Re: [Ntp] NTP Security (was NTPv5: big picture)

"Salz, Rich" <rsalz@akamai.com> Mon, 18 January 2021 13:39 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D85CF3A133A for <ntp@ietfa.amsl.com>; Mon, 18 Jan 2021 05:39:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.349
X-Spam-Level:
X-Spam-Status: No, score=-2.349 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.25, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j5sW4gfkcFi1 for <ntp@ietfa.amsl.com>; Mon, 18 Jan 2021 05:39:20 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C876D3A1338 for <ntp@ietf.org>; Mon, 18 Jan 2021 05:39:20 -0800 (PST)
Received: from pps.filterd (m0122331.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 10IDYGfY017270; Mon, 18 Jan 2021 13:39:19 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=0yBTistoKtsuUw2RDvNqqX+HxPre+G5JuBb0BHammP8=; b=Ca84PG9+BacUYvysIXyA05Kp6HoAAJ71m3WlQWxmExHZOFsOBB42s4Ukzj8J0VWuvx34 l5c87ELTQEpOWk9iBjnSpfq16STa/ReKDFCBFVmNa+mx3EWz5bfj99Ox0FYXtW77TtDx YXwft0uPvOjCafRwM1Bz7pgMyyqCqCCequ4NiyBGCeO0fKSQTVgna9U0PFtlxZFSmSF5 E9hgrJtEjFIXriJV2FTuc5j9HP3/AutkcBGfb5BVBJD9vE1p6XrM0m1zgyOxniEOYu6j mhBaY9LmV4K7jRApqzL3a+4e39ohbUN9X9BET5qRsxCsPYtBqWEgcnWf/qYDT+zWAnYo 9w==
Received: from prod-mail-ppoint1 (prod-mail-ppoint1.akamai.com [184.51.33.18] (may be forged)) by mx0b-00190b01.pphosted.com with ESMTP id 363nw3tagf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 18 Jan 2021 13:39:19 +0000
Received: from pps.filterd (prod-mail-ppoint1.akamai.com [127.0.0.1]) by prod-mail-ppoint1.akamai.com (8.16.0.43/8.16.0.43) with SMTP id 10IDY4tt020198; Mon, 18 Jan 2021 08:39:19 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.32]) by prod-mail-ppoint1.akamai.com with ESMTP id 363vc351d3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Mon, 18 Jan 2021 08:39:19 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com (172.27.123.101) by usma1ex-dag1mb4.msg.corp.akamai.com (172.27.123.104) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 18 Jan 2021 08:39:17 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com ([172.27.123.101]) by usma1ex-dag1mb1.msg.corp.akamai.com ([172.27.123.101]) with mapi id 15.00.1497.010; Mon, 18 Jan 2021 08:39:18 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Mark Andrews <marka@isc.org>, Hal Murray <hmurray@megapathdsl.net>
CC: FUSTE Emmanuel <emmanuel.fuste@thalesgroup.com>, "ntp@ietf.org" <ntp@ietf.org>
Thread-Topic: [Ntp] NTP Security (was NTPv5: big picture)
Thread-Index: AQHW7Y5j/zBMZQ9OXEWRsJy/0nNXMqotnK+A///GiAA=
Date: Mon, 18 Jan 2021 13:39:17 +0000
Message-ID: <2C6FDFB3-C9FC-4EC6-8210-04962C08F1B4@akamai.com>
References: <20210118113806.33BBE40605C@ip-64-139-1-69.sjc.megapath.net> <E083B41B-1ADB-482F-8617-B58BC12919BD@isc.org>
In-Reply-To: <E083B41B-1ADB-482F-8617-B58BC12919BD@isc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.45.21011103
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.27.164.43]
Content-Type: text/plain; charset="utf-8"
Content-ID: <8392A29CFE637748A14255F0C7657920@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.343, 18.0.737 definitions=2021-01-18_11:2021-01-18, 2021-01-18 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 phishscore=0 malwarescore=0 bulkscore=0 adultscore=0 spamscore=0 mlxscore=0 mlxlogscore=755 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2101180081
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.343, 18.0.737 definitions=2021-01-18_11:2021-01-18, 2021-01-18 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 mlxlogscore=655 bulkscore=0 clxscore=1011 impostorscore=0 priorityscore=1501 suspectscore=0 lowpriorityscore=0 mlxscore=0 spamscore=0 malwarescore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2101180081
X-Agari-Authentication-Results: mx.akamai.com; spf=${SPFResult} (sender IP is 184.51.33.18) smtp.mailfrom=rsalz@akamai.com smtp.helo=prod-mail-ppoint1
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/Ez0w9tUUuBCyf1f4YwrpPVz4AAw>
Subject: Re: [Ntp] NTP Security (was NTPv5: big picture)
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Jan 2021 13:39:22 -0000

>    A long lived cert is identical to DNSSEC.  The only difference is that DNSSEC uses signature validity periods measured in days rather than years. 

On the Web, cert lifetimes are 825 days.  LetsEncrypt, the largest CA, is 90 days.