation for use case 2. -von Oheimb, et al. Expires 16 March 2025 [Page 39] + + + +von Oheimb, et al. Expires 21 March 2025 [Page 39] Internet-Draft BRSKI-AE September 2024 - * Update of scope in Section 1.1 to include in which the pledge acts - as a server. This is one main motivation for use case 2. - * Rework of use case 2 to consider the transport between the pledge and the pledge-agent. Addressed is the TLS channel establishment between the pledge-agent and the pledge as well as the endpoint @@ -2231,23 +2228,20 @@ Internet-Draft BRSKI-AE September 2024 discovery flow from [RFC8995] in Section 4 to avoid doubling or text or inconsistencies. + * Reworked abstract and introduction to be more crisp regarding the + targeted solution. Several structural changes in the document to + have a better distinction between requirements, use case + description, and solution description as separate sections. + History moved to appendix. - - -von Oheimb, et al. Expires 16 March 2025 [Page 40] +von Oheimb, et al. Expires 21 March 2025 [Page 40] Internet-Draft BRSKI-AE September 2024 - * Reworked abstract and introduction to be more crisp regarding the - targeted solution. Several structural changes in the document to - have a better distinction between requirements, use case - description, and solution description as separate sections. - History moved to appendix. - From individual version 02 -> 03: * Update of terminology from self-contained to authenticated self- @@ -2291,16 +2285,19 @@ Internet-Draft BRSKI-AE September 2024 From individual version 00 -> 01: + * Update of examples, specifically for building automation as well + as two new application use cases in Appendix A. -von Oheimb, et al. Expires 16 March 2025 [Page 41] + + + + +von Oheimb, et al. Expires 21 March 2025 [Page 41] Internet-Draft BRSKI-AE September 2024 - * Update of examples, specifically for building automation as well - as two new application use cases in Appendix A. - * Deletion of asynchronous interaction with MASA to not complicate the use case. Note that the voucher exchange can already be handled in an asynchronous manner and is therefore not considered @@ -2349,7 +2346,10 @@ Authors' Addresses -von Oheimb, et al. Expires 16 March 2025 [Page 42] + + + +von Oheimb, et al. Expires 21 March 2025 [Page 42] Internet-Draft BRSKI-AE September 2024 @@ -2405,4 +2405,4 @@ Internet-Draft BRSKI-AE September 2024 -von Oheimb, et al. Expires 16 March 2025 [Page 43] +von Oheimb, et al. Expires 21 March 2025 [Page 43] diff --git a/draft-ietf-anima-brski-ae.xml b/draft-ietf-anima-brski-ae.xml index 9478bee..e043160 100644 --- a/draft-ietf-anima-brski-ae.xml +++ b/draft-ietf-anima-brski-ae.xml @@ -68,7 +68,7 @@ - + This document defines enhancements to the Bootstrapping Remote Secure Key Infrastructure (BRSKI) protocol, known as BRSKI-AE (Alternative Enrollment).
    @@ -108,7 +108,7 @@ ensuring secure and scalable deployment across a range of network environments.< - +
    Introduction @@ -127,7 +127,7 @@ This enhancement of BRSKI is named BRSKI-AE, where AE stands for It allows for the authentication of the origin of requests and responses independently of message transfer mechanisms. This capability facilitates end-to-end authentication -(i.e., end-to-end proof of origin) across multiple hops +(i.e., end-to-end proof of origin) across multiple transport hops and supports the asynchronous operation of certificate enrollment. Consequently, this provides architectural flexibility in determining the location and timing for the ultimate authentication and authorization of certification requests, @@ -157,7 +157,7 @@ On success, it receives the LDevID certificate along with its certificate chain. enrollment through the use of an alternative protocol to EST that: - Supports end-to-end authentication over multiple hops. + Supports end-to-end authentication over multiple transport hops. Facilitates secure message exchange over any type of transfer mechanism, including asynchronous delivery. @@ -206,7 +206,7 @@ certificate enrollment protocol other than EST, such as CMP. for certificate enrollment due to factors such as: The Registration Authority (RA) is not co-located with the registrar and requires end-to-end authentication of requesters, -which EST does not support over multiple hops. +which EST does not support over multiple transport hops. The RA or Certification Authority (CA) operator mandates auditable proof of origin for Certificate Signing Requests (CSRs), which cannot be provided by TLS as it only offers transient source authentication. @@ -314,7 +314,7 @@ received the new certificate and accepted it
  • CMP:
    - Certificate Management Protocol + Certificate Management Protocol
    CSR:
    @@ -387,7 +387,7 @@ is deployed. The target domain may have multiple sites.
    synchronous:
    - time-wise uninterrupted delivery of messages,
    + time-wise uninterrupted delivery of messages, here between a pledge and a registrar or backend system (e.g., the MASA)
    target domain:
    @@ -883,7 +883,7 @@ support the certificate enrollment protocol it expects, such as CMP. As a more general solution, the BRSKI discovery mechanism can be extended to provide up-front information on the capabilities of registrars. -Future work such as may provide this. +For further discussion, see . In the absence of such a generally applicable solution, BRSKI-AE deployments may use their particular way of doing discovery. @@ -1511,8 +1511,8 @@ Barry Leiba (SECdir review), Mahesh Jethanandani (IETF area director), Meral Shirazipour (Gen-ART reviewer), Reshad Rahman (YANGDOCTORS reviewer), -Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke -(IESG reviewers), +Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, +and Éric Vyncke (IESG reviewers), Michael Richardson (ANIMA design team member), as well as Rajeev Ranjan, Rufus Buschart, Andreas Reiter, and Szofia Fazekas-Zisch (Siemens colleagues) @@ -1951,25 +1951,38 @@ for their reviews with suggestions for improvements. - - - Discovery for BRSKI variations - - - - - - - - - + + + + + + Discovery for BRSKI variations + + Futurewei USA + + + IoTconsultancy.nl + + + + This document specifies how BRSKI entities, such as registrars, + proxies, pledges or others that are acting as responders, can be + discovered and selected by BRSKI entities acting as initiators. + + + + + + + + - +
    Application Examples @@ -2099,8 +2112,8 @@ an off-site backend component that has a sufficient level of security. Barry Leiba (SECdir) Mahesh Jethanandani (IETF area director) Meral Shirazipour (Gen-ART reviewer) - Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke -(IESG reviewers) + Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, +and Éric Vyncke (IESG reviewers) Michael Richardson (ANIMA design team) Rajeev Ranjan, Rufus Buschart, Szofia Fazekas-Zisch, etc. (Siemens) Reshad Rahman (YANGDOCTORS reviewer). Note that @@ -2128,7 +2141,7 @@ while keeping the original message, as it helps improve document quality by adapting terminology entries, leaving out 'communication' from 'asynchronous communication' and 'synchronous communication' Address Roman Danyliw's comments by updating reference
    -I-D.eckert-anima-brski-discovery to draft-ietf-anima-brski-discovery
    and +I-D.eckert-anima-brski-discovery to I-D.ietf-anima-brski-discovery
    and adding , which refers to the BRSKI privacy considerations.
    Address Éric Vyncke's comment by replacing 'production' by 'manufacturing' @@ -2497,7 +2510,7 @@ LocalWords: PoP PoI anufacturer uthorized igning uthority SECDIR nbsp passphrase LocalWords: ietf cmp lcmpp submissionType kw std org uri cmpv app sol est Certs LocalWords: github eckert lternative nrollment sec certs reg priv pledge's CMP's LocalWords: Mahesh Jethanandani Gen ART Meral Shirazipour Deb Cooley's -LocalWords: Gunter Van de Velde's Scudder's Kucherawy's Danyliw's Éric Vyncke's +LocalWords: Gunter Van de Velde's Scudder's Kucherawy's Danyliw's Eacute Vyncke's -->
    @@ -2522,571 +2535,570 @@ LocalWords: Gunter Van de Velde's Scudder's Kucherawy's Danyliw's Éric Vyncke's