Re: [Sidrops] feedback on draft-michaelson-rpki-rta

Stephen Kent <stkent@verizon.net> Mon, 11 January 2021 15:31 UTC

Return-Path: <stkent@verizon.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6B953A0F06 for <sidrops@ietfa.amsl.com>; Mon, 11 Jan 2021 07:31:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.362
X-Spam-Level:
X-Spam-Status: No, score=-2.362 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.262, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verizon.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nfTIal1SjQq0 for <sidrops@ietfa.amsl.com>; Mon, 11 Jan 2021 07:31:26 -0800 (PST)
Received: from sonic306-2.consmr.mail.bf2.yahoo.com (sonic306-2.consmr.mail.bf2.yahoo.com [74.6.132.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 806743A0F04 for <sidrops@ietf.org>; Mon, 11 Jan 2021 07:31:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=verizon.net; s=a2048; t=1610379084; bh=MLoGoXX8RB/jcEFor1nn8a2T9niZNoItn87T9mFAF+Q=; h=Subject:To:References:From:Date:In-Reply-To:From:Subject; b=ue7W0JkwoSlwLYEmYN6UDCMw77v1u/ohhlKew0VfihOV2/J8tQ52TYolNfOVwCwSXq/BOPJhkGfn6mCma6NFuaEPX0TyMx/i4REvGx+jwtEwxeo45ROG1MyxY2fytVraI2MupQ43DSM1H2slISZKSFmyxotj7X6uPEE0bMt9bwa7N44wtvayt3Z2l8TJ+R6FT3WWCiANWLC5ae6rMiyKTIQ5cpBZ8ZNbSw5zm2bvtGf40qU+XfZDgGyfJkiIiSm01A3wC5m1b6sAHhv17spnwXVpOIO5nnBuhh9ZQqaHkjMt265eX7QSBv5epRqH+2RPAnJgZ1nqk3rTKYdjIWz6bQ==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1610379084; bh=9ZG6AQarY7r2x/M3AYGkXsAbBN+JAXmXRKE9FbkOiwZ=; h=Subject:To:From:Date:From:Subject; b=qOTbn1HC+nyTDDSXSdbrSOV9Kvq15LBwtdtzK8uIzp18foCKDtwLUoGj9j5Qf/hKdVcaSolC8hTYhc0fDDCNa2VVzwXF0Udz5Nbj2AymJFAvwsxCZOnJr7PxPvLxpU0lMfpsnH+CQkR4ZVi79MS1WBN1J9c/SWCushc0sV5KpRtmer1wjWjhEquTCtOOm1ztVR5zd1Y3ob0OF+rGTGjzGmwlEbyCtLG1t3y+pJzhoqxAbSNk7YkhX9pBH3reskvWue8FBWpiou2lllzobU4Byqm1HwKQX8Z7V//D4Um5V7gsnyfuZFxoGZXP4xjZ0SQ21pAGFcI66d9ZdIiy5ugr/g==
X-YMail-OSG: yCf0bdsVM1nhjOFtf.ANIQmUZj73fVcYd..YdvB1HTm3o3T1CBpWAnKyWpfumPT ytFuWztbFLsgvR2UM4nEPWyVD.d.5zJ4XXHMUyUJ503B1wQfO0ILbvnpES9K81TAXOe0PkQjtaoK jxbf3Cre0nv0U5VWDiUFAdcrTWtXm0vyMdnNREeEgl7UeVVqdq66sCZWWQybWwb7Yh0UQhBW21yC fGIx1YqyQd_UOJbV8F9nMQKva1bM6AtvqfA4V3z5yOa1iluf_duokho9lWOIukrnB1TkeewADSYe vt.PizVuJhKKy2DtoswDQhUhk4cQJDvNuVF2Zm8.wKH0Ez3hRVhWjbOhdX9H81g5I5CeGBET9_n. pOBmxHp7lmGe9FKdp3Ruz_vH5q3PRxphVSRNP2ObGVEpAvMzthjf79eVHDL6EEwRyrYmQNTUycoK re.xFMiF5zUoel0fap35uVOKndII1rkPYwNrCW80uPG8nB9QTdfk8etXK8xQo0QRUMfKe46eVr26 e_vpQHeG.SYSjF34ZSQyKUId7Jp55Zx0S7C5R9._0UNhNUDNGu8PjRsnwOQk0eh8RuvTciNWUVA3 bq_xZoaKSxV61ztHLbgczyAtwhu5BFT6ybGD7OBonllPjYJLq1ctm5ZYmIQT9AEOm7yhppq43Oux iYf9zZFKP16LbGvyjHTP8ZY_qP7jKX7lL5k.BIvwJlAQ8SlfMCxn9Unh5BPBpcKMKNxNT3DmMvDp qABVbvIVtQFm0KZZeYZym.rtqW_8dgfTQDD6aSOQqJn6kbjV0_XIIKnfXD82c2ahbGt4fqLoc4xU omXmsSiogUA.ysXnxRPs2VNtnlb2tdiWOFU5KsovWY6KlAtD8m4d8kkObDXObjNKIPM1Lh5IVig_ g5sQAiNifdQcSjQkJiJ6mYuFMJ9mBMiDcFb8BzjegcIWuLucV9pAiTCMoFUAZ0wNyF1ayoPwd.uu T46_hm5lEK2cvX4.oekDzhJnuPKxI3njgCwmjA7KOcWTHwxRS.s_albMils0QCuEugwr_6agwMpk VcPT9UUVukLG9DErMuZeVlGXKDJj246SPr8tzkfZcj1IR5kYHBaOsPCH_a_XpfdooRIl.WkP.IPS oozircHdEJYgR3FiSVSL8r7a9C9vnbNQb1XXRazyoFMr7lyFb2c56bKYZT17HzDgOEXuPDPQ.dz0 JUsl709OF8Csa0EMVyekGSGVZJYjoPR83gwveAyzXfk_kw_qFhnELlgQvZy8xT2J3GQ8APmYqNhn EsBYpc00o90jpPxiKccoYFN.PxrxeqFWJBcNQihlSR8lOGYTh8qPhRIFqr_dKt9PQRUkV9IYS0yY EgISMyqh6ZwqeaZB3lGa_bskwvezo9d0gzGGFWWmnTM2JgwZI1KHbvEQbg_Nwu2wibtl_2.nDeT7 Biq0vy7_LBQC7F7k1ykGGvILwMW5xmb_yRII01JAMKQvpVzFYkkIHVvynTSoAYhQ2yx86MADOkCQ AxEHfjg3aUkEwciGtEMUsaQmCoL96uHZWZuuQwxREW0Z.Cn55PLOfNJzVK6ROlK4bQRHsMMoXg7d hVCvAB41RVY6toRtBv6a.0XWnXJ.i8KdaI6g9605cg.q2jJG3WAlDKlVyWyV38dsx.AI4GwcwG7g wT87g9wj4b0NVABrliLmpoMBf9b7K1HQ_mfQ__BIP1ELGE_u4dRSZb3IQ3orR9yAJ1ySEWUiu1XA syGIc04cVS25GfEN3TZggDX716L7O9nmOeu7JnJIQrv27kJ_X7G0BTWyezo1r7x3amtF_aekEZwh e_w7q2aqGNgZHxZtmF2UPlV1IEYxlEkEqipq8Ng.Snt.tLgw5Ys3c0VnyagR9NtMpVzrb3dg_BC6 tNcEr9Ml.Xjb.oiLiwuHBGdLIyt1QRS7o8mu9._lB9cHsQ.0YH77kzJet3WzZWv5aJzKjco4CnUK pjSpA7T3YbWIrQ6C0.JBEIvp6.ZlqvxcXXzmcij_1vTATqb5qingXYDrvO6o1CNnjc0M.CY7Ve6g RbNprj5RcUECN9VYQ_dBve8umNgROw1XED4vdthWiBXl.XnPAWFbAZnamEbutQHsT316K9AugwFP Tc511deP7J7WS18Uw7Ja.oqZbpqFFYF9x9f6vKxo3ddIKM.tT.lR0MjO4.s42SmFtKrEPpgiur_a 67xmT47J5iNwJ2l9ZusSZFIgnLgWV21QZQxUz4jnpQQCbmuVmk0OYtw84AiPHf3YgEQMsNEinhFl joSxjR_v4kZrMyyJFj5Te7gBgPPs0AXU3O6IH7D2oHL_FOyeJ1pnkC2.nuGMT1tTJGQkQadh6z.R 7xzVvzoozaGTcVV0rAOC37Fu_5q7H1UdO_PG.NsnrZiDxW6I861sWCAQ5NE5Qt9bS2Uf.JKyrzv8 CGiqR9ed7RIJdJfYZm6fBEjkoosJJZum_S19feLBj_igT68xCbFr9j3VW2gfcPfLgEfFlnip6dps _0eNArf0Qqw--
Received: from sonic.gate.mail.ne1.yahoo.com by sonic306.consmr.mail.bf2.yahoo.com with HTTP; Mon, 11 Jan 2021 15:31:24 +0000
Received: by smtp410.mail.bf1.yahoo.com (VZM Hermes SMTP Server) with ESMTPA ID 588cf9148e37fdbd0c1a2e9a064f25ce; Mon, 11 Jan 2021 15:31:21 +0000 (UTC)
To: sidrops@ietf.org
References: <X+d3+e5Rj/Q7Dchv@bench.sobornost.net> <20201229101412.GA56136@diehard.n-r-g.com> <X+scpsd6kDQ72nLa@bench.sobornost.net> <49a8e314-7b3f-0e8d-6e20-7d055fb1a076@verizon.net> <20201229151639.GD56136@diehard.n-r-g.com> <X+tR06kF3aPZ4+18@bench.sobornost.net> <20201230144836.ytg4u2gobkv4uzqn@benm-laptop> <3BA339C3-EADC-449E-B5B2-7A4880E16EDA@nlnetlabs.nl>
From: Stephen Kent <stkent@verizon.net>
Message-ID: <523f7597-7de9-d8db-f9d0-eb3b9b08f5ed@verizon.net>
Date: Mon, 11 Jan 2021 10:31:21 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.0) Gecko/20100101 Thunderbird/78.6.0
MIME-Version: 1.0
In-Reply-To: <3BA339C3-EADC-449E-B5B2-7A4880E16EDA@nlnetlabs.nl>
Content-Type: multipart/alternative; boundary="------------3EAFF5FD4A13FC928DED92AC"
Content-Language: en-US
X-Mailer: WebService/1.1.17501 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.aol Apache-HttpAsyncClient/4.1.4 (Java/11.0.8)
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/O3YT7zdwQHBPZPt2siTGB_6xocY>
Subject: Re: [Sidrops] feedback on draft-michaelson-rpki-rta
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Jan 2021 15:31:28 -0000

Tim,

You said:

    The use case is intentionally*_not_ limited to secure routing*  and publishing in the RPKI may not be necessary in envisaged cases.

The CP (RFC 6484) imposes constraints on the set of uses for certs 
issued under the RPKI (and thus containing the designated policy OID). 
As noted in the introduction, RPKI certs are "designed exclusively for 
use in support of validation of claims related to current INR holdings." 
Using ANY cert containing the OID defined in the CP for ageneric set of 
cases violates the CP. Thus it is inappropriate to publish a spec that 
uses certs issued under the RPKI (whether published in the repository 
system or not) for applicatons inconsistent with the CP.

Steve