Re: [Sidrops] mft/ee validity time window alignment issue - Re: I-D Action: draft-ietf-sidrops-6486bis-05.txt

Stephen Kent <stkent@verizon.net> Fri, 09 July 2021 18:04 UTC

Return-Path: <stkent@verizon.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E256A3A29F0 for <sidrops@ietfa.amsl.com>; Fri, 9 Jul 2021 11:04:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.438
X-Spam-Level:
X-Spam-Status: No, score=-2.438 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.338, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verizon.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JoXR0TbyXfdk for <sidrops@ietfa.amsl.com>; Fri, 9 Jul 2021 11:04:08 -0700 (PDT)
Received: from sonic301-32.consmr.mail.ne1.yahoo.com (sonic301-32.consmr.mail.ne1.yahoo.com [66.163.184.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8FCAD3A29C0 for <sidrops@ietf.org>; Fri, 9 Jul 2021 11:04:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=verizon.net; s=a2048; t=1625853847; bh=on5bfJweOX1Jrys0iCbeCQil+ZhWlMLgogJaJkajr+s=; h=Subject:To:References:From:Date:In-Reply-To:From:Subject:Reply-To; b=m03/WD+miGd27ix/SlZnNEOE8t5aZ8IPjcu+guoizeziDetQj38o0fLbq6dNfRR1tE/7/uzP7v9m8LMTfhFfaiTzjDlz+G2J6PHpBifoablYbuxENy1Mpz1jqnI4s/7EGlgqFKIpb2PnyFf1I8+GT7CCwNdbywJSAT10s4U/F/9c68LWrrYG1vmCt/Yp/WxhylNsqwC2DsICFGmE3MiYHy9L4krqXziZy+Ut9XmbHS6lSPeDSsfyZaZsL5nj3BlHsnzD0xzU+arGOTNKRFXAb3T1+azjZO8TNj6oXaAcFW1iQ1BeDmGYSLWAWsHbEJCHxYgzBp06u8GzvsDKCU8J4Q==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1625853847; bh=cWQNO/H+wsLQLMMvzSFVMKfd8/RAruXMvuemVRBEDMJ=; h=X-Sonic-MF:Subject:To:From:Date:From:Subject; b=aRFPzy7XbCnYDzBOydQUHJRKoNbHf86+KnJWxXSgPRTDfE4qKtWlQBIJrQClOemUOsG3avm4LGrMe32hcYt/uQ+FC4ocnX/L72zAKRN/3h0H6dxem+ZSohLTRHKI3EQysfTlR3ewScUdiBITxOGwQj//12a5PicIbNKcw4HV4jcoLkz+kq4ehu+YIYK9CgvVeSHrShwLMBQbBoE1R3AqZRVe0IPribWJk40W23ZAMLw0vtEztU7+KIq1ZctyyER8rJfaMSmMajqVHr+TRSy9z9v1uwzuvN/jGcUsp59wiupcUi0k8sDJTxlVIkwS5Z1IZNHdjVDpMnjH1JMBHWOuQg==
X-YMail-OSG: Nbtd7doVM1luVbl6kK1ckjrXoxsJsLsAmNsFcqd_pZfU0TKyqNO7NbAVzNOO85s romTqVzqBX9D4By6Q4iffkOxE1Ojw73IsALrHhpD7KSGB1ZpoKypaEPWrp3rFw3rOTPZ4YCc2rq8 gIimvz5_yoZxbIEYQSAxMA0UdJaH4tgUJ0M.CZ8LRRePV31PXljqOW40hjq5r_QOHiR5yLukyoeZ U.i1Esdct51Sm9dZjtkPDk0x5ykda0bjkXu89ArWZkMcBeTllpfyu90yrdlMN3.WvXrd60cyxISC eo_hmnv6vbMnTQLfyOQI7e.TPhv2qLb_kDqswAhPX3fMWbjTmJ_Hgkb6pIxS.AhJoWrtnJ2_5WS6 vNLt9dgg.UURIduWwfQKD9vZxqPU2XMBY.pQCyk80iiXRjJVhULkdzlQ47LdoL7diawqbyeBg_J1 Me.bFqQCsCZwqvb_ep1cKKo7CUAFx.XT9wfW7EHecsF4PrSgzkN8MwJtdywF5GSmNaqYQfBXb4gB 1F0pEOtUsTAy_VpG8z_jVYr0sDLeygMjHaxrhkrdoufJRdkpF82_wICRjpc6JNg12aOgfYRq9jia IUo2nkS9LxkYjnlZ31KRRo6Svo4kmMLGetKlSE1Bzt6QAds3MwDezwQwLoN6FKSh22bkWe0uDrBX KkVLll277nUqw1R.w1wHcQjJSG.Cpgd1RgqS73AJZQYZqhNBO0r4OHcbU7t9jYrj29nuithE83v. 31J543LKgp4UHrGlfv47GeP7xpF4huk3L0y1ko2GZo0XagKu5hDJ9sx_LtHfX7Kc8POGgvHZJM_l BaO5yf7pP_1wSrLBRncGIlPAimmYj1_mLbVnXAZo5Kwkengs6k7R5VNj_Crb8AfqWoHnkcT6pWKk BDTs4nUXEUXN.zNsMTAWkjsCt_Nv1q49uexMZmiGqsMV.xW9nbAZ2WySDwY.gV793Q7.SysWr5LE Z.acNV9yXuhh.aqFSGcm0uLHTXo1wGKBBNp4PzsriHXJ3DgudctyHAuPhdzE4rKa.fkhkvNe.o.S 6vI9nmcXnbvm63VmYXCNU7KoQleOoTNYzq.abJOIGMT48Kkclha76dTU1XNuG5X8eXYGYMCnxRQC Xq6kp3aefHB3XupEwY.KaNciNSN5AIEs_dqIgKCoAA8VsSeE1ZyXE0KKPtO.2n1pkH3N._Zx2Hn. yBg7JrUv2_Q7kmMq0XjO.Owzncl36uQ3QWo7PLU4ec1VbaLmcmyRIfGpVkSqm_eEk0nihdmDFeuK YOakjRjGpFlUStSqflKG1v6H9ObxWRqryMnlLz41p6ymryGwe26hrOfPuFrukbss.bm24eRibb7u vFFVBmqQ_8tDC5m2neA4wmQnKxQnYOYpDICIwHYiqisGiY8XnwzWFEnt7y0LovXxuNWRUNsNYgfA wLxILvKgD0EVuDOpy3mDfeb2U2KrK7s3caohpvKfaP8rU1Ro2_GTvc6lADdH3ekfdp6t7ljtb_O7 lJdhFZNIW7.g6yDynPYxMXV4X6u37eW8m_bUjUsc7YRKyU8l02iewKjVoUl9u0WgPnjIsLONHlar JkJ6rbmKYW7QtkkdnPty91w1.TmOBk7QuEpBTm4AuYRu5ZwDzFX8iqUTdsDhCdijlRnZkBeluCQ3 AxEBplnXXKDIzhruiI3NmXEhfmwNdZSMDnu9H5NnlBkSB6DP_Y50tUOMJX454IwFbebKqf2ySJsd R4dbghC3XRfs7XN0nY4iqoch5iwox0vvDk65iRaPnCmc1yjY5jLrvhduJfXL91M4rD6JS1IvdBDh NNUuN9LZzwgPTh1Fgv5pKtB3mSSvIjIukjPehj1j9Zeg6U.Tc.WXp6OUCcqML9DIwWjQViyTq4Fk adw9Ok10mzHnTAkqc9dujGiC0uoFqMk7PGgPXVd.dlQr9CERyFL8IpDUJdXBRRZW6w.QCCbUtTrg 9HqWaH08D6HhQ8iGtFhIJQm_sMDq8w9Ds89kpuhamaByLQZsVRgulKagVrCm98Lm.KA7kdpVfuDX RToo3EAIChHIy_eebIlS8hGUPAHR4igfaLdvHLb6miiLiClndyWZjl.sXTIJB6aEJ97gPeo7ebqk cfMzeJF2lh0JMKi3idKXFu5v1LfSjtI5NyopsmqM0RYxoQ9pWNc5VlfeJCVhNlswtF0w46EhgG1n _H5tPNa_bCpUvWrpFm.X5JsodH_Kul46Gnb5bOh0raiaDbm1AKUSaBvyOguCSw_t1ceTvUKWb25x Yf.yhA6d4bVmzScuMUOnemtoqFc.psqWGpAUSCuEelTa7NOmVBstO5YRigWYKXcB19WT_KKoEP8s jjG8eKIVX9ECjXduI8Mli2OK1q_cEV8UmWQUxdRIAmE.RdqUaiaBlXY7DEW2zTP2dgVY3Pr92PFj oJfipxVxCdTeLk40QalKQN3a3P.y2fas.0V0nL2diE5pAxJxS2oo_r1BGZ62uq.Xt8YHOiUdeFlm EshddrxLoKT.jFw_RZXmPPr6iH7BwW02O5v_KOekwSArA8KS0ZOfMVcjNPhQE
X-Sonic-MF: <stkent@verizon.net>
Received: from sonic.gate.mail.ne1.yahoo.com by sonic301.consmr.mail.ne1.yahoo.com with HTTP; Fri, 9 Jul 2021 18:04:07 +0000
Received: by kubenode565.mail-prod1.omega.bf1.yahoo.com (VZM Hermes SMTP Server) with ESMTPA ID 5840177623d49a831af9c69cebb3db73; Fri, 09 Jul 2021 18:04:02 +0000 (UTC)
To: sidrops@ietf.org
References: <162574988984.26098.17271669200254285008@ietfa.amsl.com> <YOc/X/fqp5RepPQD@snel>
From: Stephen Kent <stkent@verizon.net>
Message-ID: <44f0e8d8-1cfa-cfc2-6d53-7994e02a657b@verizon.net>
Date: Fri, 09 Jul 2021 14:04:01 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.0) Gecko/20100101 Thunderbird/78.11.0
MIME-Version: 1.0
In-Reply-To: <YOc/X/fqp5RepPQD@snel>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
X-Mailer: WebService/1.1.18469 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.aol
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/1ImJxdhvzW4fYGqATSOQOzCCE-o>
Subject: Re: [Sidrops] mft/ee validity time window alignment issue - Re: I-D Action: draft-ietf-sidrops-6486bis-05.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Jul 2021 18:04:21 -0000

Job,
> Hi all,
>
> I think the latest changes looked great on paper (and indeed simplify
> the text significantly), but are not operationally feasible.
>
> Quoting from draft-ietf-sidrops-6486bis-05 section 4.2.1 "Manifest":
>> Because a "one-time-use" EE certificate is employed to verify a
>> manifest, the EE certificate MUST have a validity period that
>> coincides with the interval from thisUpdate to nextUpdate in the
>> manifest, to prevent needless growth of the CA's CRL.
> It appears there are quite some CAs out there where 'nextUpdate' and
> 'notAfter' are not equivalent, I estimate it would reduce the global VRP
> count from ~ 263,175 down to ~ 209,931.
I am impressed by the work you did to discover which CAs are issuing EE 
certs for manifests that would not comply with the proposed changes. 
However, as Tim noted in his response, his CA code fails to follow the 
existing spec, so we should assume that there will need to a a gradual 
transition to a new, more restrictive spec. thus, saying that the 
proposed spec is "not operationally feasible" is an overstatement.

Nonetheless, I am open to suggestions on what we choose to mandate (vs. 
recommend) in terms of CA behavior, and to what extent we require (v.s 
recommend) that RPs check to see if CAs are following any new specs.

Steve