BootstrappingImplicit Requirements …. Not necessarily in band Possibility to use out-of-DNS technology Not used to maintain the trust anchor set Note the problem of priming a device that sits in a shrink-wrapped box for a long time before being brought into use with automated (frequent) rollovers any TAs it had will be stale (and therefore dangerous) |