[Sidrops] Re: new MerkleTree/HTTP-based cache syncing approach: draft-spaghetti-sidrops-rpki-erik-protocol-00

Russ Housley <housley@vigilsec.com> Tue, 08 July 2025 16:55 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4C706417EAB0 for <sidrops@mail2.ietf.org>; Tue, 8 Jul 2025 09:55:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.868
X-Spam-Level:
X-Spam-Status: No, score=-1.868 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.232, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vigilsec.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vkE55caAu10e for <sidrops@mail2.ietf.org>; Tue, 8 Jul 2025 09:55:05 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 859FA417EA92 for <sidrops@ietf.org>; Tue, 8 Jul 2025 09:55:00 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 613961A1A39; Tue, 8 Jul 2025 12:55:00 -0400 (EDT)
Received: from smtpclient.apple (pool-96-255-71-95.washdc.fios.verizon.net [96.255.71.95]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 51A3C1A28C3; Tue, 8 Jul 2025 12:55:00 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.600.51.1.1\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <aGw0FblU5WTN1D48@anton.sobornost.net>
Date: Tue, 08 Jul 2025 12:54:50 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <EFFB771F-02BB-47D1-B1BC-4AA8712708EC@vigilsec.com>
References: <aGw0FblU5WTN1D48@anton.sobornost.net>
To: Job Snijders <job@sobornost.net>
X-Mailer: Apple Mail (2.3826.600.51.1.1)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com; h=content-type:mime-version:subject:from:in-reply-to:date:cc:content-transfer-encoding:message-id:references:to; s=pair-202402141609; bh=0S2f4ypw6JfpNqHM+zRjvExu7lC2tRyniP7hX5wXXc8=; b=rIFPpfE6E+FrnXFf7cH+Lo9UnIl7sELieB6JN06Pg+NgDWsDcpVicZQn7Nn4GQlaqpv2M34kZ0tqkAfI59T80walnCfgxKylKnIa16DnJaS+bvObTF6MnIqhTlWNKdX5tZqWAU/lJ6v90/aNnYiyK4NLI5jHxZPjKOXX+72jdl6zHXhHYc++vUKfHOLQuyopRNepZwouOLWDkpnWsFUZ1t65h8Q56JCHudmcvxU4JUknNxjIP4GJAPlPtJr8/o8C2NNLkPuZPVk6rp2npf7CFsrVovFcL84H/28m3sKS+Y97+IK3Up3OiZlY8T0rVuoVfHC8AWXqzFLlNk6nHyQ6Dg==
X-Scanned-By: mailmunge 3.09 on 66.39.134.11
Message-ID-Hash: 4MOY34UVUUPBJ4MKGX73HDPA5OJHXYPZ
X-Message-ID-Hash: 4MOY34UVUUPBJ4MKGX73HDPA5OJHXYPZ
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF SIDRops <sidrops@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Re: new MerkleTree/HTTP-based cache syncing approach: draft-spaghetti-sidrops-rpki-erik-protocol-00
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/J0e3I4YQSZ2msmQYQs3RAEQTJ9U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>

Job:

Why is the OCTET STRING wrapper used here:

	...
	location OCTET STRING } -- subjectInfoAccess extnValue

I realize that this is the form that it might appear in a certificate extension, but in many ASN.1 decoder implementations, this forces two separate calls to the decoder.

In certificates this was done on purpose as part of the transition from the v1 syntax to v3 syntax.  Such backward compatibility is not a concern here.

Russ

> On Jul 7, 2025, at 4:54 PM, Job Snijders <job@sobornost.net> wrote:
> 
> Dear SIDROPS,
> 
> Here the internet-draft that accompanies the earlier request for a
> presentation slot at IETF 123. Request archived here:
> https://mailarchive.ietf.org/arch/msg/sidrops/1BI8PMtGicJnys5GAHBttqWMeVw/
> 
> Erik Synchronization is a novel promising approach for RPKI data
> distribution. Please do a read over when you have a chance! :-)
> 
> Kind regards,
> 
> Job
> 
> ----- Forwarded message from internet-drafts@ietf.org -----
> 
> Date: Mon, 07 Jul 2025 13:36:26 -0700
> From: internet-drafts@ietf.org
> To: Job Snijders <job@sobornost.net>, Tim Bruijnzeels <tim@ripe.net>, Tom
> 	Harrison <tomh@apnic.net>, Wataru Ohgai <alt@nic.ad.jp>
> Subject: New Version Notification for
> 	draft-spaghetti-sidrops-rpki-erik-protocol-00.txt
> 
> A new version of Internet-Draft
> draft-spaghetti-sidrops-rpki-erik-protocol-00.txt has been successfully
> submitted by Job Snijders and posted to the
> IETF repository.
> 
> Name:     draft-spaghetti-sidrops-rpki-erik-protocol
> Revision: 00
> Title:    The Erik Synchronization Protocol for use with the Resource Public Key Infrastructure (RPKI)
> Date:     2025-07-07
> Group:    Individual Submission
> Pages:    14
> URL:      https://www.ietf.org/archive/id/draft-spaghetti-sidrops-rpki-erik-protocol-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-spaghetti-sidrops-rpki-erik-protocol/
> HTML:     https://www.ietf.org/archive/id/draft-spaghetti-sidrops-rpki-erik-protocol-00.html
> HTMLized: https://datatracker.ietf.org/doc/html/draft-spaghetti-sidrops-rpki-erik-protocol
> 
> 
> Abstract:
> 
>   This document specifies the Erik Synchronization Protocol for use
>   with the Resource Public Key Infrastructure (RPKI).  Erik
>   Synchronization can be characterized as a data replication system
>   using Merkle trees, a content-addressable naming scheme, concurrency
>   control using monotonically increasing sequence numbers, and HTTP
>   transport.  Relying Parties can combine information retrieved via
>   Erik Synchronization with other RPKI transport protocols.  The
>   protocol's design is intended to be efficient, fast, and easy to
>   implement.
> 
> 
> 
> The IETF Secretariat
> 
> 
> 
> ----- End forwarded message -----
> 
> _______________________________________________
> Sidrops mailing list -- sidrops@ietf.org
> To unsubscribe send an email to sidrops-leave@ietf.org