Re: [Sidrops] what to do when the CRL is hosed?

Stephen Kent <stkent@verizon.net> Tue, 24 March 2020 15:41 UTC

Return-Path: <stkent@verizon.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB7DE3A0C65 for <sidrops@ietfa.amsl.com>; Tue, 24 Mar 2020 08:41:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.563
X-Spam-Level:
X-Spam-Status: No, score=-3.563 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-1.463, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verizon.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FNCnb5IjmDVd for <sidrops@ietfa.amsl.com>; Tue, 24 Mar 2020 08:41:07 -0700 (PDT)
Received: from sonic313-56.consmr.mail.ne1.yahoo.com (sonic313-56.consmr.mail.ne1.yahoo.com [66.163.185.31]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8C5F33A0C0D for <sidrops@ietf.org>; Tue, 24 Mar 2020 08:41:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=verizon.net; s=a2048; t=1585064466; bh=0dcjorPk4mjaTJBwbIFxFEZe9MgY0vPSYTQqP8aYQoI=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From:Subject; b=kPhyVyRXFf7dIBFYtpZIGTR3rChDOb6yY3YUUN2pkPNLt7DZk6qJP1X7DIJ3oqW0v4OJrvhn52NwcENnjwA+53aCQfKb+1gFEhXArHdpjJriifd0OKb4jHBs0KWBbV/vuwdDOZts78io2HLf9kuHLvOPh5bBXiRnzM1hpXfYsmnugtw3alTHS5IZ4AJOXKQVJorUbQXyXrG0XHkReYbA3WFoJcInUUagonaoXiDrqm6E3i4WjnSz9lMmxY1D+fjKbmti/L18V2g1B6ZUPJ1oGnMbqXei929y+da+xWb+IbGqTVNkPnSvgwdoTmSfvow9QrJxslJdIOszPiHW3GOudQ==
X-YMail-OSG: IUlPje4VM1mFI9dYBvlp5_BA89p0Q.IlQsZ.mgbhETANyhKlxHm0_7EUY7BCXiN wVzojrkw64YZvrSb2BEOpTFIMMXr9j97Q2P9wj2AzxqMMTShGmCMbaHkCO54F3zjM9bofk6NTCzd vRFGY7SjIC9KxXyOsn8yVXSR_x4M1BV_w3n0dyYQ09j_WgV9HcACVqxyhcRRPF5yDJa1AapLoZ8o iN_LGgJ0lf97awOPn26w_kosN3mWTL.NdNjtANARhiNhkBVYo_K2gCeeqAXWQwKhhbVRTb4LPRRr EG1v4jbmHEhNMl.Io8bUjtmWwjhecnuUu1UapKzpoXZVTQFYEHe2FB0YIgWo2rg1ktxDI8Iwy5oB dwxCQiLkfJ5oS2Q_API.Askot1Sj7zWPAPetBXTQJ87iKVoeQLJjIABPIHEM24PHa1EObPeMHPn1 3E4zZT6K8jfdypwlqkq.dyYUfPsQEv9vJ_5.9M6vGnXMSKxkPK7l6Zj_PufneY4pvXEKk8jja_6H m56r0K23HxckjoVzFVYrnZhU4MzXi360MP9vYj74yey9QCxNx0sHRaDDfj0gxzRDaR3zjO.zsAL0 FIo8e9JAMpqW5kVEmvQEIP_QIM9nmFYkRHeZoPxC8bXyriLMCLAJCptdgS.HBQMLmfmyOLqX4BD1 6Mp893nMwmOG9OqHfTgyY4GAbIUP_YfTSjcgCYYXpyvOihs.lNrayQokCtFXf9aDil.IFKFEZzEu gP2TAteNqCTJoT3HL5agivTg5lSdmxwLzm8_663b6DDJFeCemqTGYtvo40L2KAHo.I82qmRH7h5V WQPZW1X6o8lgG099K0C7aEoO2We2HMGOzlfGR6FfF6T0m1Yi9.OV7yObzNUVlv5LbcAz0GKdjvOa evQgGBK5lhnmKEw1S05.DAjtXtckpNOydegk78HXeQs7oeQvXQx2JPVPo9aKllPbnxG15UeJE8HT vv1Q8HjerRxfVltxmKAWMXvYgwxYLd3M6shD.QMFTFEWmmwN0Jhr5r_Juxs9mxwZk8_xRr2_inv4 SOFn.gLxBaiU64J6A6gQ5JoArgpRHFpOtA22sIDO1JKPe2BN_t7XtZsNTnYpsAhD8EtEMdIiJNzJ UJFrkQP3LdF.z0WMG19suvUiGM07DcoZeTvEFB0Qj8MqsYIjIagOrqrv01Xo6L1fiYbPsw1jBD8c jc5UKQiRfUiX6Ao0XdomUsmfyllmgBkkPck1oLaAilwlkRoKsfCNugQDQyOBrJkw7e5O2bh.Nc7x CsQIG1QUEBEYY1xpxRreVbGPK00X2ydysFhxJtjGaW3C4tBHJmEFTG2Vh1FMPd6LbCz37Kh2T2CD q5U1QmGgzC4_tsW.bWUkhtFMfCyK1FuFXUssB8_h2baThDS3LI3PWck78FeDX95pJJfAiOsvVJ_z LR5rlhHKogNaSSuAWs7l728yW
Received: from sonic.gate.mail.ne1.yahoo.com by sonic313.consmr.mail.ne1.yahoo.com with HTTP; Tue, 24 Mar 2020 15:41:06 +0000
Received: by smtp428.mail.bf1.yahoo.com (Oath Hermes SMTP Server) with ESMTPA ID bf34da7b2fec840e9019b28be4abebfc; Tue, 24 Mar 2020 15:41:05 +0000 (UTC)
To: Tim Bruijnzeels <tim@nlnetlabs.nl>
Cc: SIDR Operations WG <sidrops@ietf.org>
References: <20200224151532.GD19221@vurt.meerval.net> <20200224211531.GB60925@vurt.meerval.net> <20200225090338.10464b1a@glaurung.nlnetlabs.nl> <9cc3a6a5-f9c8-23df-588e-48dee5db62d4@verizon.net> <3B7006DE-5366-47E7-9CD6-AF392F9ED0CC@nlnetlabs.nl> <6602d1a7-ecbf-73a0-21d8-1254fb2aff97@verizon.net> <253D1ED7-52D8-4A00-9D69-095E61D09C9F@nlnetlabs.nl> <db920115-e188-700f-ceb2-08cd2996046a@verizon.net> <BBE92EA7-5017-462B-A071-2F0F72F2C06D@nlnetlabs.nl> <9860FAC3-5473-42EE-B2DC-BBBEF3E1A2FB@nlnetlabs.nl>
From: Stephen Kent <stkent@verizon.net>
Message-ID: <01560d7d-6378-eadd-0cc5-476a429cc3eb@verizon.net>
Date: Tue, 24 Mar 2020 11:41:04 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:68.0) Gecko/20100101 Thunderbird/68.6.0
MIME-Version: 1.0
In-Reply-To: <9860FAC3-5473-42EE-B2DC-BBBEF3E1A2FB@nlnetlabs.nl>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
X-Mailer: WebService/1.1.15518 hermes Apache-HttpAsyncClient/4.1.4 (Java/1.8.0_242)
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/A59jrNNDsa-pibkllKoKg1MxAdk>
Subject: Re: [Sidrops] what to do when the CRL is hosed?
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Mar 2020 15:41:26 -0000

Tim,
>
> One more thought.. specifically on this:
>
>>> redundancy is often beneficial in security systems. it helps prevent a single error from having terrible consequences.
>
> It's the same engine that signs both CRLs and MFTs. I believe that this increases the chance of bugs in signing, and orchestration of publication. And a failure in any of these cases can lead to bad results.

Any bugs in the software that manages MFTs and CRLs is of concern. If 
one cannot manage to do both jobs correctly then maybe one ought not be 
running an RPKI CA.

Steve