Re: [sidr] RPKI validator testing summary

Geoff Huston <gih@apnic.net> Sat, 03 December 2011 05:29 UTC

Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D80721F8CBD for <sidr@ietfa.amsl.com>; Fri, 2 Dec 2011 21:29:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.233
X-Spam-Level:
X-Spam-Status: No, score=-100.233 tagged_above=-999 required=5 tests=[AWL=1.150, BAYES_00=-2.599, HOST_MISMATCH_NET=0.311, RCVD_IN_PBL=0.905, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cx7gwZoMYcti for <sidr@ietfa.amsl.com>; Fri, 2 Dec 2011 21:29:53 -0800 (PST)
Received: from asmtp.apnic.net (asmtp.apnic.net [IPv6:2001:dc0:2001:11::199]) by ietfa.amsl.com (Postfix) with ESMTP id 4868321F8CBC for <sidr@ietf.org>; Fri, 2 Dec 2011 21:29:52 -0800 (PST)
Received: from [10.242.58.184] (mcf0f36d0.tmodns.net [208.54.15.207]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by asmtp.apnic.net (Postfix) with ESMTP id 70759B6767; Sat, 3 Dec 2011 15:29:49 +1000 (EST)
Mime-Version: 1.0 (Apple Message framework v1251.1)
Content-Type: text/plain; charset="us-ascii"
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <m2r50m8gk2.wl%randy@psg.com>
Date: Sat, 03 Dec 2011 16:29:46 +1100
Content-Transfer-Encoding: quoted-printable
Message-Id: <1BADD28A-5808-48BB-A85D-275ED141D2D8@apnic.net>
References: <4ED64E04.7030408@bbn.com> <E3871AC3-6960-433A-8A34-7F10087A7EC7@apnic.net> <E03612FA-E271-4243-AE29-858D242B91CE@apnic.net> <m2r50m8gk2.wl%randy@psg.com>
To: Randy Bush <randy@psg.com>
X-Mailer: Apple Mail (2.1251.1)
Cc: sidr wg <sidr@ietf.org>
Subject: Re: [sidr] RPKI validator testing summary
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 03 Dec 2011 05:29:54 -0000

On 03/12/2011, at 2:44 PM, Randy Bush wrote:

> so are you saying bottom up is just a no-go?
> 

I believe I am, in that by following the AIA pointers you may be lead to places that may not match your chosen trust anchors.

This is particularly the case for those who want to set up local TAs as per some draft or another.


 Geoff