
Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC8995
Discuss this RFC: Send questions or comments to the mailing listanima@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 8995
This document specifies automated bootstrapping of an AutonomicControl Plane. To do this, a Secure Key Infrastructure isbootstrapped. This is done using manufacturer-installed X.509certificates, in combination with a manufacturer's authorizingservice, both online and offline. We call this process theBootstrapping Remote Secure Key Infrastructure (BRSKI) protocol.Bootstrapping a new device can occur when using a routable addressand a cloud service, only link-local connectivity, orlimited/disconnected networks. Support for deployment models withless stringent security requirements is included. Bootstrapping iscomplete when the cryptographic identity of the new keyinfrastructure is successfully deployed to the device. Theestablished secure connection can be used to deploy a locally issuedcertificate to the device as well.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.