|
1224 | 1224 | </tr></thead>
|
1225 | 1225 | <tfoot><tr>
|
1226 | 1226 | <td class="left">von Oheimb, et al.</td>
|
1227 |
| -<td class="center">Expires 16 March 2025</td> |
| 1227 | +<td class="center">Expires 21 March 2025</td> |
1228 | 1228 | <td class="right">[Page]</td>
|
1229 | 1229 | </tr></tfoot>
|
1230 | 1230 | </table>
|
|
1237 | 1237 | <dd class="internet-draft">draft-ietf-anima-brski-ae-13</dd>
|
1238 | 1238 | <dt class="label-published">Published:</dt>
|
1239 | 1239 | <dd class="published">
|
1240 |
| -<time datetime="2024-09-12" class="published">12 September 2024</time> |
| 1240 | +<time datetime="2024-09-17" class="published">17 September 2024</time> |
1241 | 1241 | </dd>
|
1242 | 1242 | <dt class="label-intended-status">Intended Status:</dt>
|
1243 | 1243 | <dd class="intended-status">Standards Track</dd>
|
1244 | 1244 | <dt class="label-expires">Expires:</dt>
|
1245 |
| -<dd class="expires"><time datetime="2025-03-16">16 March 2025</time></dd> |
| 1245 | +<dd class="expires"><time datetime="2025-03-21">21 March 2025</time></dd> |
1246 | 1246 | <dt class="label-authors">Authors:</dt>
|
1247 | 1247 | <dd class="authors">
|
1248 | 1248 | <div class="author">
|
@@ -1312,7 +1312,7 @@ <h2 id="name-status-of-this-memo">
|
1312 | 1312 | time. It is inappropriate to use Internet-Drafts as reference
|
1313 | 1313 | material or to cite them other than as "work in progress."<a href="#section-boilerplate.1-3" class="pilcrow">¶</a></p>
|
1314 | 1314 | <p id="section-boilerplate.1-4">
|
1315 |
| - This Internet-Draft will expire on 16 March 2025.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
| 1315 | + This Internet-Draft will expire on 21 March 2025.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
1316 | 1316 | </section>
|
1317 | 1317 | </div>
|
1318 | 1318 | <div id="copyright">
|
@@ -1478,7 +1478,7 @@ <h2 id="name-introduction">
|
1478 | 1478 | It allows for the authentication of the origin of requests and responses
|
1479 | 1479 | independently of message transfer mechanisms.
|
1480 | 1480 | This capability facilitates end-to-end authentication
|
1481 |
| -(i.e., end-to-end proof of origin) across multiple hops |
| 1481 | +(i.e., end-to-end proof of origin) across multiple transport hops |
1482 | 1482 | and supports the asynchronous operation of certificate enrollment. Consequently,
|
1483 | 1483 | this provides architectural flexibility in determining the location and timing
|
1484 | 1484 | for the ultimate authentication and authorization of certification requests,
|
@@ -1511,7 +1511,7 @@ <h2 id="name-introduction">
|
1511 | 1511 | enrollment through the use of an alternative protocol to EST that:<a href="#section-1-5" class="pilcrow">¶</a></p>
|
1512 | 1512 | <ul class="normal">
|
1513 | 1513 | <li class="normal" id="section-1-6.1">
|
1514 |
| - <p id="section-1-6.1.1">Supports end-to-end authentication over multiple hops.<a href="#section-1-6.1.1" class="pilcrow">¶</a></p> |
| 1514 | + <p id="section-1-6.1.1">Supports end-to-end authentication over multiple transport hops.<a href="#section-1-6.1.1" class="pilcrow">¶</a></p> |
1515 | 1515 | </li>
|
1516 | 1516 | <li class="normal" id="section-1-6.2">
|
1517 | 1517 | <p id="section-1-6.2.1">Facilitates secure message exchange over any type of transfer mechanism,
|
@@ -1559,7 +1559,7 @@ <h3 id="name-supported-scenarios">
|
1559 | 1559 | <li class="normal" id="section-1.1-2.2.2.1">
|
1560 | 1560 | <p id="section-1.1-2.2.2.1.1">The Registration Authority (RA) is not co-located with the registrar
|
1561 | 1561 | and requires end-to-end authentication of requesters,
|
1562 |
| -which EST does not support over multiple hops.<a href="#section-1.1-2.2.2.1.1" class="pilcrow">¶</a></p> |
| 1562 | +which EST does not support over multiple transport hops.<a href="#section-1.1-2.2.2.1.1" class="pilcrow">¶</a></p> |
1563 | 1563 | </li>
|
1564 | 1564 | <li class="normal" id="section-1.1-2.2.2.2">
|
1565 | 1565 | <p id="section-1.1-2.2.2.2.1">The RA or Certification Authority (CA) operator mandates
|
@@ -1686,7 +1686,7 @@ <h2 id="name-terminology-and-abbreviatio">
|
1686 | 1686 | <dd class="break"></dd>
|
1687 | 1687 | <dt id="section-2-4.25">CMP:</dt>
|
1688 | 1688 | <dd style="margin-left: 1.5em" id="section-2-4.26">
|
1689 |
| - <p id="section-2-4.26.1">Certificate Management Protocol <span>[<a href="#RFC9480" class="cite xref">RFC9480</a>]</span><a href="#section-2-4.26.1" class="pilcrow">¶</a></p> |
| 1689 | + <p id="section-2-4.26.1">Certificate Management Protocol <span>[<a href="#RFC4210" class="cite xref">RFC4210</a>]</span> <span>[<a href="#RFC9480" class="cite xref">RFC9480</a>]</span><a href="#section-2-4.26.1" class="pilcrow">¶</a></p> |
1690 | 1690 | </dd>
|
1691 | 1691 | <dd class="break"></dd>
|
1692 | 1692 | <dt id="section-2-4.27">CSR:</dt>
|
@@ -1774,7 +1774,7 @@ <h2 id="name-terminology-and-abbreviatio">
|
1774 | 1774 | <dd class="break"></dd>
|
1775 | 1775 | <dt id="section-2-4.55">synchronous:</dt>
|
1776 | 1776 | <dd style="margin-left: 1.5em" id="section-2-4.56">
|
1777 |
| - <p id="section-2-4.56.1">time-wise uninterrupted delivery of messages,<br> |
| 1777 | + <p id="section-2-4.56.1">time-wise uninterrupted delivery of messages, |
1778 | 1778 | here between a pledge and a registrar or backend system (e.g., the MASA)<a href="#section-2-4.56.1" class="pilcrow">¶</a></p>
|
1779 | 1779 | </dd>
|
1780 | 1780 | <dd class="break"></dd>
|
@@ -2256,7 +2256,7 @@ <h4 id="name-pledge-registrar-discovery">
|
2256 | 2256 | support the certificate enrollment protocol it expects, such as CMP.<a href="#section-4.2.1-1" class="pilcrow">¶</a></p>
|
2257 | 2257 | <p id="section-4.2.1-2">As a more general solution, the BRSKI discovery mechanism can be extended
|
2258 | 2258 | to provide up-front information on the capabilities of registrars.
|
2259 |
| -Future work such as <span>[<a href="#draft-ietf-anima-brski-discovery" class="cite xref">draft-ietf-anima-brski-discovery</a>]</span> may provide this.<a href="#section-4.2.1-2" class="pilcrow">¶</a></p> |
| 2259 | +For further discussion, see <span>[<a href="#I-D.ietf-anima-brski-discovery" class="cite xref">I-D.ietf-anima-brski-discovery</a>]</span>.<a href="#section-4.2.1-2" class="pilcrow">¶</a></p> |
2260 | 2260 | <p id="section-4.2.1-3">In the absence of such a generally applicable solution,
|
2261 | 2261 | BRSKI-AE deployments may use their particular way of doing discovery.
|
2262 | 2262 | <a href="#brski-cmp-instance" class="auto internal xref">Section 5.1</a> defines a minimalist approach that <span class="bcp14">MAY</span> be used for CMP.<a href="#section-4.2.1-3" class="pilcrow">¶</a></p>
|
@@ -2850,8 +2850,8 @@ <h2 id="name-acknowledgments">
|
2850 | 2850 | Mahesh Jethanandani (IETF area director),
|
2851 | 2851 | Meral Shirazipour (Gen-ART reviewer),
|
2852 | 2852 | Reshad Rahman (YANGDOCTORS reviewer),
|
2853 |
| -Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke |
2854 |
| -(IESG reviewers), |
| 2853 | +Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, |
| 2854 | +and Éric Vyncke (IESG reviewers), |
2855 | 2855 | Michael Richardson (ANIMA design team member),
|
2856 | 2856 | as well as Rajeev Ranjan, Rufus Buschart,
|
2857 | 2857 | Andreas Reiter, and Szofia Fazekas-Zisch (Siemens colleagues)
|
@@ -2906,9 +2906,9 @@ <h3 id="name-informative-references">
|
2906 | 2906 | <span class="refAuthor">S. Fries</span> and <span class="refAuthor">D. von Oheimb</span>, <span class="refTitle">"BRSKI-AE Protocol Overview"</span>, <time datetime="2023-03" class="refDate">March 2023</time>, <span><<a href="https://datatracker.ietf.org/meeting/116/materials/slides-116-anima-update-on-brski-ae-alternative-enrollment-protocols-in-brski-00">https://datatracker.ietf.org/meeting/116/materials/slides-116-anima-update-on-brski-ae-alternative-enrollment-protocols-in-brski-00</a>></span>. <span class="annotation">Graphics on slide 4 of the status update on the BRSKI-AE draft 04 at IETF 116.</span>
|
2907 | 2907 | </dd>
|
2908 | 2908 | <dd class="break"></dd>
|
2909 |
| -<dt id="draft-ietf-anima-brski-discovery">[draft-ietf-anima-brski-discovery]</dt> |
| 2909 | +<dt id="I-D.ietf-anima-brski-discovery">[I-D.ietf-anima-brski-discovery]</dt> |
2910 | 2910 | <dd>
|
2911 |
| -<span class="refAuthor">Eckert, T.</span> and <span class="refAuthor">E. Dijk</span>, <span class="refTitle">"Discovery for BRSKI variations"</span>, <span class="seriesInfo">Work in Progress, Internet-Draft, draft-ietf-anima-brski-discovery-04 </span>, <time datetime="2024-07" class="refDate">July 2024</time>, <span><<a href="https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04">https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04</a>></span>. </dd> |
| 2911 | +<span class="refAuthor">Eckert, T. T.</span> and <span class="refAuthor">E. Dijk</span>, <span class="refTitle">"Discovery for BRSKI variations"</span>, <span class="refContent">Work in Progress</span>, <span class="seriesInfo">Internet-Draft, draft-ietf-anima-brski-discovery-04</span>, <time datetime="2024-07-25" class="refDate">25 July 2024</time>, <span><<a href="https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04">https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04</a>></span>. </dd> |
2912 | 2912 | <dd class="break"></dd>
|
2913 | 2913 | <dt id="I-D.ietf-anima-constrained-voucher">[I-D.ietf-anima-constrained-voucher]</dt>
|
2914 | 2914 | <dd>
|
@@ -3153,8 +3153,8 @@ <h2 id="name-history-of-changes-tbd-rfc-">
|
3153 | 3153 | <p id="appendix-B-2.4.1">Meral Shirazipour (Gen-ART reviewer)<a href="#appendix-B-2.4.1" class="pilcrow">¶</a></p>
|
3154 | 3154 | </li>
|
3155 | 3155 | <li class="normal" id="appendix-B-2.5">
|
3156 |
| - <p id="appendix-B-2.5.1">Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke |
3157 |
| -(IESG reviewers)<a href="#appendix-B-2.5.1" class="pilcrow">¶</a></p> |
| 3156 | + <p id="appendix-B-2.5.1">Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, |
| 3157 | +and Éric Vyncke (IESG reviewers)<a href="#appendix-B-2.5.1" class="pilcrow">¶</a></p> |
3158 | 3158 | </li>
|
3159 | 3159 | <li class="normal" id="appendix-B-2.6">
|
3160 | 3160 | <p id="appendix-B-2.6.1">Michael Richardson (ANIMA design team)<a href="#appendix-B-2.6.1" class="pilcrow">¶</a></p>
|
@@ -3198,7 +3198,7 @@ <h2 id="name-history-of-changes-tbd-rfc-">
|
3198 | 3198 | </li>
|
3199 | 3199 | <li class="normal" id="appendix-B-4.6">
|
3200 | 3200 | <p id="appendix-B-4.6.1">Address Roman Danyliw's comments by updating reference<br>
|
3201 |
| -I-D.eckert-anima-brski-discovery to draft-ietf-anima-brski-discovery<br> and |
| 3201 | +I-D.eckert-anima-brski-discovery to I-D.ietf-anima-brski-discovery<br> and |
3202 | 3202 | adding <a href="#priv-consider" class="auto internal xref">Section 8</a>, which refers to the BRSKI privacy considerations.<a href="#appendix-B-4.6.1" class="pilcrow">¶</a></p>
|
3203 | 3203 | </li>
|
3204 | 3204 | <li class="normal" id="appendix-B-4.7">
|
|
0 commit comments