Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

Ties de Kock <tdekock@ripe.net> Thu, 29 June 2023 10:47 UTC

Return-Path: <tdekock@ripe.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92364C151534 for <sidrops@ietfa.amsl.com>; Thu, 29 Jun 2023 03:47:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level:
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ripe.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iJe6upKylbDr for <sidrops@ietfa.amsl.com>; Thu, 29 Jun 2023 03:47:34 -0700 (PDT)
Received: from mail-mx-2.ripe.net (mail-mx-2.ripe.net [IPv6:2001:67c:2e8:11::c100:1312]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79059C15152E for <sidrops@ietf.org>; Thu, 29 Jun 2023 03:47:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ripe.net; s=s1-ripe-net; h=To:Message-Id:Cc:Date:From:Subject:Mime-Version:Content-Type ; bh=puGUEZIpR1DjCGGuADaJWlYA9xlxbdooFI56Y7mfaVw=; b=m/BX1V1grWdctA5lakPyNHnL KcDlKI4ocYNu9Gq9ADM03lXAQ7PtkpO7JAe03KzDJsIPHr54okmmvP38yEffpO45pRibXPeZ7j5gO kEvdHXuvvszvs9lszx4u9zb4PGBd0oF1uZzk+L+by8nrJ4UCF24lXKCuUftfFmN3gXfDwck+29qoA cX8qFi2hpbVlwZ7HKw4ON9kWYnwqejPwtkZRcl3w6YZ95IlZ5uAt/15A/T8yJIzFZPCGgIDznZdd8 0HZZKwfh2vK1Z/SXFXFhC5iFtAj0w7dNLEJ0rsNKzipiTrj5+pPZy+ZTnUpeyNuSYNzY69ZO9+6+Q Piqj2DI8HQ==;
Received: from bufobufo.ripe.net ([2001:67c:2e8:23::c100:170d]:56006) by mail-mx-2.ripe.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <tdekock@ripe.net>) id 1qEpBU-00FaE1-03; Thu, 29 Jun 2023 10:47:32 +0000
Received: from sslvpn.ipv6.ripe.net ([2001:67c:2e8:9::c100:14e6] helo=smtpclient.apple) by bufobufo.ripe.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <tdekock@ripe.net>) id 1qEpBT-0004oT-33; Thu, 29 Jun 2023 10:47:31 +0000
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.600.7\))
From: Ties de Kock <tdekock@ripe.net>
In-Reply-To: <ZJ1dTcwLtXIenGE2@snel>
Date: Thu, 29 Jun 2023 12:47:21 +0200
Cc: Martin Hoffmann <martin@nlnetlabs.nl>, sidrops@ietf.org
Content-Transfer-Encoding: 7bit
Message-Id: <61B2F635-4347-47BF-960E-8A1DF455CEE4@ripe.net>
References: <168621843689.33017.6897451444105786551@ietfa.amsl.com> <ZIGogKIH4Srb8Nxt@snel> <20230628173307.29fefec2@glaurung.nlnetlabs.nl> <ZJxXjg1NNdgVRP50@snel> <20230629115810.1c65c0c8@glaurung.nlnetlabs.nl> <4301BB4A-F87D-423E-94CC-C8B3037DA232@ripe.net> <ZJ1dTcwLtXIenGE2@snel>
To: Job Snijders <job@fastly.com>
X-Mailer: Apple Mail (2.3731.600.7)
X-RIPE-Signature: 059faafd1cc22ebb05e1592c815fe1e13473296bdece41228fbe92ff5c592fe1
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/AxJ_jzeUVcvCbE-7wijjEmMRnhM>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2023 10:47:39 -0000


> On 29 Jun 2023, at 12:30, Job Snijders <job@fastly.com> wrote:
> 
> On Thu, Jun 29, 2023 at 12:14:46PM +0200, Ties de Kock wrote:
>> A benefit of a separate version is a cleaner way to support both profiles.
> 
> Supporting both old-format and new-format is a non-goal for me.
> 
>> As a repository operator we parse _all_ objects in repositories for
>> some consistency checks
> 
> If you don't mind me asking, what happens if an object fails some
> consistency check? Or are these checks merely to facilitate gathering of
> statistics?

Continuous checks, and trend-based alerts, based on the semantic validity of
content published by third parties in repositories. 

Furthermore, object parsing (not purely generic CMS signed object parsing,
because our library did not expose this) is currently used to determine the
signing time of objects before writing them in an rsync repository.