Re: [sidr] Fwd: New Version Notification for draft-ietf-sidr-algorithm-agility-03.txt

Roque Gagliano <rogaglia@cisco.com> Tue, 09 August 2011 15:58 UTC

Return-Path: <rogaglia@cisco.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 086B821F8C16 for <sidr@ietfa.amsl.com>; Tue, 9 Aug 2011 08:58:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EatuB2maqkMl for <sidr@ietfa.amsl.com>; Tue, 9 Aug 2011 08:58:52 -0700 (PDT)
Received: from ams-iport-1.cisco.com (ams-iport-1.cisco.com [144.254.224.140]) by ietfa.amsl.com (Postfix) with ESMTP id BB55C21F8B81 for <sidr@ietf.org>; Tue, 9 Aug 2011 08:58:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=rogaglia@cisco.com; l=8247; q=dns/txt; s=iport; t=1312905561; x=1314115161; h=subject:mime-version:from:in-reply-to:date:cc:message-id: references:to; bh=Mx6BVrJmbzqSEC3tgmpllMKtBLgAMvQDTJEregIZNN8=; b=AgIkZu58vFfHQR2SYAW9Sz4zIa0abuvYs67h3tbWZZ47WwdlQ9nGIkj4 LPAmBUrWVa/1ZWTd6/Wwf39qMP7rRBmIKLvdmw75ddt3iD0hNPaoePocI fUGnTJgbTbA47ai0r6jLosToPuXotP4zywUrXILaWH9VZZti/lCogIeVF M=;
X-Files: smime.p7s : 4389
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Av4EAGtYQU6Q/khR/2dsb2JhbABCpz53gUABAQEBAgEBAQEPAVsJAgULCxguAiUwBhMih0sEoB4Bnm+FZ18EkwWQbQ
X-IronPort-AV: E=Sophos; i="4.67,344,1309737600"; d="p7s'?scan'208"; a="108450394"
Received: from ams-core-1.cisco.com ([144.254.72.81]) by ams-iport-1.cisco.com with ESMTP; 09 Aug 2011 15:59:20 +0000
Received: from dhcp-10-61-97-252.cisco.com (dhcp-10-61-97-252.cisco.com [10.61.97.252]) by ams-core-1.cisco.com (8.14.3/8.14.3) with ESMTP id p79FxJvp010751; Tue, 9 Aug 2011 15:59:19 GMT
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: multipart/signed; boundary="Apple-Mail-1845--409089361"; protocol="application/pkcs7-signature"; micalg="sha1"
From: Roque Gagliano <rogaglia@cisco.com>
In-Reply-To: <4E3C503D.2050004@ieca.com>
Date: Tue, 09 Aug 2011 17:59:18 +0200
Message-Id: <EE05681A-CC67-4417-A335-379E7DB90338@cisco.com>
References: <20110802092022.13671.96567.idtracker@ietfa.amsl.com> <1C1A5E2A-1C8A-4023-B2BA-A2D340470649@cisco.com> <p06240807ca5e0bcbcee5@[192.168.1.12]> <B02911FA-F807-4A6F-837A-205236B02325@cisco.com> <m239hiqa4p.wl%randy@psg.com> <4E3A9A65.4010207@ieca.com> <Pine.WNT.4.64.1108051408150.6664@SMURPHY-LT.columbia.ads.sparta.com> <4E3C503D.2050004@ieca.com>
To: Sean Turner <turners@ieca.com>
X-Mailer: Apple Mail (2.1084)
Cc: Sandra Murphy <Sandra.Murphy@sparta.com>, sidr@ietf.org
Subject: Re: [sidr] Fwd: New Version Notification for draft-ietf-sidr-algorithm-agility-03.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Aug 2011 15:58:53 -0000

Sean,

In Section 3.3 of http://datatracker.ietf.org/doc/draft-turner-sidr-bgpsec-pki-profiles/, you are missing to mention that one of the difference from draft-ietf-sidr-res-cert-profile is that your document refers a different algorithm suite document. Consequently, a BGPSEC certificate will not validate draft-ietf-res-cert-profile, as long as the two algorithm suites are different, correct? If that is the case, I believe you should clarify it and probably remove the references that the new profile is consistent with draft-ietf-sidr-res-cert-profile certificates.

Roque



On Aug 5, 2011, at 10:19 PM, Sean Turner wrote:

> On 8/5/11 2:11 PM, Sandra Murphy wrote:
>> 
>> 
>> On Thu, 4 Aug 2011, Sean Turner wrote:
>> 
>>> On 8/3/11 8:43 PM, Randy Bush wrote:
>>>>> The intention was to focus on the use case for the proposed changes
>>>>> (BGPSEC certs).
>>>> 
>>>> what is a "BGPSEC cert?"
>>> 
>>> What Mark and I are currently proposing in
>>> draft-turner-sidr-bgpsec-pki-profiles is that a BGPSEC certificate is a
>> 
>> <snip>
>> 
>>> 
>>> PS Technically, the EKU is defined in
>>> draft-turner-bpgsec-pki-profiles. It's
>> 
>> <snip>
>> 
>>> If the WG decides to adopt this approach, then we'll go through the
>>> appropriate procedures to request an OID and include it in the draft.
>> 
>> Sean, would you like to request wg adoption for these two drafts?
> 
> Yes I would like the wg to consider adoption of:
> 
> http://datatracker.ietf.org/doc/draft-turner-sidr-bgpsec-pki-profiles/
> http://datatracker.ietf.org/doc/draft-turner-sidr-bgpsec-algs/
> 
> as the starting point for certificates and algorithms for BGPSEC.
> 
> spt
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr