6 ms·
You assume almost correct, the device is the pledge itself! RFC8366 is used (among others) in the BRSKI protocol family. For device attestation purposes in 802.
by selfmodruntime 6mo ago
You assume almost correct, the device is the pledge itself! RFC8366 is used (among others) in the BRSKI protocol family. For device attestation purposes in 802.1x Networks, a pledge comes with a manufacturer provided public key material, often a certificate but not always, that links it to the manufacturer via a publicly available trust root. In an exchange process, the customer - called the registrar in the specification documents - then asks for and verifies the pledge's key material before issuing their own domain certificates.
It's in essence an automated zero-trust-ish protocol for network join purposes :)