Re: [Sidrops] ASPA verification questions
Ben Maddison <benm@workonline.africa> Wed, 14 December 2022 18:10 UTC
Return-Path: <benm@workonline.africa>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 27F3CC14CE2A for <sidrops@ietfa.amsl.com>; Wed, 14 Dec 2022 10:10:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=workonline.africa
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6DC1vFTXeWVO for <sidrops@ietfa.amsl.com>; Wed, 14 Dec 2022 10:10:50 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on2065.outbound.protection.outlook.com [40.107.21.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E937CC14F726 for <sidrops@ietf.org>; Wed, 14 Dec 2022 10:10:46 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=I+MngrLit8uu9HFwF/mOPzT8MXEUhdd+jSw9/LhPrt/pNO6XQPRNhhIfXtj46FFE64vv8ugMWrL98PCB8zyPFX/iH6EF0rPUZl+s5yLs1hevKCcjN4ySNMueDK3ZGUI/jbJc/HBewdvAFIWMOaKRgauc/fvgP1xt1LKd68k0jIU5hU166VdcDL4fM0oKDSCWyBtPzYhihM82dbgPG0OcKzuGbfohnuSb8/YUKupchryLV+DDpRq7vUhuwRZ702EA3M+4OuU9bAK3Jx5sVmzti+6DplhMIsFXwO5B9rviFFLNx5xfsG654q/yqsUM8D80igG0/fbfSmxwLO/wjx4KPg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=UKj4Wo8pztOpGmI4lRmxE7RJA0qsHeFJj4MRzoKQMUc=; b=Q+GBAV7KRNU+hG/Iz7u6nJ2UBGdVSD5v5bfSBpxhwAckFwOttlfMWTQlCTdx5bfqJmIqlSVFjOcvjxhRSMPdp1CejkSMhLdM/N6YHKVe47aDGaTePgGE+ZxdbWlC6HS9PMDw/AiKtPV7pJrfc5Bpp3rP2LFE0I/i8i0dE4VXvhG1zGRc57iCd59hbiDG5FuWe/5orFYUL87lfZqZd0ud0mOuOGiPBALfqKnt+6QoNcsqeazNPN0QJDYF4IEMyu2czMPhqLFcFwQ98kbkl0J9USP5seZEpQNm3Yl0GBLq32PYjQ1Mgyh9RwdxJDYByzMNh9SNl+EEjRORyNcmIvHzyg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=workonline.africa; dmarc=pass action=none header.from=workonline.africa; dkim=pass header.d=workonline.africa; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=workonline.africa; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=UKj4Wo8pztOpGmI4lRmxE7RJA0qsHeFJj4MRzoKQMUc=; b=Lant+GE9F3sUcDwRRmMZcl7rDEeYPUsvw3M1Tnr0DeZVT+KTgqdQO7cln/ivfLkNEi1e0J4KTvV4Ua3uTzlIgaNfIGIMF2BPC7v2fYvrB7BZm5Zj8K3flCidp2c1edIYaiK9/rOekuCxa8RaechgX9+K7dbbm+Fr3aAge9NHlv0=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=workonline.africa;
Received: from AS8P190MB1078.EURP190.PROD.OUTLOOK.COM (2603:10a6:20b:2e7::13) by VI1P190MB0719.EURP190.PROD.OUTLOOK.COM (2603:10a6:800:12b::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5880.19; Wed, 14 Dec 2022 18:10:42 +0000
Received: from AS8P190MB1078.EURP190.PROD.OUTLOOK.COM ([fe80::3b1a:1862:8cba:ffa1]) by AS8P190MB1078.EURP190.PROD.OUTLOOK.COM ([fe80::3b1a:1862:8cba:ffa1%8]) with mapi id 15.20.5880.019; Wed, 14 Dec 2022 18:10:42 +0000
Date: Wed, 14 Dec 2022 20:10:35 +0200
From: Ben Maddison <benm@workonline.africa>
To: Claudio Jeker <cjeker@diehard.n-r-g.com>
Cc: sidrops@ietf.org
Message-ID: <20221214181035.bydtb3nvtsklav4j@iolcus>
References: <Y5nh7YrUMjxOy1xA@diehard.n-r-g.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="ryq5frbs3pfq2jso"
Content-Disposition: inline
In-Reply-To: <Y5nh7YrUMjxOy1xA@diehard.n-r-g.com>
X-ClientProxiedBy: LO4P123CA0682.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:351::7) To AS8P190MB1078.EURP190.PROD.OUTLOOK.COM (2603:10a6:20b:2e7::13)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: AS8P190MB1078:EE_|VI1P190MB0719:EE_
X-MS-Office365-Filtering-Correlation-Id: e72611c9-e964-47ec-7147-08daddfe835f
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: uN5IMymJZlU3t6lr9sUgcuvo+rydJNq9svBgV27zoLam8P/5VuQu8pRc7rbheiw0Q+vmIu9DgG6ahjK6uWdJ0yRpbxU++XtpebcYyaklemq4i9l8wG/Z31JH6e04Wf/pIj01uUTszW3O6IviwcK6BA7PBReyqHrj/YOrMPLrzCXyRvy5JG6RzjdLXz2HWTjSL9Uwsymu9PraYwWZL61C03Pi+hcaiwUaQ7AWBaS10cCKOEjiHpB8TGElbneT/m+m9eYebNWPE9ZL0ElchSYFOS9X8AQqvQoyeVSElSlkWk1/k+owNVRTOD0jB267kReD/8/ZTnzhZI11mbzjCLZD0/yWK45ZPjVzh+KpBk9/0e/SXGFhc2pRfE2Hmb/6o9DzJ6Kz6Jc898clZ+sqaJD8kO9sjYK0XmvV/JDKbyBKkOA2iONEeAUNB/3Zd408GJDXlTh1gGW0Tu5eQCL6oeZrDcGiDR5SG92hogh5aJzsL9RqSXQ1QoMjB2Vaun37zSIfLigHanRPZj0z7+0WptnxkQkcNeRsHMe3aQCJ5bDmrYQqgVFBf8pZtltmcDDfmS9/th5XbzkQ3Y/1DBEZdtgVqJMTXiehsuJrjRA3KC6bJ4xJD2sYdufWTqMn1dlAWKgBsx5ZEoIVk6hDic3kX+drr2VC1cikg8Ggk5uXU1jSP74GcwFoLPHG058Qq/W91OM/7RXR934nPhxXF3JaRjiw7co/S56tSIHxv03Cum03zvoK/h4n6migHFEgxcdXN/OG
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS8P190MB1078.EURP190.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230022)(7916004)(39840400004)(136003)(346002)(376002)(396003)(366004)(451199015)(8936002)(15650500001)(8676002)(4326008)(66556008)(66476007)(66946007)(316002)(2906002)(5660300002)(41300700001)(6916009)(44144004)(33716001)(26005)(186003)(9686003)(52116002)(6506007)(6486002)(1076003)(6512007)(478600001)(6666004)(21480400003)(83380400001)(38350700002)(86362001)(38100700002)(46492015)(2700100001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 6z6gh3/GMyQzrryvKcMniWceSmcwy2GktW37Ab8WgGDwTMFeIhSRHZ8fA0T1OdTF1Nkau53lmuWDAP/obp0OqzVrTqMX4g0ntFJsAQCxvajdgE3xWYdbw6/sSjoT+2ROEeFPOEw7lMmLvdfrDO/9hpE7tNgD+psqguD7xI+WsvatxYC93inphUv+WG5LkCeA9wnvXQwQItkt2ng2LHvV18f4kTnqM1tBX+TSzoHsayfk7VgAedsG8WRataRFjXA0xlMIt6n43wak44hxCOjvL2Maml/MaCmQ9tzEGRc4XXKypQQ1xzv++rUVwRVIQgJh0HErthVXbNaniJAPbe/Fk24bgwHUJncMxh5o20tFM7XOOXyObnJ5bS2vir7TefPaIwWLvDS/nC3gtrsIm/Il/sMLNyqAsElRg9RrhQ2ymPRKvglXRLcq5RO12/r13JVne7EL1UZ53/WHuk4O439opyuPjHbCWUedXHEw/ojIfUzvrGH0AOlmuaVXMzD2zxsgDsRnqdiN+BAokgkkFUFfA6Ftyr21qEAWjwds064NQ6o18+TFeWsAdWDN7L5BXZrKFGjpd7o2OL+RlRTCjvRAghQdFuCoJCTVcGwXQjYuR2H+Oea1qVUb6AIjzZNwwpvv1C2/4uOvtXcbe1fs9u8Eg5rs9XfEgecqaysOtgn51A3uPS595T5LRp+9Usflg0iRSD7L9XAjx55+eFwE0i0SLyJr3xx7w0NY7sKC0aMxK4peVW3M6UmzXdsN8w6pcz0yhucF7ZqHW4kHK3f3m4sE525JHFIXyFSctFJODbm5pm1uIt1YwlPu3TU0vm/LDihXRfqyo3pPgsvN3hYFpB6R+TUcUEi2Oqo9tgGmzrXIqKYrrTdSBXHkcRIybEJBVjBdv+SpMVQcZwcYVCAblb0PBwYx6VvU6YqyQLVz6SW4OENa8hjr5G11EWfn0kJl76ClUZvf9ziImhiigvrJhtAiggSUcbduBG35quxqlMAMXHqbuxK/2S2GPkPS/Umj5fPKTPQgrPZDFA372tQuQBnqqAFRjFQzI3/AUjhqQb1M9FwD4YolL/T3IdVsNOmfpNckgNXNgT3ZxC+M+j79mZdUoeew+mAPSD9tjORGDd56ghh+30viSLk92QplUtePFfKnQZv5SytZxSGgB0JWpvmqjAeCCoe2QmZ3Ckvj/9Y0hd2wqQDD7FsJ075C7FkqpLgDbNdGU70sEwpksawjYuPuO/9AVrujxHp1/hRWczkFQhE8bWJtXXlfhLVpHbPdipMSuJJ35DiQKla7GsHoeSvEa06i5x8ow4qQ8S+SmrVneHO+S4Vrd3qLHSk7ku3+YGJ5gsY3UGFZoqhi+R7nKcmlTjb+esCoz3J6p3mMW6/r8r9tJdOJpy4IrqGm8A86mGlEMvPSI8Z4vi/3nLyT01/HRF1z5EWYkWb1nyfnb31FwfHWl810VFT051NYdM4j3RihsTrRiePEOeZOhetjUHDw+eNv1gRkpwJqKbIo4yMrEcxpw9fEaVQC8h4qcq1yIBz58LNFRZj3HCEY8PdYHp+B+rn31st1oNcmpg0ziXpWIWTIS5Gcz/BLMN3ICrBTpj5A
X-OriginatorOrg: workonline.africa
X-MS-Exchange-CrossTenant-Network-Message-Id: e72611c9-e964-47ec-7147-08daddfe835f
X-MS-Exchange-CrossTenant-AuthSource: AS8P190MB1078.EURP190.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Dec 2022 18:10:42.3410 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: b4e811d5-95e8-453a-b640-0fba8d3b9ef7
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 4wmKo49dC/SZXBjTLxEMAXQw2m1ze8kdKV8Lkf41Np2iHmhNW6rAItIE91DaszKvIRAweaGXrrK4kmvtacGW/w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1P190MB0719
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/FVJ5AJfFLgQM7JhVf8fnj41OIEQ>
Subject: Re: [Sidrops] ASPA verification questions
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Dec 2022 18:10:59 -0000
Hi Claudio, On 12/14, Claudio Jeker wrote: > Hi all, > > I'm working on ASPA verification in OpenBGPD and while I have the basic > validation algorithm working I have a question that is not covered by > draft-ietf-sidrops-aspa-verification-11: > > What should happen with ebgp peers that have no role assigned? My personal view (which I have previously discussed, without agreement, with some of the authors) is that the default 'provider/non-provider' status of an external peer should be derived from the ASPAs issued by the local AS. This obviously needs a knob for override on a per-peer, per-afi basis. I would prefer not to have a tight coupling with RFC9234 roles in implementations. Cheers, Ben
- [Sidrops] ASPA verification questions Claudio Jeker
- Re: [Sidrops] ASPA verification questions Job Snijders
- Re: [Sidrops] ASPA verification questions Ben Maddison
- Re: [Sidrops] ASPA verification questions Randy Bush
- Re: [Sidrops] ASPA verification questions Wanghaibo (Rainsword)
- Re: [Sidrops] ASPA verification questions Claudio Jeker
- Re: [Sidrops] ASPA verification questions Zhuangshunwan
- Re: [Sidrops] ASPA verification questions Sriram, Kotikalapudi (Fed)
- Re: [Sidrops] ASPA verification questions Claudio Jeker