Re: [sidr] Simpler trust anchor format

Terry Manderson <terry.manderson@icann.org> Tue, 08 June 2010 00:35 UTC

Return-Path: <terry.manderson@icann.org>
X-Original-To: sidr@core3.amsl.com
Delivered-To: sidr@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9F5383A68B1 for <sidr@core3.amsl.com>; Mon, 7 Jun 2010 17:35:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.999
X-Spam-Level:
X-Spam-Status: No, score=-3.999 tagged_above=-999 required=5 tests=[BAYES_50=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hjA1ax27kPX8 for <sidr@core3.amsl.com>; Mon, 7 Jun 2010 17:35:24 -0700 (PDT)
Received: from EXPFE100-2.exc.icann.org (expfe100-2.exc.icann.org [64.78.22.237]) by core3.amsl.com (Postfix) with ESMTP id 4AA3B3A68BD for <sidr@ietf.org>; Mon, 7 Jun 2010 17:35:24 -0700 (PDT)
Received: from EXVPMBX100-1.exc.icann.org ([64.78.22.232]) by EXPFE100-2.exc.icann.org ([64.78.22.237]) with mapi; Mon, 7 Jun 2010 17:35:25 -0700
From: Terry Manderson <terry.manderson@icann.org>
To: Samuel Weiler <weiler@watson.org>, "sidr@ietf.org" <sidr@ietf.org>
Date: Mon, 07 Jun 2010 17:35:23 -0700
Thread-Topic: [sidr] Simpler trust anchor format
Thread-Index: AcsGVTfxXBwMBTtERjSxuPYH1hz01QATUMp+
Message-ID: <C833CD6B.49EC%terry.manderson@icann.org>
In-Reply-To: <alpine.BSF.2.00.1006062239350.39651@fledge.watson.org>
Accept-Language: en-US
Content-Language: en
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [sidr] Simpler trust anchor format
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Jun 2010 00:35:25 -0000

Before I lend my support to either the simpler format or the current
compound TA format I'd like to see a pros/cons list comparing the two
approaches.

While I find myself liking simple approaches but I also wonder if it has any
downfalls in use.

Cheers
Terry




On 7/06/10 2:21 PM, "Samuel Weiler" <weiler@watson.org> wrote:

> I just submitted an i-d documenting a much simpler trust anchor format
> than the one in the current WG draft.  Like the format in the WG doc,
> this one allows for a long-lived trust anchor even though the unlying
> certificate changes more often, e.g. when new resources are added.
> This format has the advantage of being noticeably simpler.
> 
> I encourage the WG to adopt this format in place of the one in the
> current WG doc.
> 
> -- Sam
> 
> ---------- Forwarded message ----------
> Date: Sun,  6 Jun 2010 19:30:02 -0700 (PDT)
> From: Internet-Drafts@ietf.org
> To: i-d-announce@ietf.org
> Subject: I-D Action:draft-weiler-sidr-trust-anchor-format-00.txt
> 
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> 
>         Title           : RPKI Trust Anchor Format
>         Author(s)       : S. Weiler
>         Filename        : draft-weiler-sidr-trust-anchor-format-00.txt
>         Pages           : 4
>         Date            : 2010-06-06
> 
> This document describes a simple convention for distributing trust
> anchors for the Resource Public Key Infrastructure (RPKI).
> 
> A URL for this Internet-Draft is:
> http://www.ietf.org/internet-drafts/draft-weiler-sidr-trust-anchor-format-00.t
> xt
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> Below is the data which will enable a MIME compliant mail reader
> implementation to automatically retrieve the ASCII version of the
> Internet-Draft.
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr