Re: [sidr] draft-sriram-bgpsec-design-choices-00 -- IXP and Route Server

Randy Bush <randy@psg.com> Fri, 08 July 2011 18:23 UTC

Return-Path: <randy@psg.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 161E321F8B30 for <sidr@ietfa.amsl.com>; Fri, 8 Jul 2011 11:23:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.58
X-Spam-Level:
X-Spam-Status: No, score=-2.58 tagged_above=-999 required=5 tests=[AWL=0.019, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IA88immoCtZX for <sidr@ietfa.amsl.com>; Fri, 8 Jul 2011 11:23:34 -0700 (PDT)
Received: from ran.psg.com (ran.psg.com [IPv6:2001:418:1::36]) by ietfa.amsl.com (Postfix) with ESMTP id 680C921F8AAA for <sidr@ietf.org>; Fri, 8 Jul 2011 11:23:34 -0700 (PDT)
Received: from localhost ([127.0.0.1] helo=rair.psg.com.psg.com) by ran.psg.com with esmtp (Exim 4.76 (FreeBSD)) (envelope-from <randy@psg.com>) id 1QfFi9-000Hzs-6A; Fri, 08 Jul 2011 18:23:33 +0000
Date: Sat, 09 Jul 2011 03:23:32 +0900
Message-ID: <m2oc14ljh7.wl%randy@psg.com>
From: Randy Bush <randy@psg.com>
To: Chris Hall <chris.hall@highwayman.com>
In-Reply-To: <014a01cc3d7f$6312f730$2938e590$@highwayman.com>
References: <012601cc3d54$8f07c4e0$ad174ea0$@highwayman.com> <m2y609kptw.wl%randy@psg.com> <014001cc3d74$319571c0$94c05540$@highwayman.com> <m2pqlklw3v.wl%randy@psg.com> <014a01cc3d7f$6312f730$2938e590$@highwayman.com>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset="US-ASCII"
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] draft-sriram-bgpsec-design-choices-00 -- IXP and Route Server
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Jul 2011 18:23:35 -0000

> I'm suggesting that A delegates a unique signing key to the RS.

the expression we use is, now RS can sign gifs of naked furries in A's
name.  i.e. A has given away the store.  you do NOT let anyone else have
your private keys.

for example. in this context, RS can now give that key to Perp who can
originate A's prefixes.  #fail

> This is what "6.6 Proxy Signing" in
> draft-sriram-bgpsec-design-choices suggests, is it not ?  Or does that
> blow the trust model to hell, also ?

it does indeed.  that is why 6.6 was rejected.

randy