RFC 9733: BRSKI with Alternative Enrollment (BRSKI-AE)
In plain English — editorial summary, not part of the RFC
This document defines enhancements to the Bootstrapping Remote Secure Key Infrastructure (BRSKI) protocol, known as BRSKI with Alternative Enrollment (BRSKI-AE). BRSKI-AE extends BRSKI to support certificate enrollment mechanisms instead of the originally specified use of Enrollment over Secure Transport (EST). It supports certificate enrollment protocols such as the Certificate Management Protocol (CMP) that use authenticated self-contained signed objects for certification messages, allowing for flexibility in network device onboarding scenarios. The enhancements address use cases where the existing enrollment mechanism may not be feasible or optimal, providing a framework for integrating suitable alternative enrollment protocols. This document also updates the BRSKI reference architecture to accommodate these alternative methods, ensuring secure and scalable deployment across a range of network environments.
Document record
- Document ID
- RFC9733
- Published
- March 2025
- Authors
- D. von Oheimb; S. Fries; H. Brockhaus
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 27
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9646Conveying a Certificate Signing Request (CSR) in a Secure Zero-Touch Provisioning (SZTP) Bootstrapping RequestCurrent
October 2024
- RFC 8994An Autonomic Control Plane (ACP)Current
May 2021
- RFC 7548Management of Networks with Constrained Devices: Use CasesCurrent
May 2015
- RFC 7547Management of Networks with Constrained Devices: Problem Statement and RequirementsCurrent
May 2015
- RFC 9770Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
June 2025
- RFC 9810Internet X.509 Public Key Infrastructure -- Certificate Management Protocol (CMP)Current
July 2025
- RFC 9811Internet X.509 Public Key Infrastructure -- HTTP Transfer for the Certificate Management Protocol (CMP)Current
July 2025
- RFC 9820Authentication Service Based on the Extensible Authentication Protocol (EAP) for Use with the Constrained Application Protocol (CoAP)Current
September 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?