[Sidrops] Roman Danyliw's No Objection on draft-ietf-sidrops-rpki-has-no-identity-06: (with COMMENT)

Roman Danyliw via Datatracker <noreply@ietf.org> Tue, 19 April 2022 20:03 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: sidrops@ietf.org
Delivered-To: sidrops@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id CE1763A116A; Tue, 19 Apr 2022 13:03:18 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Roman Danyliw via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-sidrops-rpki-has-no-identity@ietf.org, sidrops-chairs@ietf.org, sidrops@ietf.org, morrowc@ops-netman.net, morrowc@ops-netman.net
X-Test-IDTracker: no
X-IETF-IDTracker: 7.46.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Roman Danyliw <rdd@cert.org>
Message-ID: <165039859882.4772.8718431308370982924@ietfa.amsl.com>
Date: Tue, 19 Apr 2022 13:03:18 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/MZXCry2E_6a3k0UzMmXRcjq7CHM>
Subject: [Sidrops] Roman Danyliw's No Objection on draft-ietf-sidrops-rpki-has-no-identity-06: (with COMMENT)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Apr 2022 20:03:26 -0000

Roman Danyliw has entered the following ballot position for
draft-ietf-sidrops-rpki-has-no-identity-06: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-sidrops-rpki-has-no-identity/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thank you to Kyle Rose for the SECDIR review.

** Section 2
   Given sufficient external, i.e. non-RPKI, verification of authority,
   the use of RPKI-based credentials seems superfluous.

Consider rephrasing this sentence to clarify the application of these
credentials.  For example:

Given sufficient external verification of authority (through non-RPKI
mechanisms), the use of RPKI-based credentials is superfluous for <explain the
application>.

** Section 4.
   Attempts to use RPKI data to authenticate real-world documents or
   other artifacts requiring identity are invalid and misleading.

Recommend describing what is mean by “invalid”.  In the cryptographic operation
sense, these signatures are “valid”.  They were just “misleading” in terms of
the degree of authenticity they are providing.