Name: draft-bellovin-mandate-keymgmt-01
Title: Guidelines for Mandating Automated Key Management
State: Active
Authors: Steven Bellovin
Group: Individual Submissions (none)
Date: 2004-11-04
The question often arises of whether or not a given security system
requires some form of automated key management, or whether manual keying is
sufficient. This memo proposes guidelines for making such decisions. The
presumption is that when symmetric cryptographic mechanisms are used in a
protocol, then automated key management is generally but not always needed.
If manual keying is proposed, the burden of proving that automated key
management is not required falls to the proposer.
|
|
|