Re: [Sidrops] Test objects: ASPA and BGPSec Router Certificate

Tim Bruijnzeels <tim@nlnetlabs.nl> Mon, 25 July 2022 21:22 UTC

Return-Path: <tim@nlnetlabs.nl>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41F7EC13CCE8 for <sidrops@ietfa.amsl.com>; Mon, 25 Jul 2022 14:22:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.81
X-Spam-Level:
X-Spam-Status: No, score=-2.81 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nlnetlabs.nl
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AQN4RxJnhgyA for <sidrops@ietfa.amsl.com>; Mon, 25 Jul 2022 14:22:13 -0700 (PDT)
Received: from outbound.soverin.net (outbound.soverin.net [IPv6:2a10:de80:1:4091:b9e9:2215:0:1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DECF9C13CCC2 for <sidrops@ietf.org>; Mon, 25 Jul 2022 14:22:12 -0700 (PDT)
Received: from smtp.soverin.net (c04smtp-lb01.int.sover.in [10.10.4.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by outbound.soverin.net (Postfix) with ESMTPS id 4LsCfk2cR9zNK; Mon, 25 Jul 2022 21:22:06 +0000 (UTC)
Received: from smtp.soverin.net (smtp.soverin.net [10.10.4.99]) by soverin.net
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=nlnetlabs.nl; s=soverin; t=1658784126; bh=Gt8XSqKCOSfb4qUi9hBqF0WWUsuRoNXi2eK4NqEashE=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=OgaoL5FWM/FibvQ+4aYpBiDjSLn8Q83+nN9xaJSxJ3uBIqkR9MftHl4KNBDyyvUFC oEIJKYJM6cX7rkPpdBwN/vq5Qv8OEBn4yawvpZYE2QhPKZggv4JKUA+nZXGtN/Bzfr a2qQS/SuWu7zHKwhol2GIlDUh7mATKIhh6Yxq50fYHwg3S/Tp8JmkBH+IqZMeWHBIr rHh2YjzxQ3t43iIOhf9SF+MsP4oa1WfEUk5VqdJQRQxmx4CduKU6Fky4GJ3CmMYwgw fLciOK4xzbaKS/GCwZv3+7Bu8wuNUT8CFDG9/6Ycg5HbUM7s1+ZMkUKP1ZqEuODviA cpor4XnNyXOZA==
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.100.31\))
From: Tim Bruijnzeels <tim@nlnetlabs.nl>
In-Reply-To: <6A4FA576-E506-4376-8837-BF3CD62FCC82@nlnetlabs.nl>
Date: Mon, 25 Jul 2022 17:22:02 -0400
Cc: SIDR Operations WG <sidrops@ietf.org>
Content-Transfer-Encoding: 7bit
Message-Id: <CC611E4A-F6AC-4E59-89D9-7ED6042F759E@nlnetlabs.nl>
References: <DADDAAB3-109E-4B83-A54A-2AAF65E2FA62@nlnetlabs.nl> <127BBB15-7F9A-4983-9D7F-742B43F28B05@rpstir.net> <6A4FA576-E506-4376-8837-BF3CD62FCC82@nlnetlabs.nl>
To: Di Ma <madi@rpstir.net>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/3FPBPvMGVPN_RoAJYj-nglrkMCI>
Subject: Re: [Sidrops] Test objects: ASPA and BGPSec Router Certificate
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Jul 2022 21:22:17 -0000

Hi Di, all,

> On 24 Jul 2022, at 20:06, Tim Bruijnzeels <tim@nlnetlabs.nl> wrote:
> 
> I will have a fix during the week, test it better this time,
> and let you know!

Our testbed should be in better shape now.*

Could you check again?

@Job. It's high on my todo list to set up a smoketest environment
which will include rpki-client and other RP implementations.

Unfortunately, our previous setup for this proved too unreliable
and we had to switch it off. I won't have time to do this until
perhaps later in the week or next week though, so if you could have
another look again it's highly appreciated.

Tim

==
*: Beware.. this is public testbed primarily focussed on CA testing.
Anyone can set up a CA as a child, claiming any resources, and anyone
can publish anything they like. It is expected that many such test
CAs will be broken (or just switched off) leaving expired manifests
etc.