Re: [sidr] WGLC draft-sidr-rpki-rtr - take 2?

Joe Touch <touch@isi.edu> Wed, 24 August 2011 21:44 UTC

Return-Path: <touch@isi.edu>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F4AF21F8D7C; Wed, 24 Aug 2011 14:44:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.524
X-Spam-Level:
X-Spam-Status: No, score=-103.524 tagged_above=-999 required=5 tests=[AWL=-0.925, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aGPFkHRwWsa5; Wed, 24 Aug 2011 14:44:35 -0700 (PDT)
Received: from vapor.isi.edu (vapor.isi.edu [128.9.64.64]) by ietfa.amsl.com (Postfix) with ESMTP id C7FFA21F8D5F; Wed, 24 Aug 2011 14:44:35 -0700 (PDT)
Received: from [207.151.143.121] ([207.151.143.121]) (authenticated bits=0) by vapor.isi.edu (8.13.8/8.13.8) with ESMTP id p7OLjJOw014010 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 24 Aug 2011 14:45:29 -0700 (PDT)
Message-ID: <4E5570EF.4020202@isi.edu>
Date: Wed, 24 Aug 2011 14:45:19 -0700
From: Joe Touch <touch@isi.edu>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:6.0) Gecko/20110812 Thunderbird/6.0
MIME-Version: 1.0
To: Paul Hoffman <paul.hoffman@vpnc.org>
References: <AANLkTimq3hcdK7-f_Pa9sWJJOTzF_GBLcYu36sB3WszN@mail.gmail.com> <CAL9jLaaVbmExEM2ZwBf5Ur6aRbBayxX13xGBL27r-svOmC3Wvg@mail.gmail.com> <001801cc60bb$19329d00$4001a8c0@gateway.2wire.net> <4E527D5B.2080104@isi.edu> <003f01cc626f$4d2d2d40$4001a8c0@gateway.2wire.net> <4E554ECC.3020408@isi.edu> <F350099E-1EEA-4478-BFC2-72A4622012E5@vpnc.org>
In-Reply-To: <F350099E-1EEA-4478-BFC2-72A4622012E5@vpnc.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Cc: Christopher Morrow <christopher.morrow@gmail.com>, sidr-chairs@ietf.org, sidr@ietf.org
Subject: Re: [sidr] WGLC draft-sidr-rpki-rtr - take 2?
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2011 21:44:36 -0000

On 8/24/2011 1:27 PM, Paul Hoffman wrote:
> On Aug 24, 2011, at 12:19 PM, Joe Touch wrote:
>
>> Is there ever a reason that this service should exist as a totally open and insecure port?
>
> Given that it is explicitly listed in the draft, I find it worrisome that you even ask the question.
>
>     Caches and routers MUST implement unprotected transport over TCP
>     using a port, RPKI-Rtr, to be assigned, see Section 12.  Operators
>     SHOULD use procedural means, ACLs, ... to reduce the exposure to
>     authentication issues.

I saw a declaration that this was required, but no REASON that 
unprotected transport was necessary.

>> Also, is there a reason for not assuming that the out-of-band and
> in-band services cannot exist on the same port (other than performance
> of the connection establishment)?
>
> Those aren't enough !?!?

"those"? I listed only one - performance.

There are not enough ports to assign multiples just for performance reasons.

Joe