| draft-ietf-sidrops-signed-tal-15.txt | draft-ietf-sidrops-signed-tal-16.txt | |||
|---|---|---|---|---|
| Network Working Group C. Martinez | Network Working Group C. Martinez | |||
| Internet-Draft LACNIC | Internet-Draft LACNIC | |||
| Intended status: Standards Track G. Michaelson | Intended status: Standards Track G. Michaelson | |||
| Expires: 12 October 2024 T. Harrison | Expires: 4 November 2024 T. Harrison | |||
| APNIC | APNIC | |||
| T. Bruijnzeels | T. Bruijnzeels | |||
| RIPE NCC | RIPE NCC | |||
| R. Austein | R. Austein | |||
| Dragon Research Labs | Dragon Research Labs | |||
| 10 April 2024 | 3 May 2024 | |||
| RPKI Signed Object for Trust Anchor Key | RPKI Signed Object for Trust Anchor Key | |||
| draft-ietf-sidrops-signed-tal-15 | draft-ietf-sidrops-signed-tal-16 | |||
| Abstract | Abstract | |||
| A Trust Anchor Locator (TAL) is used by Relying Parties (RPs) in the | A Trust Anchor Locator (TAL) is used by Relying Parties (RPs) in the | |||
| Resource Public Key Infrastructure (RPKI) to locate and validate a | Resource Public Key Infrastructure (RPKI) to locate and validate a | |||
| Trust Anchor (TA) Certification Authority (CA) certificate used in | Trust Anchor (TA) Certification Authority (CA) certificate used in | |||
| RPKI validation. This document defines an RPKI signed object for a | RPKI validation. This document defines an RPKI signed object for a | |||
| Trust Anchor Key (TAK), that can be used by a TA to signal the | Trust Anchor Key (TAK), that can be used by a TA to signal the | |||
| location(s) of the accompanying CA certificate for the current key to | location(s) of the accompanying CA certificate for the current key to | |||
| RPs, as well as the successor key and the location(s) of its CA | RPs, as well as the successor key and the location(s) of its CA | |||
| skipping to change at page 1, line 44 ¶ | skipping to change at page 1, line 44 ¶ | |||
| Internet-Drafts are working documents of the Internet Engineering | Internet-Drafts are working documents of the Internet Engineering | |||
| Task Force (IETF). Note that other groups may also distribute | Task Force (IETF). Note that other groups may also distribute | |||
| working documents as Internet-Drafts. The list of current Internet- | working documents as Internet-Drafts. The list of current Internet- | |||
| Drafts is at https://datatracker.ietf.org/drafts/current/. | Drafts is at https://datatracker.ietf.org/drafts/current/. | |||
| Internet-Drafts are draft documents valid for a maximum of six months | Internet-Drafts are draft documents valid for a maximum of six months | |||
| and may be updated, replaced, or obsoleted by other documents at any | and may be updated, replaced, or obsoleted by other documents at any | |||
| time. It is inappropriate to use Internet-Drafts as reference | time. It is inappropriate to use Internet-Drafts as reference | |||
| material or to cite them other than as "work in progress." | material or to cite them other than as "work in progress." | |||
| This Internet-Draft will expire on 12 October 2024. | This Internet-Draft will expire on 4 November 2024. | |||
| Copyright Notice | Copyright Notice | |||
| Copyright (c) 2024 IETF Trust and the persons identified as the | Copyright (c) 2024 IETF Trust and the persons identified as the | |||
| document authors. All rights reserved. | document authors. All rights reserved. | |||
| This document is subject to BCP 78 and the IETF Trust's Legal | This document is subject to BCP 78 and the IETF Trust's Legal | |||
| Provisions Relating to IETF Documents (https://trustee.ietf.org/ | Provisions Relating to IETF Documents (https://trustee.ietf.org/ | |||
| license-info) in effect on the date of publication of this document. | license-info) in effect on the date of publication of this document. | |||
| Please review these documents carefully, as they describe your rights | Please review these documents carefully, as they describe your rights | |||
| skipping to change at page 2, line 42 ¶ | skipping to change at page 2, line 42 ¶ | |||
| 7.4. Phase 4: Remove Key 'A' . . . . . . . . . . . . . . . . . 12 | 7.4. Phase 4: Remove Key 'A' . . . . . . . . . . . . . . . . . 12 | |||
| 8. Using TAK objects to distribute TAL data . . . . . . . . . . 12 | 8. Using TAK objects to distribute TAL data . . . . . . . . . . 12 | |||
| 9. Deployment Considerations . . . . . . . . . . . . . . . . . . 13 | 9. Deployment Considerations . . . . . . . . . . . . . . . . . . 13 | |||
| 9.1. Relying Party Support . . . . . . . . . . . . . . . . . . 13 | 9.1. Relying Party Support . . . . . . . . . . . . . . . . . . 13 | |||
| 9.2. Alternate Transition Models . . . . . . . . . . . . . . . 13 | 9.2. Alternate Transition Models . . . . . . . . . . . . . . . 13 | |||
| 10. Operational Considerations . . . . . . . . . . . . . . . . . 14 | 10. Operational Considerations . . . . . . . . . . . . . . . . . 14 | |||
| 10.1. Acceptance Timers . . . . . . . . . . . . . . . . . . . 14 | 10.1. Acceptance Timers . . . . . . . . . . . . . . . . . . . 14 | |||
| 11. Security Considerations . . . . . . . . . . . . . . . . . . . 14 | 11. Security Considerations . . . . . . . . . . . . . . . . . . . 14 | |||
| 11.1. Previous Keys . . . . . . . . . . . . . . . . . . . . . 15 | 11.1. Previous Keys . . . . . . . . . . . . . . . . . . . . . 15 | |||
| 11.2. TA Compromise . . . . . . . . . . . . . . . . . . . . . 15 | 11.2. TA Compromise . . . . . . . . . . . . . . . . . . . . . 15 | |||
| 12. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 15 | 11.3. Alternate Transition Models . . . . . . . . . . . . . . 15 | |||
| 12.1. Content Type . . . . . . . . . . . . . . . . . . . . . . 15 | 12. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 16 | |||
| 12.1. Content Type . . . . . . . . . . . . . . . . . . . . . . 16 | ||||
| 12.2. Signed Object . . . . . . . . . . . . . . . . . . . . . 16 | 12.2. Signed Object . . . . . . . . . . . . . . . . . . . . . 16 | |||
| 12.3. File Extension . . . . . . . . . . . . . . . . . . . . . 16 | 12.3. File Extension . . . . . . . . . . . . . . . . . . . . . 16 | |||
| 12.4. Module Identifier . . . . . . . . . . . . . . . . . . . 16 | 12.4. Module Identifier . . . . . . . . . . . . . . . . . . . 17 | |||
| 12.5. Registration of Media Type application/ | 12.5. Registration of Media Type application/ | |||
| rpki-signed-tal . . . . . . . . . . . . . . . . . . . . 16 | rpki-signed-tal . . . . . . . . . . . . . . . . . . . . 17 | |||
| 13. Implementation Status . . . . . . . . . . . . . . . . . . . . 17 | 13. Implementation Status . . . . . . . . . . . . . . . . . . . . 18 | |||
| 13.1. APNIC . . . . . . . . . . . . . . . . . . . . . . . . . 18 | 13.1. APNIC . . . . . . . . . . . . . . . . . . . . . . . . . 19 | |||
| 13.2. rpki-client . . . . . . . . . . . . . . . . . . . . . . 18 | 13.2. rpki-client . . . . . . . . . . . . . . . . . . . . . . 19 | |||
| 13.3. rpki-rs . . . . . . . . . . . . . . . . . . . . . . . . 19 | 13.3. rpki-rs . . . . . . . . . . . . . . . . . . . . . . . . 19 | |||
| 14. Revision History . . . . . . . . . . . . . . . . . . . . . . 20 | ||||
| 14. Revision History . . . . . . . . . . . . . . . . . . . . . . 19 | ||||
| 15. Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . 20 | 15. Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . 20 | |||
| 16. References . . . . . . . . . . . . . . . . . . . . . . . . . 20 | 16. References . . . . . . . . . . . . . . . . . . . . . . . . . 21 | |||
| 16.1. Normative References . . . . . . . . . . . . . . . . . . 20 | 16.1. Normative References . . . . . . . . . . . . . . . . . . 21 | |||
| 16.2. Informative References . . . . . . . . . . . . . . . . . 22 | 16.2. Informative References . . . . . . . . . . . . . . . . . 22 | |||
| Appendix A. ASN.1 Module . . . . . . . . . . . . . . . . . . . . 22 | Appendix A. ASN.1 Module . . . . . . . . . . . . . . . . . . . . 22 | |||
| Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 23 | Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 23 | |||
| 1. Requirements Notation | 1. Requirements Notation | |||
| The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", | The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", | |||
| "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and | "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and | |||
| "OPTIONAL" in this document are to be interpreted as described in BCP | "OPTIONAL" in this document are to be interpreted as described in BCP | |||
| 14 [RFC2119] [RFC8174] when, and only when, they appear in all | 14 [RFC2119] [RFC8174] when, and only when, they appear in all | |||
| skipping to change at page 15, line 31 ¶ | skipping to change at page 15, line 31 ¶ | |||
| mitigate the risk of an adversary gaining access to the key and its | mitigate the risk of an adversary gaining access to the key and its | |||
| associated publication points in order to send invalid/incorrect data | associated publication points in order to send invalid/incorrect data | |||
| to RPs seeded with the TAL data for that key. | to RPs seeded with the TAL data for that key. | |||
| 11.2. TA Compromise | 11.2. TA Compromise | |||
| TAK objects do not offer protection against compromise of the current | TAK objects do not offer protection against compromise of the current | |||
| TA key or the successor TA key. TA key compromise in general is out | TA key or the successor TA key. TA key compromise in general is out | |||
| of scope for this document. | of scope for this document. | |||
| While it is possible for a malicious actor to use TAK objects to | ||||
| cause RPs to transition from the current TA key to a successor TA | ||||
| key, such action is predicated on the malicious actor having | ||||
| compromised the current TA key in the first place, so TAK objects do | ||||
| not alter the security considerations relevant to this scenario. | ||||
| 11.3. Alternate Transition Models | ||||
| Section 9.2 describes other ways in which a TA may transition from | ||||
| one key to another. Transition by way of an in-band process reliant | ||||
| on TAK objects is not mandatory for TAs or RPs, though the fact that | ||||
| the TAK objects are verifiable by way of the currently-trusted TA key | ||||
| is a benefit compared with existing out-of-band mechanisms for TA key | ||||
| distribution. | ||||
| There will be a period of time where both the current key and the | ||||
| successor key are available for use, and RPs that are initialised at | ||||
| different points of the transition process, or from different out-of- | ||||
| band sources, may be using either the current key or the successor | ||||
| key. TAs are required to ensure so far as is possible that for the | ||||
| purposes of RPKI validation, it makes no difference which key is | ||||
| used. | ||||
| 12. IANA Considerations | 12. IANA Considerations | |||
| 12.1. Content Type | 12.1. Content Type | |||
| IANA is asked to register an object identifier for one content type | IANA is asked to register an object identifier for one content type | |||
| in the "SMI Security for S/MIME CMS Content Type | in the "SMI Security for S/MIME CMS Content Type | |||
| (1.2.840.113549.1.9.16.1)" registry as follows: | (1.2.840.113549.1.9.16.1)" registry as follows: | |||
| Decimal | Description | References | Decimal | Description | References | |||
| --------+--------------------------------+--------------- | --------+--------------------------------+--------------- | |||
| skipping to change at page 18, line 36 ¶ | skipping to change at page 19, line 16 ¶ | |||
| * Responsible Organization: Asia-Pacific Network Information Centre | * Responsible Organization: Asia-Pacific Network Information Centre | |||
| * Location: https://github.com/APNIC-net/rpki-signed-tal-demo | * Location: https://github.com/APNIC-net/rpki-signed-tal-demo | |||
| * Description: A proof-of-concept for relying party TAK usage. | * Description: A proof-of-concept for relying party TAK usage. | |||
| * Level of Maturity: This is a proof-of-concept implementation. | * Level of Maturity: This is a proof-of-concept implementation. | |||
| * Coverage: This implementation includes all of the features | * Coverage: This implementation includes all of the features | |||
| described in version 15 of this specification, except for writing | described in version 16 of this specification, except for writing | |||
| TAL files based on TAK data. The repository includes a link to | TAL files based on TAK data. The repository includes a link to | |||
| various test TALs that can be used for testing TAK scenarios, too. | various test TALs that can be used for testing TAK scenarios, too. | |||
| * Contact Information: Tom Harrison, tomh@apnic.net | * Contact Information: Tom Harrison, tomh@apnic.net | |||
| 13.2. rpki-client | 13.2. rpki-client | |||
| * Responsible Organization: Job Snijders, the OpenBSD project | * Responsible Organization: Job Snijders, the OpenBSD project | |||
| * Location: https://www.rpki-client.org | * Location: https://www.rpki-client.org | |||
| skipping to change at page 20, line 15 ¶ | skipping to change at page 20, line 41 ¶ | |||
| 12 - TAK object comments. | 12 - TAK object comments. | |||
| 13 - Removal of compromise text, extra RP support text, key | 13 - Removal of compromise text, extra RP support text, key | |||
| destruction text, media type registration, signed object registry | destruction text, media type registration, signed object registry | |||
| note. | note. | |||
| 14 - Keepalive. | 14 - Keepalive. | |||
| 15 - Additional implementation notes and editorial updates. | 15 - Additional implementation notes and editorial updates. | |||
| 16 - Updates from Secdir review. | ||||
| 15. Acknowledgments | 15. Acknowledgments | |||
| The authors wish to thank Martin Hoffmann for a thorough review of | The authors wish to thank Martin Hoffmann for a thorough review of | |||
| the document, Russ Housley for multiple reviews of the ASN.1 | the document, Russ Housley for multiple reviews of the ASN.1 | |||
| definitions and for providing a new module for the TAK object, Job | definitions and for providing a new module for the TAK object, Job | |||
| Snijders for the extensive suggestions around TAK object structure/ | Snijders for the extensive suggestions around TAK object structure/ | |||
| distribution and rpki-client implementation work, and Ties de Kock | distribution and rpki-client implementation work, and Ties de Kock | |||
| for text/suggestions around TAK/TAL distribution and general security | for text/suggestions around TAK/TAL distribution and general security | |||
| considerations. | considerations. | |||
| End of changes. 12 change blocks. | ||||
| 16 lines changed or deleted | 41 lines changed or added | |||
This html diff was produced by rfcdiff 1.45. The latest version is available from http://tools.ietf.org/tools/rfcdiff/ | ||||