Re: [sidr] some comments and questions regarding rpki-rtr

Tim Bruijnzeels <tim@ripe.net> Mon, 03 October 2011 09:15 UTC

Return-Path: <tim@ripe.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 434F621F8B01 for <sidr@ietfa.amsl.com>; Mon, 3 Oct 2011 02:15:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KY4wql+9dZj9 for <sidr@ietfa.amsl.com>; Mon, 3 Oct 2011 02:15:37 -0700 (PDT)
Received: from postlady.ripe.net (postlady.ipv6.ripe.net [IPv6:2001:67c:2e8:11::c100:1341]) by ietfa.amsl.com (Postfix) with ESMTP id 5C54921F8AF9 for <sidr@ietf.org>; Mon, 3 Oct 2011 02:15:37 -0700 (PDT)
Received: from ayeaye.ripe.net ([193.0.23.5]) by postlady.ripe.net with esmtps (TLSv1:AES256-SHA:256) (Exim 4.72) (envelope-from <tim@ripe.net>) id 1RAefV-0001hC-4Q; Mon, 03 Oct 2011 11:18:38 +0200
Received: from timbru.vpn.ripe.net ([193.0.21.62]) by ayeaye.ripe.net with esmtps (TLSv1:AES128-SHA:128) (Exim 4.72) (envelope-from <tim@ripe.net>) id 1RAefU-0004An-TL; Mon, 03 Oct 2011 11:18:36 +0200
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: text/plain; charset="us-ascii"
From: Tim Bruijnzeels <tim@ripe.net>
In-Reply-To: <m2oby0tzlh.wl%randy@psg.com>
Date: Mon, 03 Oct 2011 11:18:36 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <DD3C8E75-A31C-4CEE-BDF2-E4CD7703517A@ripe.net>
References: <49638.80.57.195.122.1317462144.squirrel@webmail.ripe.net> <m2oby0tzlh.wl%randy@psg.com>
To: Randy Bush <randy@psg.com>
X-Mailer: Apple Mail (2.1084)
X-RIPE-Spam-Level: ---
X-RIPE-Spam-Report: Spam Total Points: -3.4 points pts rule name description ---- ---------------------- ------------------------------------ -1.0 ALL_TRUSTED Passed through trusted hosts only via SMTP -0.5 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000]
X-RIPE-Signature: 784d7acfe6559f2a0b602ec6519a071987821b0be669947e1fdf55a511bfd8ae
Cc: sidr wg list <sidr@ietf.org>, Tim Bruijnzeels <timbru@ripe.net>
Subject: Re: [sidr] some comments and questions regarding rpki-rtr
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Oct 2011 09:15:38 -0000

Randy, Rob,

thank you both for your explanations.

regarding my questions

> A = No changes
> B = Nonce and cache reset

I think that reading your responses we were on the right track, but I wasn't 100% sure. I am happy to see your responses confirming this.

> C = Duplicate announcements / withdrawals

Points taken about difficulty on client to know how many withdrawals it would take to negate an announce seen more than once ;and that computational power being lots cheaper on the box running the validator (compared to routers)

> D = Keep alive timeout
> E = Cache shutdown

I wasn't sure about these, but I am not particularly looking for extra complexity. If just closing the channel is okay, that's what we'll do. We'll probably up the time-out threshold a bit (say 90 mins) to avoid cutting the connection on a client router the minute before it would send another serial.


Thanks,
Tim