Re: [OPSAWG] Benjamin Kaduk's Discuss on draft-ietf-opsawg-finding-geofeeds-12: (with DISCUSS and COMMENT)

"Rob Wilton (rwilton)" <rwilton@cisco.com> Tue, 25 May 2021 11:53 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF7783A0EF3; Tue, 25 May 2021 04:53:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.595
X-Spam-Level:
X-Spam-Status: No, score=-9.595 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=lxLMw4fd; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=q548PSPf
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JKslD94uPYAP; Tue, 25 May 2021 04:53:35 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1C90D3A0F09; Tue, 25 May 2021 04:53:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1853; q=dns/txt; s=iport; t=1621943615; x=1623153215; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=/0fUAHXHu5AuME4EBxWjSBIYB2BxI7yN9D+XpzUbu20=; b=lxLMw4fdP7b9o6wWlGXFoFk5yQ8XtQa2tjEKwIc6Dh3XGWklX98CXLvi 6tAd7Lqb7f7zpp0Tk0yfQzx6WFtB9meJMRP/Vqd129xysqCwgtiNWk8/u B7hJoSAGg+Ppk9NeY6uM/xL/ZL2R6/ov/fhr2XTzPFdU2kr5zbslNz5xD Y=;
IronPort-PHdr: A9a23:y4IpMxcIbslrb2ICSiMoVi3ZlGM/q4qcDmcuAtIPk6lBNK+k+seqME/e4KBri1nEFcXe5ulfguXb+6bnRSQb4JmHvXxDFf4EVxIMhcgM2QB1BsmDBB7jN/GsZCs/T4xOUVZ/9CS9Nk5YUM/1e1zVpCi06jgfUhXyPAZ4PKL7AInX2s+2zOu1vZbUZlYguQ==
IronPort-Data: A9a23:GliOwazB7jRQucH9jTt6t+evxCrEfRIJ4+MujC+fZmUNrF6WrkUPxjceCj2EOf7bMDenfowlb4638kMGvpWDmNYwTVM+rVhgHilAwSbn6Xt1DatR0xt/paQvdWo/hyklQoSGfJpcokP0/E/3a+C89yQkj8lke5KlYAL6EnEpLeNbYH9JZSJLw4bVs6Yw6TSLK1rlVeDa+6UzDGSYNwtcaQr43U4sRCRH55wesBtA1rA3iGsiUFX2zxH5B7pHTU29wueRf2VaIgK6b76rILCR92fd+VImDcmo1++hNEYLWbXVewOJjxK6WYD73UME/XJ0i/19baFAAatUo23hc9RZ0spMsYC3Ty8iP7bHn6IWVBww/yRWbfIep++bfCfv2SCU5wicG5f2+N1pFFo/IoIw++trDydJ7/NwAD8CaziKg+27yqiyUa9rnMtLBMjmJ4w3u3x8w3feF/lOaZfbWKzV6ppT3D4xnNtmHPvCaYweczUHRBjaahNTf1YaFJx7m/+zj2bwNjNZrl6Uo6Vy7GXUwgF83KPFMdfJdJqNX8o9tkWRqn/F12H4HlcXOMH34SCM9H69rvfUkmXwX4d6KVES3paGm3WawmgVTRYRT1b++KP/gU+lUNUZIEsRkhfCZJMarCSDJuQRlTXiyJJcgiMhZg==
IronPort-HdrOrdr: A9a23:wyx7ZaDMkK03JH/lHeh5sceALOsnbusQ8zAXPh9KKCC9I/b3qynxppsmPEfP+UkssHFJo6HmBEDyewKjyXcT2/hRAV7CZniphILMFuFfBOTZskbd8kHFh4tgPOJbAtRD4b7LfBhHZKTBkXOF+r8bqbHtms3F9ISurUuFDzsaFp2IhD0JbDpzZ3cGPDWucqBJbaZ0iPA3wwaISDAyVICWF3MFV+/Mq5ngj5T9eyMLABYh9U2nkS6owKSSKWna4j4uFxd0hZsy+2nMlAL0oo+5teug9xPa32jPq7xLhdrazMdZDsDksLlWFtyssHfsWG1SYczEgNkHmpDo1L/sqqiUn/4UBbU215oWRBDsnfKi4Xi67N9k0Q6S9bbRuwqSnSW+fkNhNyKE7rgpLicwLCEbzYxBOetwrhGknosSAhXakCvn4d/UExlsi0qvuHIn1fUelnpFTOIlGfJsRKEkjQho+a07bWjHAUEcYZ9T5crnlbprmJOhHjjkV0xUsZORt1gIb2O7q3k5y4WoOmJt7QVEJmMjtbsid1k7heAAd6U=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AbAAAF5axg/4YNJK1aDg0BAQEBAQEBAQUBAQESAQEBAwMBAQFAgUMGAQEBCwGBUlEHd1o2MQuIBQOEWWCIbAOaAYEugSUDVAsBAQENAQE1CgIEAQGBGIM4AoF+AiU0CQ4CBAEBARIBAQUBAQECAQYEcROFaA2GRAEBAQQSKAYBATcBCwQCAQgRBAEBHxAyHQgCBAENBQgaglCCVQMvAQMLnEsBgToCih94gTSBAYIHAQEGBASBSEGDNBiCEwMGgToBgnqGcYN5JxyBSUSBFUOCXz6CYgIDgTQrg0uCLYFZcANmJyxPMBlkkW+CfKdaCoMXigqOCIVjEYNbixmWW5U9jBGYCwICAgIEBQIOAQEGgVQ7gVlwFYMkUBcCDo4fDBYVgzmFFIUFRXM4AgYKAQEDCXyGPIE2AYEQAQE
X-IronPort-AV: E=Sophos;i="5.82,328,1613433600"; d="scan'208";a="870784578"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by rcdn-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 25 May 2021 11:53:33 +0000
Received: from mail.cisco.com (xbe-aln-007.cisco.com [173.36.7.22]) by alln-core-12.cisco.com (8.15.2/8.15.2) with ESMTPS id 14PBrXhX006881 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 25 May 2021 11:53:34 GMT
Received: from xfe-rcd-004.cisco.com (173.37.227.252) by xbe-aln-007.cisco.com (173.36.7.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15; Tue, 25 May 2021 06:53:33 -0500
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by xfe-rcd-004.cisco.com (173.37.227.252) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.2.792.15; Tue, 25 May 2021 06:53:32 -0500
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1497.18 via Frontend Transport; Tue, 25 May 2021 07:53:32 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=TrPb9ZGpiD1I/2E4lbnKEUqrjWSvFsLs1RtuJzLXfIfiq9QpD1drGTya0PyFtfFcvPwHXXSR0sp8jU6Dt9QbxQPygziYlW1AQCSL/PzywH2yMpswh1FTtzKYyKfPSivkt/WZagGhhqUln/7j82mz9Ynlza3146XKbOpjj7OsaE7NtWzEBd2LgQVBUIL1smgLnxgY7M8a+NYZV88hSlgIXTA9RHXWufqat48y8rjb3yTQhepBfmsXxwQlW+XlKLNjIGhF6Ydy1iqvUl+I8cN0ly3k5nIz0T6HPtSvDhW5XFrb/dyKGA/4VpK6Xh4cAXbZdj4fP3nHH3O6+80smr+xvA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=azYJ5fSXaQlS+qC1wax380TBvYC9hYnmodqDQrwRYYs=; b=Rmb9Bb032rJu91eiM4tsXcrjyYDgsZ7SKUwSLV51vj6dB73pyyXIondw0QA84VyNzS0WndeyYM+OnLeVBf9pWS7Az8a5uhizgBQ4hLOtyiFZwiKqbWnDsDpGhjMd8CsZCASg48a6INZgNGpG38rIL3zozej7iqAk6P/ouIh3s02JM4T/i5WiMlfXOrXfNaa2FrfFUYsVFMWiGhAHEDjDpiNco5m7w9gvigjB1XiBilrn6nVmlemGj/xeCMfaz5fPMYr6vV3XyyXhItmp79bA7E/WenNSvKDuXsItTImzbzPc8pdeGL6DGxN426Y3esbkQcopfidXsY3fucmKYZmZ2w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=azYJ5fSXaQlS+qC1wax380TBvYC9hYnmodqDQrwRYYs=; b=q548PSPfubEB/YpEnVgFqi1Q1dww71AGpe+P7clvyQ2k8m5jb1xuaPVwmgLhY9WtkcbLMByzSMxdynavUS63iKZ1SlBVBlfeFYN5BGu8rdMijAXB01RZszyIYyepPeI8TS++J7W9pi3jNyLjluq97ncRmUTcZgBzgX2WEp87790=
Received: from MN2PR11MB4366.namprd11.prod.outlook.com (2603:10b6:208:190::17) by MN2PR11MB4535.namprd11.prod.outlook.com (2603:10b6:208:24e::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4173.20; Tue, 25 May 2021 11:53:29 +0000
Received: from MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::217d:4810:6cea:ef72]) by MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::217d:4810:6cea:ef72%6]) with mapi id 15.20.4150.027; Tue, 25 May 2021 11:53:29 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: Randy Bush <randy@psg.com>, Benjamin Kaduk <kaduk@mit.edu>
CC: "draft-ietf-opsawg-finding-geofeeds@ietf.org" <draft-ietf-opsawg-finding-geofeeds@ietf.org>, "opsawg-chairs@ietf.org" <opsawg-chairs@ietf.org>, The IESG <iesg@ietf.org>, "ggm@algebras.org" <ggm@algebras.org>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: Benjamin Kaduk's Discuss on draft-ietf-opsawg-finding-geofeeds-12: (with DISCUSS and COMMENT)
Thread-Index: AQHXTo5uktmdtwAlkU+GR/8GriVgtar0G0LQ
Date: Tue, 25 May 2021 11:53:29 +0000
Message-ID: <MN2PR11MB4366535BB2BA0D39E3B2F3CAB5259@MN2PR11MB4366.namprd11.prod.outlook.com>
References: <162149688912.26611.7060363738222603934@ietfa.amsl.com> <m2h7ivzt0c.wl-randy@psg.com> <20210521214555.GX32395@kduck.mit.edu> <m2cztjzqgq.wl-randy@psg.com>
In-Reply-To: <m2cztjzqgq.wl-randy@psg.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: psg.com; dkim=none (message not signed) header.d=none;psg.com; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [82.12.233.180]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 67d4ca77-0f4b-4e90-65f7-08d91f73b69f
x-ms-traffictypediagnostic: MN2PR11MB4535:
x-microsoft-antispam-prvs: <MN2PR11MB4535D887441D6E12EA45F6ECB5259@MN2PR11MB4535.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: XEcamJTU4P03LTYaU+b8MWdR8IriuWauIC+mQUC3mEbWtmqcIkE4/bkUe7nynC98oJSs+BNKLTSGO/t7nghrsILWAKatJEB+I0JYRz1LtoisLvfmqK/Avy10HEW72tHQiDJ7PVYIczdqMawXo9osN8n8buS8qkxPzefUc2EdqRg1kMMnSgEyW19DnRYhtM5AO1vogcpb5aHunCRQBpbf1T8woU/92xgRnejRWxMajmgjlJd419YOMdcYw7XFM/SNULarbLtLTKPOkMag9kECXR62b0l36dQ14UtFr1Kz/Uksv1cny5n6ixfh4jJHXmNWKlHwdJO4PbgAQa/koOgeoy/iDD/2QBQfD1u4M+fBTjR701zY15EG+3wWH10qoB90w6FDcDlX9qXLy10N9QF1ZFvzHAfwrAfu072gP6/mCp3Z+NsoLFrCKD4/nM/egprggWv9hN5iYhERlZT20AN1RefZ1G/eJWKN+5IqCPRqptEqAbVzYgz5bZ9egn9v1i1pXjlJ1Vz6I4mhLVt0F5QdxptrKcS/+Pu0beYNkw1fDb3bV2n5zQROLhV0bTZjrru0cvi/thTPy83b2Lv8DEprnENYvOHfZZ6Wf/I5Z4+3QrfKW0B9HpnYSEgilxZfQFzimJkfCd6NWluOh2dRUEdAIvgiDW5xPu4rG7KNwGphokMk4TSdg5bv/pHdDdLCjdLwsNjeatvtOKTjJQykJs+OSg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4366.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(346002)(396003)(376002)(39860400002)(366004)(136003)(86362001)(186003)(71200400001)(110136005)(316002)(33656002)(7696005)(26005)(53546011)(6506007)(54906003)(5660300002)(122000001)(38100700002)(55016002)(9686003)(8936002)(8676002)(4326008)(2906002)(76116006)(966005)(52536014)(83380400001)(66556008)(66946007)(64756008)(66476007)(478600001)(66446008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: yL/LOD0VJNtDHAJoMep+YmfBO1tgLQtUWZUNHffn2CleMbmPmTWLU2hQUHAKuyrdl+xzTmBipdqRK7gYb4mPwrKbV6Om7/95lj2eViYo16hRfSd2T3Gp9hflhLxaKQMQzi67+Cqk1x0K7X49xL7ruMEhygw4qZQOU4ySBAj0u6/8ItxAE78JYF1U6i1vUgjw9kyq/sLC9xhnbmwAsQtMBDB+YTkELf+NjR9GlwkvnWsBYePZQ+23mtK5NmiSm4g2bROyAgUPnW/o9ZogEqbeojdFNtjzXRbm48BNv/J2Ur0MbYLXJgpeC9ABLTRGfA/SP5Ps4kfWbmEgJfhZek7RqXCYcOz3NS9jAOmlXlgLYND1TVzFIcwozd7XrGkrK/Q8DZrzncKKjJDBmduiPfeUakZYFfWaRsBgd8pa4nCtnSww0STN0AGj1tBwW+9tcpK7bflk5S1MZxbWonIcUn3hkAtoFzSgEsnopCyKyOKFnjA7eEwR4owmYIinN/BDGpk3Wx8V4onxHxwdol2+zRD6zenS2br0HdJuKEeEeR3zwGfzq1ZJbiO/0cS1iavxcQQH+HEXa57aG2RLhX+cVp0/kdQvFZX5A9u1j91hIZFZHZvOK2JkMJUcr4xQJ0QlIlQfKENSx8rEv2WbWqYbaYCWflyh4rszdr0v4byumW9/pGtlC9bo1Cb7+BHd8abEvAJNhfFutpzGRSAuRPTiTgM+5Jo/k4eEEtqQCa3d5MU1xy0FCnBb5U/Gv6dVcpQj/oodlMNRBrO/eKxT75/dnb8eY1agw0/ObO9CYesN/ivOW5jVOUUhGeQ2ZLZvrkb8wrpWzScbYB7R9N8sLFN0kAZfUSypLaU2zEVJTu+q9qo2OB1AyVzACWI3WMZQR8apNJIftyEyrBnc/f/4lEe4sqR8CVhP92CKkn4sMD544woV99YPUqjiuO28D25QvOBquiXI59SN14l7Amo1p+k1LtUPdPRwwF8UvduIjgahGcovEr5+a88bjH5oOzu+zzNozzypfqjuDMPw4987vSdI5lzpngZeBCWj9jRsuGeUPWPdtZlrGWOB3tV/5DtZioQlAlWJjNAyeWp2R8pizNVBqFpL6F4SmgFymja/nohE0LuzAOxLknyVfdq/7jFTqbSUOpRyjfw0TdHtsGEffLXwVnICCjp/fzvr/rf/dKD093g/q3qwQbqvDZsnN+E+48CTkroTY4YW7EyTU21pqReU0xYElhJOddJujGA0x4ynPxVLse+HOSvrmGN0tPbB7HdELFI5OfRVejoMZj++oNo6Sp7f3iEx5dv89C2ADT0JFax2bDtm4hHKRq5X4fnE73UYiD2p
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR11MB4366.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 67d4ca77-0f4b-4e90-65f7-08d91f73b69f
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 May 2021 11:53:29.3876 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ba4cIjPcw1NKi8EuCrAjysTdJlekU0YceEyLWMw8UuQ+WXlWYZEUq7uGSL9WyzdaHF0mMH/LriLPF2qLzIX4Uw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4535
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.22, xbe-aln-007.cisco.com
X-Outbound-Node: alln-core-12.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/-NhVYM06CGLZl49NptmQkCvO7LY>
Subject: Re: [OPSAWG] Benjamin Kaduk's Discuss on draft-ietf-opsawg-finding-geofeeds-12: (with DISCUSS and COMMENT)
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 May 2021 11:53:40 -0000

Hi Ben,

When you get a chance, please can you check whether -15 is sufficient to clear your discuss.  I think that is the last step to progressing this doc.

https://datatracker.ietf.org/doc/draft-ietf-opsawg-finding-geofeeds/

Regards,
Rob


> -----Original Message-----
> From: iesg <iesg-bounces@ietf.org> On Behalf Of Randy Bush
> Sent: 21 May 2021 23:12
> To: Benjamin Kaduk <kaduk@mit.edu>
> Cc: Benjamin Kaduk via Datatracker <noreply@ietf.org>; draft-ietf-opsawg-
> finding-geofeeds@ietf.org; opsawg-chairs@ietf.org; The IESG
> <iesg@ietf.org>; ggm@algebras.org; opsawg@ietf.org
> Subject: Re: Benjamin Kaduk's Discuss on draft-ietf-opsawg-finding-
> geofeeds-12: (with DISCUSS and COMMENT)
> 
> > If we're going with "[#RPKI Signature] address range MUST match
> [inetnum:
> > followed to get here]", then there are probably a couple places that
> still
> > talk about "covered by" that should catch up.
> 
> don't find any
> 
> what i did find is that i forgot to remove
> 
>          The address range of the signing certificate MUST cover all
> -        prefixes in the geofeed file it signs; and therefore must be
> -        covered by the range of the inetnum:.
> +        prefixes in the geofeed file it signs.
> 
> > We may also need to look more closely at the bits after "# RPKI
> > Signature".  The example uses a CIDR range, but IIRC inetnum: ranges
> > are not limited to CIDR blocks, which would mean we need a story for
> > how to handle non-CIDR blocks.
> 
> ranges are well-defined in rpki, inetnum:, etc.  8805 entries must be
> cidr.
> 
> that an inetnum: or rpki cert range must cover geofeed file prefixes
> seems pretty clear.  but i have tweaked wording a bit.  i can push my
> emacs buffer to id repo, but will wait a bit for other comments.
> 
> randy