I reviewed this draft. The keyprov working group has defined a CMS content type for transporting a symmetric key and related parameters. (That was a big part of why we chartered them) In order to protected these keys, various CMS facilities can be used. This draft describes what algorithms need to be implemented each CMS mode. There were no surprises; this looks fine.