Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-signing-time-03.txt

Ties de Kock <tdekock@ripe.net> Fri, 19 January 2024 14:28 UTC

Return-Path: <tdekock@ripe.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A6E3C1516EA for <sidrops@ietfa.amsl.com>; Fri, 19 Jan 2024 06:28:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ripe.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RbusU85WUjZE for <sidrops@ietfa.amsl.com>; Fri, 19 Jan 2024 06:28:51 -0800 (PST)
Received: from mail-mx-2.ripe.net (mail-mx-2.ripe.net [IPv6:2001:67c:2e8:11::c100:1312]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C131CC15106F for <sidrops@ietf.org>; Fri, 19 Jan 2024 06:28:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ripe.net; s=s1-ripe-net; h=To:Message-Id:Cc:Date:From:Subject:Mime-Version:Content-Type ; bh=BO69Ujz5LaZWbbG+6EqFhFIZRmFNfprId2h17GZRNsA=; b=KzW2JlPOprcG8+tkQxMIOvyI AylNp/cP4M9pin5GtoQhukxo/Zmb2Q/9NVUroKbVa93H6DHuO2gpAu0sEp4YObwBfqQdQkubAhGet finzMHbBSt4e/saSHvyo9wQT64LcUckUaHyWz5mvr1bVIYYOlroH9vbpjVTBPFCrggUlUB943tLZZ YrHIV+8RQ7f28qZA2lbAQFbmGS2XV3vDv15pstPhpi7567dCyQ9QiA8nuKZDVzEFMsB/74yOV4WVI KKrJzysy2c+amNfTYwThy38Ta+CkS3G3bQ23roKD9cLz5G8gi0PXj0D56guzAKPU//QW0N8s0o5Sg N9Kn+nbxvQ==;
Received: from imap-01.ripe.net ([2001:67c:2e8:23::c100:170e]:33720) by mail-mx-2.ripe.net with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96.2) (envelope-from <tdekock@ripe.net>) id 1rQprW-000mqi-1V; Fri, 19 Jan 2024 14:28:50 +0000
Received: from sslvpn.ipv6.ripe.net ([2001:67c:2e8:9::c100:14e6] helo=smtpclient.apple) by imap-01.ripe.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96.2) (envelope-from <tdekock@ripe.net>) id 1rQprW-004WSB-1I; Fri, 19 Jan 2024 14:28:50 +0000
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.300.61.1.2\))
From: Ties de Kock <tdekock@ripe.net>
In-Reply-To: <ZaqF_7W-EMiYljxd@snel>
Date: Fri, 19 Jan 2024 15:28:40 +0100
Cc: sidrops@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <63F0483D-596B-42BC-A1E0-86D15D64F547@ripe.net>
References: <170561454824.54895.360140302624981870@ietfa.amsl.com> <ZamgKc5PTJPDcISD@snel> <C10EC4E3-9A59-4BBA-B5DC-DB4680AD0B0D@ripe.net> <ZapR2qVBAu7lECFB@snel> <7547BE09-8FF6-40F4-BC6E-388BAEFE6CD6@ripe.net> <ZapoTxRlSvSSVqk_@snel> <5AF9DD6B-A4F0-4C20-9E0E-62144D013D44@ripe.net> <ZaqF_7W-EMiYljxd@snel>
To: Job Snijders <job@fastly.com>
X-Mailer: Apple Mail (2.3774.300.61.1.2)
X-RIPE-Signature: 059faafd1cc22ebb05e1592c815fe1e18897a599e04c8a5d04f250c6b402b7d4
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/Ni6GHyvJ54FP_YItiMHo7K72jB4>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-signing-time-03.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Jan 2024 14:28:55 -0000

Hi Job,

> On 19 Jan 2024, at 15:23, Job Snijders <job@fastly.com> wrote:
> 
> On Fri, Jan 19, 2024 at 02:19:57PM +0100, Ties de Kock wrote:
>>> Aren't all bets off when implementations are noncompliant? :-)
>>> 
>>> I think I agree with the gist of what you're saying, but I'm not
>>> entirely sure what to add that's not already covered by existing
>>> literature.
>> 
>> Let’s add the local improvement somewhere in the doc, maybe security
>> considerations? “the status quo is that most implementations are not compliant
>> with RFC 6019, this causes signing time to be ambiguous when interoperating
>> between implementations"
> 
> How about this?
> 
> https://github.com/job/draft-sidrops-cms-signing-time/commit/9f43dfa84f7293dc547d46154f0f5296fd5533fe
> 
> -----------------------------------------
> 5.  Security Considerations
> 
>   No requirement is imposed concerning the correctness of the signing
>   time attribute.  It does not provide reliable information on the time
>   the signature was produced and it bears no relevance for seamless
>   switchover between RRDP and rsync.
> 
>   While the Security Considerations in [RFC6019] mandate that the
>   signing-time and binary-signing-time attributes, if both present,
>   MUST provide the same date and time; a potential for ambiguity is
>   removed by restricting the RPKI Signed Object profile to have only
>   one field to store the purported signing time.
> -----------------------------------------

Nice one. For me this expresses the the motivation for this more clearly in this
document.

-Ties