|
1224 | 1224 | </tr></thead> |
1225 | 1225 | <tfoot><tr> |
1226 | 1226 | <td class="left">von Oheimb, et al.</td> |
1227 | | -<td class="center">Expires 16 March 2025</td> |
| 1227 | +<td class="center">Expires 21 March 2025</td> |
1228 | 1228 | <td class="right">[Page]</td> |
1229 | 1229 | </tr></tfoot> |
1230 | 1230 | </table> |
|
1237 | 1237 | <dd class="internet-draft">draft-ietf-anima-brski-ae-13</dd> |
1238 | 1238 | <dt class="label-published">Published:</dt> |
1239 | 1239 | <dd class="published"> |
1240 | | -<time datetime="2024-09-12" class="published">12 September 2024</time> |
| 1240 | +<time datetime="2024-09-17" class="published">17 September 2024</time> |
1241 | 1241 | </dd> |
1242 | 1242 | <dt class="label-intended-status">Intended Status:</dt> |
1243 | 1243 | <dd class="intended-status">Standards Track</dd> |
1244 | 1244 | <dt class="label-expires">Expires:</dt> |
1245 | | -<dd class="expires"><time datetime="2025-03-16">16 March 2025</time></dd> |
| 1245 | +<dd class="expires"><time datetime="2025-03-21">21 March 2025</time></dd> |
1246 | 1246 | <dt class="label-authors">Authors:</dt> |
1247 | 1247 | <dd class="authors"> |
1248 | 1248 | <div class="author"> |
@@ -1312,7 +1312,7 @@ <h2 id="name-status-of-this-memo"> |
1312 | 1312 | time. It is inappropriate to use Internet-Drafts as reference |
1313 | 1313 | material or to cite them other than as "work in progress."<a href="#section-boilerplate.1-3" class="pilcrow">¶</a></p> |
1314 | 1314 | <p id="section-boilerplate.1-4"> |
1315 | | - This Internet-Draft will expire on 16 March 2025.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
| 1315 | + This Internet-Draft will expire on 21 March 2025.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
1316 | 1316 | </section> |
1317 | 1317 | </div> |
1318 | 1318 | <div id="copyright"> |
@@ -1478,7 +1478,7 @@ <h2 id="name-introduction"> |
1478 | 1478 | It allows for the authentication of the origin of requests and responses |
1479 | 1479 | independently of message transfer mechanisms. |
1480 | 1480 | This capability facilitates end-to-end authentication |
1481 | | -(i.e., end-to-end proof of origin) across multiple hops |
| 1481 | +(i.e., end-to-end proof of origin) across multiple transport hops |
1482 | 1482 | and supports the asynchronous operation of certificate enrollment. Consequently, |
1483 | 1483 | this provides architectural flexibility in determining the location and timing |
1484 | 1484 | for the ultimate authentication and authorization of certification requests, |
@@ -1511,7 +1511,7 @@ <h2 id="name-introduction"> |
1511 | 1511 | enrollment through the use of an alternative protocol to EST that:<a href="#section-1-5" class="pilcrow">¶</a></p> |
1512 | 1512 | <ul class="normal"> |
1513 | 1513 | <li class="normal" id="section-1-6.1"> |
1514 | | - <p id="section-1-6.1.1">Supports end-to-end authentication over multiple hops.<a href="#section-1-6.1.1" class="pilcrow">¶</a></p> |
| 1514 | + <p id="section-1-6.1.1">Supports end-to-end authentication over multiple transport hops.<a href="#section-1-6.1.1" class="pilcrow">¶</a></p> |
1515 | 1515 | </li> |
1516 | 1516 | <li class="normal" id="section-1-6.2"> |
1517 | 1517 | <p id="section-1-6.2.1">Facilitates secure message exchange over any type of transfer mechanism, |
@@ -1559,7 +1559,7 @@ <h3 id="name-supported-scenarios"> |
1559 | 1559 | <li class="normal" id="section-1.1-2.2.2.1"> |
1560 | 1560 | <p id="section-1.1-2.2.2.1.1">The Registration Authority (RA) is not co-located with the registrar |
1561 | 1561 | and requires end-to-end authentication of requesters, |
1562 | | -which EST does not support over multiple hops.<a href="#section-1.1-2.2.2.1.1" class="pilcrow">¶</a></p> |
| 1562 | +which EST does not support over multiple transport hops.<a href="#section-1.1-2.2.2.1.1" class="pilcrow">¶</a></p> |
1563 | 1563 | </li> |
1564 | 1564 | <li class="normal" id="section-1.1-2.2.2.2"> |
1565 | 1565 | <p id="section-1.1-2.2.2.2.1">The RA or Certification Authority (CA) operator mandates |
@@ -1686,7 +1686,7 @@ <h2 id="name-terminology-and-abbreviatio"> |
1686 | 1686 | <dd class="break"></dd> |
1687 | 1687 | <dt id="section-2-4.25">CMP:</dt> |
1688 | 1688 | <dd style="margin-left: 1.5em" id="section-2-4.26"> |
1689 | | - <p id="section-2-4.26.1">Certificate Management Protocol <span>[<a href="#RFC9480" class="cite xref">RFC9480</a>]</span><a href="#section-2-4.26.1" class="pilcrow">¶</a></p> |
| 1689 | + <p id="section-2-4.26.1">Certificate Management Protocol <span>[<a href="#RFC4210" class="cite xref">RFC4210</a>]</span> <span>[<a href="#RFC9480" class="cite xref">RFC9480</a>]</span><a href="#section-2-4.26.1" class="pilcrow">¶</a></p> |
1690 | 1690 | </dd> |
1691 | 1691 | <dd class="break"></dd> |
1692 | 1692 | <dt id="section-2-4.27">CSR:</dt> |
@@ -1774,7 +1774,7 @@ <h2 id="name-terminology-and-abbreviatio"> |
1774 | 1774 | <dd class="break"></dd> |
1775 | 1775 | <dt id="section-2-4.55">synchronous:</dt> |
1776 | 1776 | <dd style="margin-left: 1.5em" id="section-2-4.56"> |
1777 | | - <p id="section-2-4.56.1">time-wise uninterrupted delivery of messages,<br> |
| 1777 | + <p id="section-2-4.56.1">time-wise uninterrupted delivery of messages, |
1778 | 1778 | here between a pledge and a registrar or backend system (e.g., the MASA)<a href="#section-2-4.56.1" class="pilcrow">¶</a></p> |
1779 | 1779 | </dd> |
1780 | 1780 | <dd class="break"></dd> |
@@ -2256,7 +2256,7 @@ <h4 id="name-pledge-registrar-discovery"> |
2256 | 2256 | support the certificate enrollment protocol it expects, such as CMP.<a href="#section-4.2.1-1" class="pilcrow">¶</a></p> |
2257 | 2257 | <p id="section-4.2.1-2">As a more general solution, the BRSKI discovery mechanism can be extended |
2258 | 2258 | to provide up-front information on the capabilities of registrars. |
2259 | | -Future work such as <span>[<a href="#draft-ietf-anima-brski-discovery" class="cite xref">draft-ietf-anima-brski-discovery</a>]</span> may provide this.<a href="#section-4.2.1-2" class="pilcrow">¶</a></p> |
| 2259 | +For further discussion, see <span>[<a href="#I-D.ietf-anima-brski-discovery" class="cite xref">I-D.ietf-anima-brski-discovery</a>]</span>.<a href="#section-4.2.1-2" class="pilcrow">¶</a></p> |
2260 | 2260 | <p id="section-4.2.1-3">In the absence of such a generally applicable solution, |
2261 | 2261 | BRSKI-AE deployments may use their particular way of doing discovery. |
2262 | 2262 | <a href="#brski-cmp-instance" class="auto internal xref">Section 5.1</a> defines a minimalist approach that <span class="bcp14">MAY</span> be used for CMP.<a href="#section-4.2.1-3" class="pilcrow">¶</a></p> |
@@ -2850,8 +2850,8 @@ <h2 id="name-acknowledgments"> |
2850 | 2850 | Mahesh Jethanandani (IETF area director), |
2851 | 2851 | Meral Shirazipour (Gen-ART reviewer), |
2852 | 2852 | Reshad Rahman (YANGDOCTORS reviewer), |
2853 | | -Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke |
2854 | | -(IESG reviewers), |
| 2853 | +Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, |
| 2854 | +and Éric Vyncke (IESG reviewers), |
2855 | 2855 | Michael Richardson (ANIMA design team member), |
2856 | 2856 | as well as Rajeev Ranjan, Rufus Buschart, |
2857 | 2857 | Andreas Reiter, and Szofia Fazekas-Zisch (Siemens colleagues) |
@@ -2906,9 +2906,9 @@ <h3 id="name-informative-references"> |
2906 | 2906 | <span class="refAuthor">S. Fries</span> and <span class="refAuthor">D. von Oheimb</span>, <span class="refTitle">"BRSKI-AE Protocol Overview"</span>, <time datetime="2023-03" class="refDate">March 2023</time>, <span><<a href="https://datatracker.ietf.org/meeting/116/materials/slides-116-anima-update-on-brski-ae-alternative-enrollment-protocols-in-brski-00">https://datatracker.ietf.org/meeting/116/materials/slides-116-anima-update-on-brski-ae-alternative-enrollment-protocols-in-brski-00</a>></span>. <span class="annotation">Graphics on slide 4 of the status update on the BRSKI-AE draft 04 at IETF 116.</span> |
2907 | 2907 | </dd> |
2908 | 2908 | <dd class="break"></dd> |
2909 | | -<dt id="draft-ietf-anima-brski-discovery">[draft-ietf-anima-brski-discovery]</dt> |
| 2909 | +<dt id="I-D.ietf-anima-brski-discovery">[I-D.ietf-anima-brski-discovery]</dt> |
2910 | 2910 | <dd> |
2911 | | -<span class="refAuthor">Eckert, T.</span> and <span class="refAuthor">E. Dijk</span>, <span class="refTitle">"Discovery for BRSKI variations"</span>, <span class="seriesInfo">Work in Progress, Internet-Draft, draft-ietf-anima-brski-discovery-04 </span>, <time datetime="2024-07" class="refDate">July 2024</time>, <span><<a href="https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04">https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04</a>></span>. </dd> |
| 2911 | +<span class="refAuthor">Eckert, T. T.</span> and <span class="refAuthor">E. Dijk</span>, <span class="refTitle">"Discovery for BRSKI variations"</span>, <span class="refContent">Work in Progress</span>, <span class="seriesInfo">Internet-Draft, draft-ietf-anima-brski-discovery-04</span>, <time datetime="2024-07-25" class="refDate">25 July 2024</time>, <span><<a href="https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04">https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-discovery-04</a>></span>. </dd> |
2912 | 2912 | <dd class="break"></dd> |
2913 | 2913 | <dt id="I-D.ietf-anima-constrained-voucher">[I-D.ietf-anima-constrained-voucher]</dt> |
2914 | 2914 | <dd> |
@@ -3153,8 +3153,8 @@ <h2 id="name-history-of-changes-tbd-rfc-"> |
3153 | 3153 | <p id="appendix-B-2.4.1">Meral Shirazipour (Gen-ART reviewer)<a href="#appendix-B-2.4.1" class="pilcrow">¶</a></p> |
3154 | 3154 | </li> |
3155 | 3155 | <li class="normal" id="appendix-B-2.5"> |
3156 | | - <p id="appendix-B-2.5.1">Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, and Éric Vyncke |
3157 | | -(IESG reviewers)<a href="#appendix-B-2.5.1" class="pilcrow">¶</a></p> |
| 3156 | + <p id="appendix-B-2.5.1">Deb Cooley, Gunter Van de Velde, John Scudder, Murray Kucherawy, Roman Danyliw, |
| 3157 | +and Éric Vyncke (IESG reviewers)<a href="#appendix-B-2.5.1" class="pilcrow">¶</a></p> |
3158 | 3158 | </li> |
3159 | 3159 | <li class="normal" id="appendix-B-2.6"> |
3160 | 3160 | <p id="appendix-B-2.6.1">Michael Richardson (ANIMA design team)<a href="#appendix-B-2.6.1" class="pilcrow">¶</a></p> |
@@ -3198,7 +3198,7 @@ <h2 id="name-history-of-changes-tbd-rfc-"> |
3198 | 3198 | </li> |
3199 | 3199 | <li class="normal" id="appendix-B-4.6"> |
3200 | 3200 | <p id="appendix-B-4.6.1">Address Roman Danyliw's comments by updating reference<br> |
3201 | | -I-D.eckert-anima-brski-discovery to draft-ietf-anima-brski-discovery<br> and |
| 3201 | +I-D.eckert-anima-brski-discovery to I-D.ietf-anima-brski-discovery<br> and |
3202 | 3202 | adding <a href="#priv-consider" class="auto internal xref">Section 8</a>, which refers to the BRSKI privacy considerations.<a href="#appendix-B-4.6.1" class="pilcrow">¶</a></p> |
3203 | 3203 | </li> |
3204 | 3204 | <li class="normal" id="appendix-B-4.7"> |
|
0 commit comments