%% You should probably cite rfc8995 instead of this I-D. @techreport{ietf-anima-bootstrapping-keyinfra-03, number = {draft-ietf-anima-bootstrapping-keyinfra-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-anima-bootstrapping-keyinfra/03/}, author = {Max Pritikin and Michael Richardson and Michael H. Behringer and Steinthor Bjarnason}, title = {{Bootstrapping Remote Secure Key Infrastructures (BRSKI)}}, pagetotal = 46, year = 2016, month = jun, day = 30, abstract = {This document specifies automated bootstrapping of a remote secure key infrastructure (BRSKI) using vendor installed IEEE 802.1AR manufacturing installed certificates, in combination with a vendor based service on the Internet. Before being authenticated, a new device has only link-local connectivity, and does not require a routable address. When a vendor provides an Internet based service devices can be redirected to a local service. In limited/ disconnected networks or legacy environments we describe a variety of options that allow bootstrapping to proceed. Support for lower security models, including devices with minimal identity, is described for legacy reasons but not encouraged.}, }