Re: [sidr] I-D Action: draft-ietf-sidr-rtr-keying-05.txt

"George, Wes" <wesley.george@twcable.com> Wed, 30 April 2014 20:26 UTC

Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B3C91A0973 for <sidr@ietfa.amsl.com>; Wed, 30 Apr 2014 13:26:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.116
X-Spam-Level:
X-Spam-Status: No, score=-1.116 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_MODEMCABLE=0.768, HOST_EQ_MODEMCABLE=1.368, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OmCy9MtAvcMG for <sidr@ietfa.amsl.com>; Wed, 30 Apr 2014 13:26:28 -0700 (PDT)
Received: from cdpipgw01.twcable.com (cdpipgw01.twcable.com [165.237.59.22]) by ietfa.amsl.com (Postfix) with ESMTP id 243431A8893 for <sidr@ietf.org>; Wed, 30 Apr 2014 13:26:28 -0700 (PDT)
X-SENDER-IP: 10.136.163.11
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="4.97,960,1389762000"; d="scan'208";a="293627706"
Received: from unknown (HELO PRVPEXHUB02.corp.twcable.com) ([10.136.163.11]) by cdpipgw01.twcable.com with ESMTP/TLS/RC4-MD5; 30 Apr 2014 16:25:54 -0400
Received: from PRVPEXVS15.corp.twcable.com ([10.136.163.79]) by PRVPEXHUB02.corp.twcable.com ([10.136.163.11]) with mapi; Wed, 30 Apr 2014 16:26:18 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: Sean Turner <TurnerS@ieca.com>, "sidr@ietf.org" <sidr@ietf.org>
Date: Wed, 30 Apr 2014 16:26:17 -0400
Thread-Topic: [sidr] I-D Action: draft-ietf-sidr-rtr-keying-05.txt
Thread-Index: Ac9ksnC9tWu1xSnlT4+RfZqPCEF2KA==
Message-ID: <CF86D3BA.1A323%wesley.george@twcable.com>
References: <20140429141007.21954.23015.idtracker@ietfa.amsl.com> <99F6C803-C724-430F-AF95-461CBE778C05@ieca.com>
In-Reply-To: <99F6C803-C724-430F-AF95-461CBE778C05@ieca.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.4.1.140326
acceptlanguage: en-US
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/sidr/7fWtPlgDtfT5iQUshTreR3oJxPw
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rtr-keying-05.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Apr 2014 20:26:30 -0000

This update address my comments on the document, and I think it’s in good
shape now. The new section 4 is really good. The one thing I might
recommend adding for completeness is a few additional words around
revocation process at the end of section 4, specifically if there is any
difference or recommendation in process for make before break (provision
new key, then revoke old) or when that may not be a good idea compared
with the risk of outage caused by revoking and then rekeying. It may be as
simple as saying something similar to the above about whether a router
supports multiple private keys or not, but I’m not sure if there are
additional considerations that need to be discussed.

Thanks,

Wes



On 4/29/14, 10:14 AM, "Sean Turner" <TurnerS@ieca.com> wrote:

>Hi,
>
>This version includes a new section 4 that addresses key management
>(i.e., keep a timer to make sure your cert doesn’t expire).  There’s also
>some editorial/readability corrections.  Please review as the authors
>think this version pretty much wraps up what we wanted to say.
>
>spt
>
>On Apr 29, 2014, at 10:10, internet-drafts@ietf.org wrote:
>
>>
>> A New Internet-Draft is available from the on-line Internet-Drafts
>>directories.
>> This draft is a work item of the Secure Inter-Domain Routing Working
>>Group of the IETF.
>>
>>        Title           : Router Keying for BGPsec
>>        Authors         : Sean Turner
>>                          Keyur Patel
>>                          Randy Bush
>>      Filename        : draft-ietf-sidr-rtr-keying-05.txt
>>      Pages           : 10
>>      Date            : 2014-04-29
>>
>> Abstract:
>>   BGPsec-speaking routers are provisioned with private keys to sign BGP
>>   messages; the corresponding public keys are published in the global
>>   RPKI (Resource Public Key Infrastructure) thereby enabling
>>   verification of BGPsec messages.  This document describes two ways of
>>   provisioning the public-private key-pairs: router-driven and
>>   operator-driven.
>>
>>
>> The IETF datatracker status page for this draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-sidr-rtr-keying/
>>
>> There's also a htmlized version available at:
>> http://tools.ietf.org/html/draft-ietf-sidr-rtr-keying-05
>>
>> A diff from the previous version is available at:
>> http://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rtr-keying-05
>>
>>
>> Please note that it may take a couple of minutes from the time of
>>submission
>> until the htmlized version and diff are available at tools.ietf.org.
>>
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/
>>
>> _______________________________________________
>> I-D-Announce mailing list
>> I-D-Announce@ietf.org
>> https://www.ietf.org/mailman/listinfo/i-d-announce
>> Internet-Draft directories: http://www.ietf.org/shadow.html
>> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt
>
>_______________________________________________
>sidr mailing list
>sidr@ietf.org
>https://www.ietf.org/mailman/listinfo/sidr


This E-mail and any of its attachments may contain Time Warner Cable proprietary information, which is privileged, confidential, or subject to copyright belonging to Time Warner Cable. This E-mail is intended solely for the use of the individual or entity to which it is addressed. If you are not the intended recipient of this E-mail, you are hereby notified that any dissemination, distribution, copying, or action taken in relation to the contents of and attachments to this E-mail is strictly prohibited and may be unlawful. If you have received this E-mail in error, please notify the sender immediately and permanently delete the original and any copy of this E-mail and any printout.