Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)

"Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> Thu, 23 March 2023 19:56 UTC

Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA134C1526FB for <sidrops@ietfa.amsl.com>; Thu, 23 Mar 2023 12:56:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nist.gov
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3eAcacV-uYQu for <sidrops@ietfa.amsl.com>; Thu, 23 Mar 2023 12:56:52 -0700 (PDT)
Received: from GCC02-DM3-obe.outbound.protection.outlook.com (mail-dm3gcc02on20715.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d04::715]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BB994C14F6EC for <sidrops@ietf.org>; Thu, 23 Mar 2023 12:56:52 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Lhkg1U5bmdkUik1AQ9FBm1gLWZBwSD6qhzdBxvenbwj11JdhUSDh1s1X2gLqaC1K0dVT+14Cv6CUcfeLEKgombcLllAr+AfSufHo+HKWZgB24aRdUCFBEjQmSd/Wzg584NMYMRra8rRg9eQhlikk+syu/4hskE/wg40Y2ty5WziycN2ar+MOOxN0H4BzMhWR1D4nTNO/Aw1nqYSbpaRWjsHISQ06rndirR5nYxcIpRL/TbGguRKiFc9ygfWNgdSziYEW++pLvER/UViV0ACmGCN3qIuloftDZd0JhCArN0qSIa5Ar4c/ReKYPX42pC1gbaiHQCDh4D+X7TJCx30YVg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=U8WsJMqaI5z5oReLJb+dMHo1J2fBy+pWEFFeRPHiS78=; b=R8i7Wp+ldoL0cS9GBcKQsqbgUlo0Tyln2mj4dzBImOBHNF/miDztxCA5w9eO1MBldKzQaaFTPOCYbbyMc5r3L6Xy5qLUyLErlPwCeKTHuXvy4FpjB4Slcy92KCbPpvG5mqGv+VEkl0h+hAS/TzzOvJ1KbPXjqiNhBzvMA8U1Gyap15tpErCEUzxeVi5gZMLRGYqWattCXoarsNchYgVGFqyL6CyYFom0GSalsu3mm6zRJgrnlHacmLsh/TseVyXNUTfY9lrDIFyrOj9NglVDCyuobGDO9p1pCX264TTv9Sa6/3LzNxb4zX9c+DuZsVOGldxj7G01u9Sj66Z2Oizvcg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nist.gov; dmarc=pass action=none header.from=nist.gov; dkim=pass header.d=nist.gov; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nist.gov; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=U8WsJMqaI5z5oReLJb+dMHo1J2fBy+pWEFFeRPHiS78=; b=r/Q1W2hOECQLA18/wKUQxnzjma5MJ8BguDE3RVyrhwmWS1aALb5Jkijt4vrBSwpbwckz4pJUYRA9Lks0c81RXf4DT+NAHfXXyvTHcj6vPsQ+2xQ+2fxtvzs0H9PjrjXdSMRRGakcsMGUMx5WFzbmrkEFZtUwRI/irewLRZJ2CbIo8/CHLlKotMBc/QIfZUJDS0A/CwPCkDLo3U+bdX3JEAMyXyv5c4SKiYfsHdPkzSmOgwQYjEh2wds6+av1tCqFUMAmBTjK0gd9NebpL82IPAnzJoP3QDtLqNNAEYWULBH+IPVIqnuhtqRN4SnCmM8QJ4MfqttLaYaL0pRddq1rkg==
Received: from SA1PR09MB8142.namprd09.prod.outlook.com (2603:10b6:806:171::8) by SJ0PR09MB9546.namprd09.prod.outlook.com (2603:10b6:a03:46d::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6178.38; Thu, 23 Mar 2023 19:56:45 +0000
Received: from SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::5a71:2eb6:5ff8:eb4f]) by SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::5a71:2eb6:5ff8:eb4f%7]) with mapi id 15.20.6178.038; Thu, 23 Mar 2023 19:56:45 +0000
From: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
To: Claudio Jeker <cjeker@diehard.n-r-g.com>, Martin Hoffmann <martin@nlnetlabs.nl>
CC: "sidrops@ietf.org" <sidrops@ietf.org>
Thread-Topic: Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)
Thread-Index: AdldwWqJMQG1SH+fTZSdILVx1RPLLA==
Date: Thu, 23 Mar 2023 19:56:45 +0000
Message-ID: <SA1PR09MB81423B8F34F3F94C774D4BFD84879@SA1PR09MB8142.namprd09.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nist.gov;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA1PR09MB8142:EE_|SJ0PR09MB9546:EE_
x-ms-office365-filtering-correlation-id: 9a1ee83d-7608-4605-9a6a-08db2bd8baf4
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: wiNhj4RCfGm/6yOMMfXcGAtoiot9ddl+/2iBZyAGEEDaiHv9DeaC39T4ilzKLtLwD3LTw2VIlYkZBF1Ved+eNjHiyjJtkcbmSLR1lmqtkfxEwCbxgxjuy8WydTL1z7FMv3/wp05wFFwpmK//oIXchxuHqxgyEg9ursUxAuP79zV5bjlmXx2sRw6h6YVuZLnwvmUEqsxcWVjOm0/qHC7Rya/uFN0RKQFfxlBft1ti164AduiqBazHV2jEpnWIx8kz9mn6b1nZDbf4NgPNfrkdmrvBHVDbsMhhV9J+kJHQnAWGzyNdcBTGE86MnueKfbMIS4UCqd2SEdwan1rxXrlJVtnBivPYpbXHeWjWK9unfSYKYfuOcwYP0wRi+PTW17yIJtYl/L7SAU3C9VgeqoCCECJVeCP/d1HW+RINMRnHFznN5B7q0FApEvPSCdbr7sWidW1B32iysGeG5xggMc8Dn5HalP1IKn3QB4pKkQvtDXAC6V1MrK/HE8oL6hiZVnXDh+F3VD9m4NSaHhpuj4+NtfrHJMVjSn5ppKX/xpZLT9Fzi7iO/gDJUnxsdOzuT9Xa6AmjOuprwnVYUhY+jnGEfpfFVhjI/sH+cagCRi1Hm0XMwGJy1s6SkKu3LX0OAJ5TmCGnaTLIyk0K7sDXtnZRuZBypaG2dw3BE66cxAuZRGQQNgQ4jM23MYlv9MEP4MG5
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR09MB8142.namprd09.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230025)(4636009)(366004)(451199018)(33656002)(38100700002)(86362001)(8676002)(4326008)(66476007)(64756008)(66446008)(66946007)(66556008)(52536014)(8936002)(76116006)(110136005)(71200400001)(7696005)(966005)(498600001)(15650500001)(2906002)(5660300002)(82960400001)(38070700005)(55016003)(26005)(122000001)(9686003)(6506007)(186003)(66574015)(83380400001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: UbONRPMptDPGzoe+YTgx3QWFz1uWrx8bDTeegUZA+VApNi68EH7NiJ3k2yBn206PkAHU1U68Y7aQkaQjD8XRNcGKGQP+SdYZ3QdIDetqy5UXJU1dA8mgBjl1aSb8ehaxxS0rrib45SG7If0beo5aVc7/xU1OxoTJJEazAUORglO3CfMyy2Njnst+Tcjb1+lo1CQql3DueiQM38Po5W2iWW5IPyWHXnxpCchAI8eTqV1L276/W9PPrRxXHS8gbgjAWwVDbiReDH+QPMRqQggWn8bXI1Re2u+f2nU3Yvr3X/kipJLk33eibLITXFTfHhNqvUUrWmx7t1tRbv4tOdjeoOVHK7pd1SiFN6GOkUw3EeOvOpMn5RYGV9cTSZ1reWZHGgQeYZAX+K9OgHVfBX1ZW2xwl+Hi6NkF7h2Tt/P3v5UYqmkHVCLwd02p5z2YvypRbtjemqNZ1oNQb4ip3NOhl2X63+V++2FGv9mrIxtwkBeFrkX7fP2AS4J0AzW9cDFSQsD6IYgqLI5+aUxlPtlsDeLjAOM1vFXXmWt4CqMykIwk1VP7KhjFEcgV+NUWHb10IApsYJpcMPOwXxeTEdLEas7u6ljNHe5K12Z9zFdzGAsPVyGu5ItEojZhDKXKxkS5LnIScmAU9uncnCa/XrE1kQkpdPc/tS4xCv4YrDLL0zkxLKfAt8wdOKH/QxQV6lQJf7bC+HMDSGMFBqShL4Q1mAr9ILsX+KpW0/7yHcc6hdlAMORLy4CR7T7IqpcShL8SlsK0INqvzsl5p8qx0knrgmkZNAFD3aOiH8qyIpzLFIz8t/X8yuZG8NYt8MhQqqcKcl3vJEFyxXA2IRPPPr8aaRlhVLup9F3SMBgvs30HtIoj75FsDYiaCS/l/u9ZVvv3yUH0eYI7A0tMcVAcP3JHHn7v8sZBebPM5Ii+cXg/LoLdSwNYXzR9mtfGT3xawEfTSHPwE0Wm5B4QF6lj/gzDZ6qDGNch286OpXnTSf9YIOBX/wq7WpaRr7bKEHFE1avik4MsJjV3btgwu1xSL9RrI+3o7Qy+c34/boiOQkV9umrqSSRR/wWuf2i+pUAsscMsWpPc6X5vl35sZMa/qMEgcw0bvAUot3Q9o5cr5H6IllidEnd8BM23MTCjyVXAvajAaW0bd08kAeJi7XONZQofryAfXEznZEkRSmYiv1/eNmhBmMKULdeoGAi46hbYV9Q76zyzHcP2LG/JyTyjSPH+cznzEmF0hIBCB7ruIZvcE+kE8H05kQGcBix1m6HoCGu+Ryh1WIpp29tgJ+hjnUuZNW2DGrgLC807WKOF6ZWek4wcIAynIOlASHaQi431CqxYlcnQbD1koReRd9nqex7rY/WcTa3zJ0bz95cpKMTwRZI5dVGiQLYI3A5MmtVVSG03Lq/SUn+jTjt1j9UH5mfLxPzdCyq6kvNzCdtIs0YrNjxb7PZpkCimGCvMZ5hvh5wQsawjggFprwWfXlkmSWsDtbhYOh9rSHtmuakJfUkKws3imo7I9o/h7aGVNd3RtP9abx6Xg8i3WkqF9/ejUr3qvnvk1raiPf5SwkmSM+c8wLg=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR09MB8142.namprd09.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9a1ee83d-7608-4605-9a6a-08db2bd8baf4
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Mar 2023 19:56:45.2267 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR09MB9546
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/PDGx-InWzRFih_Nim3u8WhrS9Zg>
Subject: Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Mar 2023 19:56:56 -0000

Hi Claudio, Martin:

I have followed your discussion closely.
Can you please read this post from me and comment? 

https://mailarchive.ietf.org/arch/msg/sidrops/vy9n1StEQshh38-nEs7qTf-39O0/
(Claudio:  Also, an important question from you about ASPA interpretation is answered here.)

We all agree it is OK for the ASPA to allow afiLimit unspecified and there are benefits (the verification draft captures that correctly).

But after X.509 validation of ASPA, we have VAPs and then the SPAS derived from the VAPs, which can be called VAP-SPAS.
(These are different from ASPA-SPAS -- those are SPAS pre X.509 validation.)
I think it is inevitable that VAP-SPAS need to be differentiated/organized based on AFI.
Because for a given route the router is verifying, it is either IPv4 or IPv6, and accordingly it needs to look up VAP-SPAS  for AFI = 1 or AFI = 2.
In that sense, the 8210-bis ASPA PDU seems fine. It is reporting data post X.509 validation and per AFI. 
The router can use the data in that form (per AFI) to its benefit.

More details and examples are in the post mentioned above. 

Thanks.

Sriram