[Sidrops] Call for WG Adoption of draft-snij-sidrops-constraining-rpki-trust-anchors

Luigi Iannone <ggx@gigix.net> Mon, 19 January 2026 12:47 UTC

Return-Path: <ggx@gigix.net>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 06CACA9D96DF for <sidrops@mail2.ietf.org>; Mon, 19 Jan 2026 04:47:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gigix-net.20230601.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vMRq3I6rwUVC for <sidrops@mail2.ietf.org>; Mon, 19 Jan 2026 04:47:30 -0800 (PST)
Received: from mail-wm1-x32d.google.com (mail-wm1-x32d.google.com [IPv6:2a00:1450:4864:20::32d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 567D2A9D96D8 for <sidrops@ietf.org>; Mon, 19 Jan 2026 04:47:30 -0800 (PST)
Received: by mail-wm1-x32d.google.com with SMTP id 5b1f17b1804b1-47ee0291921so27893635e9.3 for <sidrops@ietf.org>; Mon, 19 Jan 2026 04:47:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gigix-net.20230601.gappssmtp.com; s=20230601; t=1768826849; x=1769431649; darn=ietf.org; h=to:date:message-id:subject:mime-version:from:from:to:cc:subject :date:message-id:reply-to; bh=11MvP/Wq4hp88WleE4yvpyNdSlRrqjxRaGnwgOM1DLs=; b=sjHs0kWGs5Dae4m007KzipmLZdkaQPsxj8xt0vz6xYR3Y6RNV9/CYtEnugTBlIraCw kirQVxwZS1WZVYVBaeRd+cuyuFRNFTZHyciKzy1t/+7oq2QTH6FiGMdnyl+HFJOuUqxv 52QTl9lWR6tojC01caOhHJ7OQfyUm9WcokRcIeZD6M+fJJaGCnWBktbOsgnQLdgrCCZV p+cIDsm2J5yNVsaqhyrA9YHivAvRNBZ71HZyC6EZ3hb1Lz6ONNF7SsbIKmTS33dG0aX5 CGx/rzISsTqmbG6u6KTnXnsH7NTx88fPpf6NK0gRWpH4o/Tpj3/mZhi555tte/Oz6JJC 6duw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768826849; x=1769431649; h=to:date:message-id:subject:mime-version:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=11MvP/Wq4hp88WleE4yvpyNdSlRrqjxRaGnwgOM1DLs=; b=AsWmYbmzMb3ShuPL+H9FC6iDJi2o90hY+cYOZTyaAiBQR9EolrekE1KMPiQSJ4IUW3 QsGR0f8yAJSuSEcry1jbXWKZJxh0+VA9et4R6HFgxG5IKftoFj7+ArnSB5LnyFxMt/ZR 2FHdBb6Zikhs3uf9fEz/EgPQj3gzwn5SxEUZevxE7J3yXEr5AZ63WhOtlj49Sxvl85pZ /79UVEjEhWhNGEgR1JhMRqE76q+PlaTv8HzccuTEqQQpAWXReVr/93wBZVO0XeNlP7io 2rEc/XzkCxAvg9j1a/AUcCn/FrnanPhavnmDNGM3P/uNRkkh6ue3KBSieP2NkbrxtIJq BsAQ==
X-Gm-Message-State: AOJu0YzqvU68Z54LxeMvZ/UVylBqe5Z2/5d3hjZ+iFh8CEkG+hnZ7NPV vdu0J8NJ5qy6vYu2csElfoa/XGL1mqY3u8zT8VShECZODlBpgN9QOQ3CR6Ri8TpI/KArNDbNG25 tsBSXREWBAg==
X-Gm-Gg: AY/fxX6wDFuw5st2cOxY9OpH7b5CEVMjL0ipR/DAG3btLzgzQiSVWr+CZGeS6Yhov1p b4uoOVIQK5IbE5+1oOiprgLnJsywlonidcZH36BiFHum+iee4tbJCakxYxQJsy0iIxdLyNUdlVx zIENZp+dm9jcFERUdJctN6XfWKnf+WmoSwcMDrOOFHycPamudC1McNcdJNZLCrReqzA8FAXZzMV hk78Hrc617z7w9NcRo0hd9Mguc5WkiyoI8/Y6+3ShUU2CyNx6HuesA25ljxEXJnGJpR8QdnOqB1 p1Vl7dzHR7SUO538oE//NOr2txBE2ct6h3nUb0GKulttaI88Dz1oI9m0JxWn5M43u4yaodiKjn1 u4CRg2/Lc0miz/cBFmRYPkbiJt94oHh1uAurznWCx/n/rs7e8uATast/r/qc/jvsn9J6brvudve hMahOF/7E/ZWSQasy4V9sz/0xPZ8r+zgrHxjKMCm5Ykd4qIWSpd9D9Mh28FL0=
X-Received: by 2002:a05:600c:4f4e:b0:47e:dc64:f1c6 with SMTP id 5b1f17b1804b1-4801eab51c8mr150174375e9.6.1768826848793; Mon, 19 Jan 2026 04:47:28 -0800 (PST)
Received: from smtpclient.apple (91-167-176-17.subs.proxad.net. [91.167.176.17]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4801fe47dddsm79598955e9.13.2026.01.19.04.47.27 for <sidrops@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 19 Jan 2026 04:47:27 -0800 (PST)
From: Luigi Iannone <ggx@gigix.net>
Content-Type: multipart/alternative; boundary="Apple-Mail=_8430BB81-1256-4629-B444-3BB5ACFA6888"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\))
Message-Id: <5C5B8F40-6E19-4082-89C0-3DDC0AB6364A@gigix.net>
Date: Mon, 19 Jan 2026 13:46:55 +0100
To: SIDRops IETF <sidrops@ietf.org>
X-Mailer: Apple Mail (2.3826.700.81.1.4)
Message-ID-Hash: GAAZ74TCQFNTPWS4TFZKHKMPC7BMV3SS
X-Message-ID-Hash: GAAZ74TCQFNTPWS4TFZKHKMPC7BMV3SS
X-MailFrom: ggx@gigix.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Call for WG Adoption of draft-snij-sidrops-constraining-rpki-trust-anchors
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/-uAtawj2sINL6I9anHchqMYWb_8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>

All,

The authors have asked the SIDROPS WG to adopt the document draft-snij-sidrops-constraining-rpki-trust-anchors (https://datatracker.ietf.org/doc/draft-snij-sidrops-constraining-rpki-trust-anchors/)

Title: Constraining RPKI Trust Anchors

Abstract:
  This document describes an approach for Resource Public Key
   Infrastructure (RPKI) Relying Parties (RPs) to impose locally
   configured Constraints on cryptographic products subordinate to Trust
   Anchors (TAs).  The ability to constrain a Trust Anchor operator's
   effective signing authority to a limited set of Internet Number
   Resources (INRs) allows Relying Parties to enjoy the potential
   benefits of assuming trust - within a bounded scope.  The specified
   approach and configuration format allow RPKI operators to communicate
   efficiently about observations related to Trust Anchor operations.


This email formally opens the two weeks Call for Adoption.

If you are supporting adoption, please state so.
If you have concerns, please detail them.

Please voice your opinion for the SIDROPS WG adoption of this document by 2 February 2026.  
 
For the SIDROps WG Chairs, 
Luigi