Re: [GROW] draft-ss-grow-rpki-as-cones-00

Christopher Morrow <christopher.morrow@gmail.com> Wed, 23 May 2018 20:57 UTC

Return-Path: <christopher.morrow@gmail.com>
X-Original-To: grow@ietfa.amsl.com
Delivered-To: grow@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 507A712D7E6 for <grow@ietfa.amsl.com>; Wed, 23 May 2018 13:57:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wo4nAxYiWyO4 for <grow@ietfa.amsl.com>; Wed, 23 May 2018 13:57:10 -0700 (PDT)
Received: from mail-vk0-x22d.google.com (mail-vk0-x22d.google.com [IPv6:2607:f8b0:400c:c05::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D487012E8D5 for <grow@ietf.org>; Wed, 23 May 2018 13:57:09 -0700 (PDT)
Received: by mail-vk0-x22d.google.com with SMTP id x191-v6so14013006vke.10 for <grow@ietf.org>; Wed, 23 May 2018 13:57:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=aEcKrSdM3BQjlz+7XO0R4oGg4BV28/AnFuhNl3X3znA=; b=otr1D8+vXw+LaGWVnBoRG5fDxKykGpD90ENd/p3vRZEcJFJy1LfGGPLjJT4ifNgm3Z pg+BrbthAEKrqr57NlnyhNYNXTFdej/aDp8YO9qlmdcfeSQK2FAN64YRDP+KnIxKuSnF HTxtjS9lqnSwPArN2HdBiN85IgBP/1afpIqUVn9Gb5V5x+52bpzMlxDqVYMzEIg+EWfT 3Y3E7lkaTcd33JAlQwXvy9nyyHUCbXFFBbT3+1sDE3vxfdPXIhsgkXyQogeuqNrYbyRE bROb34bW/+imenKQFWHBh+Gn1IonUMvsAAkGz7uqTV3i4inXDMvUFCsCgGnwmYqrIKdT tg/Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=aEcKrSdM3BQjlz+7XO0R4oGg4BV28/AnFuhNl3X3znA=; b=VZjSg55LFdXloIY8JOLe6gJ3FZPox9n+x/sL0Y90LGTvwmNanHa3DzcpF07YXIMno4 etaFVq1+zyKFGy72vQs2IbXclmYHhxCBBwBb9x+9l67NZ42GLDecpQBPoumGkCOBiwEK MbatNpoPLDZem7cKo/+AlENIh+vTaYNczOLvxxUZ5keRHelu2YhWqrXriLkYPaa5cWzw J/HR4vU4YXX18Opf46GTwJ9cvJqq9J3YAYG5B+q+INTs0f/jgHYTt3a2gXLVwvZYTsHb C/AW/HZNnrxuoAdW1Wu0iAF/xmWvbnzLnh02KiQ6iSzJn5jBaEF0SaqM5B1UZXZEUtHv DpbA==
X-Gm-Message-State: ALKqPweJHK/lSzHH7stEARLzskKeSQ4QLPsDKaNdZrCVZd8qQj6BBEqd FmqH7smuNTuFykdYSCdhiOns+hvLLS3tlbA6lhw+aQ==
X-Google-Smtp-Source: AB8JxZpVr3uOG4qAeitrC6O3FPf+Ixce+0chVD4sFrIHSuE2ThwlPQ7xvBHW2qEz+3yJgHkYwUsVqjKQKqHv40rPOAU=
X-Received: by 2002:a1f:1d4e:: with SMTP id d75-v6mr95484vkd.113.1527109028732; Wed, 23 May 2018 13:57:08 -0700 (PDT)
MIME-Version: 1.0
References: <8c2da168-af67-9463-adbc-d6a0b778f24d@stucchi.ch> <m2tvr0eq0f.wl-randy@psg.com> <20180523134849.GV56139@hanna.meerval.net> <m2h8mybei6.wl-randy@psg.com> <20180523170728.GW73966@vurt.meerval.net> <CAH1iCir7_oddkaeJGJ-qNyUgwumd55R-0AC8CMPrKmNKGiaxqQ@mail.gmail.com> <CACWOCC8NvWZQYN9b1y65C_s4J8VATRWmUkKDR-n8CL9J1QY-_g@mail.gmail.com> <57356A8C-B82D-4084-9BC0-B6F1A23CCCF5@psg.com> <20180523193307.GA73966@vurt.meerval.net> <CAL9jLaZ26ndwX03dnWaYfN5Wr+k6THgEdw-YhGGz3=7zT30i-w@mail.gmail.com> <20180523202625.GB73966@vurt.meerval.net>
In-Reply-To: <20180523202625.GB73966@vurt.meerval.net>
From: Christopher Morrow <christopher.morrow@gmail.com>
Date: Wed, 23 May 2018 16:56:56 -0400
Message-ID: <CAL9jLaavq9ahR0u29SL_j=Bfm1tHbxh3V5Xz=TpeGaS1e_O2+w@mail.gmail.com>
To: Job Snijders <job@ntt.net>
Cc: Randy Bush <randy@psg.com>, "grow@ietf.org grow@ietf.org" <grow@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000030e55f056ce5c7bc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/grow/7LDkYAr1G6590RTxY5IU72rEW-s>
Subject: Re: [GROW] draft-ss-grow-rpki-as-cones-00
X-BeenThere: grow@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Grow Working Group Mailing List <grow.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/grow>, <mailto:grow-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/grow/>
List-Post: <mailto:grow@ietf.org>
List-Help: <mailto:grow-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/grow>, <mailto:grow-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 May 2018 20:57:22 -0000

On Wed, May 23, 2018 at 4:26 PM Job Snijders <job@ntt.net> wrote:

> On Wed, May 23, 2018 at 04:22:06PM -0400, Christopher Morrow wrote:
> > <lurk mode=off>
> >
> > On Wed, May 23, 2018 at 3:33 PM Job Snijders <job@ntt.net> wrote:
> >
> > > The signing AS is saying they created (and named) the list. This
> > > helps resolve various issues, such as "does AS-STEALTH belong to
> > > AS41847 or to AS8002"?
> >
> > wait, they signed this data and put it in their RPKI publication point
> > (for instance - forget that there is no RPKI object type for this), so
> > they 'claimed':
> >   as-set:     AS-STEALTH
> >
> > from which IRR? Or did you mean that they may sign something like:
> >   as-set:     AS-STEALTH@radb
> >
> > but did not sign:
> >   as-set:         AS-STEALTH@RIPE
> >
> > Else we still have confusion, because the MAINT-AS8002 may be upset when
> I
> > only accept AS-SET content from STEALTH-NET-MNT :(
> >
> > -chris
> > (who hopes to one day have better answers for this than: "err, ask the
> > customer / peer which irr they use?"
>
> You are now describing issues of the IRR, I merely used this example to
> illustrate the problem. With AS Cones we can do better. We can structure
> the naming convention for this type of objects.
>
>
ok, cool.


> For instance, for an AS Cone named "AS15562:AS-SNIJDERS" - we can
> structure it in such a way that only the CA Holder of the cert related
> to AS 15562 can sign "AS15562:AS-SNIJDERS". Earlier in the thread I used
> the term 'namespace'.
>
>
ok, my misunderstanding perhaps :) Oh, so: "like as-set, not as-set
exactly".


> Kind regards,
>
> Job
>