Re: [sidr] wglc draft-ietf-sidr-policy-qualifiers-00

Andy Newton <andy@arin.net> Sun, 25 August 2013 14:40 UTC

Return-Path: <andy@arin.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 93CDA21F9991 for <sidr@ietfa.amsl.com>; Sun, 25 Aug 2013 07:40:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.569
X-Spam-Level:
X-Spam-Status: No, score=-2.569 tagged_above=-999 required=5 tests=[AWL=0.030, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XmZJ8MGGs7H1 for <sidr@ietfa.amsl.com>; Sun, 25 Aug 2013 07:40:14 -0700 (PDT)
Received: from smtp2.arin.net (smtp2.arin.net [IPv6:2001:500:4:13::32]) by ietfa.amsl.com (Postfix) with ESMTP id B21D121F8D90 for <sidr@ietf.org>; Sun, 25 Aug 2013 07:40:14 -0700 (PDT)
Received: by smtp2.arin.net (Postfix, from userid 323) id 3689D21365E; Sun, 25 Aug 2013 10:40:14 -0400 (EDT)
Received: from CHAXCH05.corp.arin.net (chaxch05.corp.arin.net [192.149.252.94]) by smtp2.arin.net (Postfix) with ESMTP id 5F78F21363E; Sun, 25 Aug 2013 10:40:13 -0400 (EDT)
Received: from CHAXCH04.corp.arin.net (10.1.30.101) by CHAXCH05.corp.arin.net (192.149.252.94) with Microsoft SMTP Server (TLS) id 14.2.342.3; Sun, 25 Aug 2013 10:40:07 -0400
Received: from CHAXCH02.corp.arin.net ([169.254.2.131]) by CHAXCH04.corp.arin.net ([10.1.30.101]) with mapi id 14.02.0342.003; Sun, 25 Aug 2013 10:40:07 -0400
From: Andy Newton <andy@arin.net>
To: Geoff Huston <gih@apnic.net>, "Murphy, Sandra" <Sandra.Murphy@parsons.com>
Thread-Topic: [sidr] wglc draft-ietf-sidr-policy-qualifiers-00
Thread-Index: Ac5/P7KlsWW9gua6S/mEz+yRY2Jx6ACSJbqA///q8YCAAUv7gIAADzOAgDv5C7SAAIyLAIACZbGA
Date: Sun, 25 Aug 2013 14:40:06 +0000
Message-ID: <CE3F8DF3.27D2A%andy@arin.net>
In-Reply-To: <973B0890-766F-4023-8F35-876936E470C6@apnic.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.3.6.130613
x-originating-ip: [192.149.252.96]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <CFEB0676B6E3C349AB2C6C0900DA0075@corp.arin.net>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "sidr@ietf.org" <sidr@ietf.org>
Subject: Re: [sidr] wglc draft-ietf-sidr-policy-qualifiers-00
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Aug 2013 14:40:20 -0000

You are exactly right, but I think Rogue's text connects the dots on using
old RP software.

-andy

On 8/23/13 6:03 PM, "Geoff Huston" <gih@apnic.net> wrote:

>Wouldn't it be better to note that: As an update to RFC6487, this
>document broadens the class of certificates that conform to the RPKI
>profile by explicitly including within the profile those certificates
>that contain a policy qualifier as described here.
>
>Geoff
>
>
>
>On 24/08/2013, at 4:09 AM, "Murphy, Sandra" <Sandra.Murphy@parsons.com>
>wrote:
>
>> Speaking as working group chair:
>> 
>> I can't be certain that this indicates a promise to modify the draft or
>>not.  Roque, Andy, could you comment?
>> 
>> If so, a new version is needed and I'll say so on the list.
>> If not, I'll have to ask for resolution on list.
>> 
>> Speaking as regular ol' member (and a bit as wg chair, as I'm not clear
>>about the intent of the new text):
>> 
>> I don't think this text hurts anything, but I am puzzled about the
>>intent.  If "all known" implementations comply, why mention the problem?
>> OTOH, it might serve to forestall AD/IESG questions.
>> 
>> So I agree with Andy's observation, though I'd say a heading "Backward
>>Compatibility Considerations" rather than "Interoperability
>>Considerations" suits the situation better.
>> 
>> (Apologies - searching for the thread, I found these comments stuck in
>>my draft folder from 17 July.)
>> 
>> --Sandy
>> 
>> P.S.  
>> 
>> "strick"->"strict"
>> "RPKI signed objects" -> "RPKI objects" <because you mean CA certs as
>>well and signed objects might be taken to mean only ROAs and
>>ghostbusters and manifests etc>
>> "implements"->"include" or "contain" or...
>> "RP"-> relying party (or you'll have to define the acronym somewhere)
>> Not sure what ""as in IDR" means.
>> 
>> ________________________________________
>> From: Andy Newton [andy@arin.net]
>> Sent: Tuesday, July 16, 2013 9:49 AM
>> To: Roque Gagliano (rogaglia)
>> Cc: Murphy, Sandra; sidr@ietf.org
>> Subject: Re: [sidr] wglc draft-ietf-sidr-policy-qualifiers-00
>> 
>> This sounds fine to me, though it is really an interoperability
>> considerations section thingy. The IETF does those now, right? :)
>> 
>> -andy
>> 
>> On 7/16/13 4:55 AM, "Roque Gagliano (rogaglia)" <rogaglia@cisco.com>
>>wrote:
>> 
>>> Thanks Andy.
>>> 
>>> Do you think we need to add something in the security section about the
>>> transition?
>>> 
>>> Something like:
>>> 
>>> "A RP that performs a strick validation based on RFC6487 and fails to
>>> support the updates described in this document, would incorrectly
>>> invalidate RPKI signed objects that implements the changes in Section
>>>2.
>>> At the time of this writing, all known RP software suites (you can
>>> mention them as in IDR) were tested and supported the updates on this
>>> document"
>>> 
>>> Roque
>>> 
>>> On Jul 15, 2013, at 7:07 PM, Andy Newton <andy@arin.net> wrote:
>>> 
>>>> On 7/15/13 10:22 AM, "Roque Gagliano (rogaglia)" <rogaglia@cisco.com>
>>>> wrote:
>>>> 
>>>>> Before sending my support to advance to the IESG, I wanted to ask the
>>>>> author if they have tested the effects of this change on existing RP
>>>>> tools. Do they really set the certificate as invalid?
>>>> 
>>>> Yes, we have tested against the three RP suites. One did not require a
>>>> change while the other two required simple one line changes. Current
>>>> releases of all three now accommodate it.
>>>> 
>>>> -andy
>>>> 
>>> 
>>> 
>> 
>> 
>> _______________________________________________
>> sidr mailing list
>> sidr@ietf.org
>> https://www.ietf.org/mailman/listinfo/sidr
>
>