Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)

Ben Maddison <benm@workonline.africa> Tue, 28 March 2023 08:43 UTC

Return-Path: <benm@workonline.africa>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4AF72C151B0F for <sidrops@ietfa.amsl.com>; Tue, 28 Mar 2023 01:43:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=workonline.africa
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JhePI_HZ1Tmp for <sidrops@ietfa.amsl.com>; Tue, 28 Mar 2023 01:43:30 -0700 (PDT)
Received: from EUR03-AM7-obe.outbound.protection.outlook.com (mail-am7eur03on20609.outbound.protection.outlook.com [IPv6:2a01:111:f400:7eaf::609]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2395FC151B01 for <sidrops@ietf.org>; Tue, 28 Mar 2023 01:43:26 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=V6TJ++ueNxYpG+QGUxOB6OfoY1juypc1NRlMKS8Ljfjeo9RcH+jtN6Km7LQ6WgCefh7O0nn+hSIcVuDFCKVFcqIYDbiJb6RlsGCfdlXWf40udK1sfVpH0J+yiyafETA9TUfz7ZjUnniLSIlDu8/HEaH0wJMRd+S83PsjXTVcs3dGb+fBfud7XPKF2QLalO1umZ6t9CM23r5xvnrxxMbLcGmjaNwBrNIi90IDDP/ZHGwviBK2bcJ4LTuG7dyr4X+1HskyfF+R1rDftU2vBIOOE4cKGT4QBS6arrwh/hnCmvQYMrSloTwgjtW/zr5hF1PAjdNd2Ha8iyHQr4TOBNftPQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=enJxQNb0lxyVJPFe3MvUAOLZLidBLBgqIwovkbOT64Q=; b=lNBdYFOM/wvyqrfMZPyNqZe99/CFG/1bSu5/mL4Yu0g/lFxTPA6USP3+d14Bs5g9FvRctCflpQJuy+/5IQ/fp+C9q1v3jFlbaRlVId5h4DLQHygZRpbWfOAgJnzNM+WoiWQjRwHfUPyMffZFZPAxgmg7Of5PEOtPYu2ToL6+N8drbjCGIM7dhmK1Cpl0aWqEllTwJ1U96+4UNgCi8RpS+s0OkZO2GeU5iuc8igwHmOI7Z3JruNMKllfS6FHx7vF5C0m7Bqnd8/vW+fXhMLTin5xJRlFROSe52DlMI8NppQIEKo0rLIYyMc9Dzqd4RVdCNN5Fv7mhsbLw4f2DVluFEA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=workonline.africa; dmarc=pass action=none header.from=workonline.africa; dkim=pass header.d=workonline.africa; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=workonline.africa; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=enJxQNb0lxyVJPFe3MvUAOLZLidBLBgqIwovkbOT64Q=; b=B4xtJCHO37AV59Wk5Xt9WjQpC0B7IxR3R8drmgUfOcVP/5/Ux78f1qL8AcrPav4AskE9runRDMOaSSkY0Ofk17gYTfn71qFea5MmKrvEkqoUU+KrnzggpEJo086bUOIflL3wJMxWJUghOOnYlo8xgBRCu674Oq8YejxbgB8BZsQ=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=workonline.africa;
Received: from AS8P190MB1078.EURP190.PROD.OUTLOOK.COM (2603:10a6:20b:2e7::13) by DU0P190MB1705.EURP190.PROD.OUTLOOK.COM (2603:10a6:10:329::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6222.30; Tue, 28 Mar 2023 08:43:22 +0000
Received: from AS8P190MB1078.EURP190.PROD.OUTLOOK.COM ([fe80::3723:118a:8022:ba32]) by AS8P190MB1078.EURP190.PROD.OUTLOOK.COM ([fe80::3723:118a:8022:ba32%5]) with mapi id 15.20.6222.033; Tue, 28 Mar 2023 08:43:22 +0000
Date: Tue, 28 Mar 2023 17:43:12 +0900
From: Ben Maddison <benm@workonline.africa>
To: Claudio Jeker <cjeker@diehard.n-r-g.com>
Cc: Aftab Siddiqui <me@aftabsiddiqui.com>, Job Snijders <job=40fastly.com@dmarc.ietf.org>, Amreesh Phokeer <phokeer=40isoc.org@dmarc.ietf.org>, "sidrops@ietf.org" <sidrops@ietf.org>, Aftab Siddiqui <Siddiqui@isoc.org>, Max Stucchi <stucchi@isoc.org>, Hanna Kreitem <Kreitem@isoc.org>
Message-ID: <20230328084312.zfj2j2qaa24w5wt5@iolcus>
References: <SJ0PR06MB7677230255CC9134CAF94E98D6879@SJ0PR06MB7677.namprd06.prod.outlook.com> <ZBxcTHebGjhJGpzh@snel> <CAB5NZESXFF68ez7NwK6s3hqYY6ChkHyu_r8jPggO3ysHQB0emA@mail.gmail.com> <ZCGdV7KRNMfaEUd9@diehard.n-r-g.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="lge26mxdlaxy3o3r"
Content-Disposition: inline
In-Reply-To: <ZCGdV7KRNMfaEUd9@diehard.n-r-g.com>
X-ClientProxiedBy: TYCPR01CA0008.jpnprd01.prod.outlook.com (2603:1096:405::20) To AS8P190MB1078.EURP190.PROD.OUTLOOK.COM (2603:10a6:20b:2e7::13)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: AS8P190MB1078:EE_|DU0P190MB1705:EE_
X-MS-Office365-Filtering-Correlation-Id: b28881ce-9787-4579-ad34-08db2f687cd6
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 1ymaDqRzQKk3WN3laxu98SPFkjaanPpnOdnGPnYWSb6yhR/DKoOE58LCcKiaZaC2Gnh8RkJLuRXUlBSWxp76MWbw+EZseWodH+P1+b60tBXHETmqFST7yAcS1xemiyryY0l5hioCGS3VjdH8djb/gLaXXW7Uz31+Ks438Sa2SgsBmz2EPIFB4piHUj5BF2fXsfF+DzxvrHvvEI/kChFFhFNNUQhj+6sNXZRm9sbcpH35u7JUwXrWCmQ/o2Q/2eOE01fjgDmoVp993ec8ajP5C6uLm2PVfdIUBoS3aml3lYftgnEc3BmbeW64NtuPGYEmSaTPQmFml5VtT2SanG1MUJoV+q03ExeBA3iOlGI+TsPN7gmCyeJbpr4wAK+pg5l5QiE1xx//HPIggMpJvbCyS2hwO0LYkRE6WcS96qzYSOWhYUs4wPap/4CpETd2TY6OjFouNGY1DKFiduBTArQ1VDJvgbs4Sjwpr+PP8UuxuaOpb4C2cXzmfKHIMdf5Y0fcS4Q4HV22/8BOGjm/V5WZhmzW0NjCnN+R1qV9tziI1O9RAHPAJCfCEuMQPYtlt3+Kb64iEo0viEshGO6Opc36vU64Z/2COzG+urHPD1Uum3sT2+543wuFD5o1e7SSkVrDT5I1OA+ORM6RpkQkxbbVjE8/2fU7xMOJF9aEUbbedwU=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS8P190MB1078.EURP190.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(7916004)(396003)(376002)(366004)(136003)(39840400004)(346002)(451199021)(316002)(478600001)(54906003)(8936002)(33716001)(86362001)(5660300002)(2906002)(4326008)(38100700002)(66476007)(6916009)(8676002)(66946007)(66556008)(41300700001)(1076003)(6666004)(186003)(6506007)(9686003)(44144004)(33964004)(6512007)(83380400001)(21480400003)(6486002)(46492015)(60764002)(2700100001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: B1tQK/X+ONo5Ged91nj44ib52U2gGggWE5iPWIx4bB5snIJyE4zWmZrPM2qTgkrLmWN3y3Lk4QFBGV3PMxKuR5cibEyxZrm1ibHjujJL3u85z4ocT+E1PJVlrQW+McJsg8OINyLf9m5E8RCOT9UFniZdKB4OWe1aJnFc73ByO2N/kubW7Ddd8Yo7YuzZ+Ab+NSF9aLtao9jGGV6Zw/NX53on8p5/Ge6JZ9RbmZzLZNG5a5d3k5QThpPAo8Z2phQjUw/5ENGXI0QfVIg5l9NV1sfDH7Hwkt1Nqdow1DUkHDornka7L9dCorpf6cy8Wf9u/GCbdh30CXnmMQT9EGCT7EhlKDz3ch711HoUSGOM15mV2NUWoQlA/2T8Sl/p6Yo0dwcnY/YFCIjIPRee9f4uRjnm+qujnc4EOglBLv1lI+7MpGr/MLDwgiCW3Ccs4A9UoldWGLA7ZLv6/gCY2gWsvmCzYovClnWii3ylO5F0acHkQ+1HfFtzjaXWxci3j7cgg/4W4/XVucXvL5yGI46arbtSTq7g321oLV7wXFzqgFu5IPj9m7oVuSwwmJ2ldiXKboyR2FngrkLgp1CD50UDYLR+XbcUzs/o1dR0U4NW3PjwmIL8pWIrYDUrhXTMyOfb3LwgsCYOtE3WkNvTSFfnDQDzrVyliESUP+QAUkTzt48Sc/MetwEFZOA+3+1k112vTca1y0BzWqrRZKF1JH0MOoPS0u1l+YaidT/zSBnE+oRmGM+li1rpiSEHadgRMvf8lVEaWiz8SlNkEYzZ8hOqZRRlwvTV+LWFXWtcVvu9kcPit6PqkxNu3VA8b6xAtOCDC4AhHSrfxCiE1XoCFgxPWh8BYWH4F0zWxqHUAmQUdQ5wTClbj/F0sZhmbgs6wjWG4xILugCTk4EHhRzG7s0+PgfTgPhaWwW+YbcW0rhNcnNt9eDja4iyjz50u2YQwC/qH0FohvwYvIHOnHTni/MOAk4zSu5B6J9DVgooEXPfxJMWh7hv4wBgX+69FEJ1piR9MX5Nesd9n+G1EOUhVYRiyQkW5q8Q8RRpxjozK+v3w6+LaJ69v6QBdRDLDQE8zeAJub6CEDhWGbGkQyugm9+nN7tCM5FucokVwXvcyLbbypERbImd2VKXueWB/D9qqtUZbERkqPkSzElPF7LO5OtdnVrcCEVBEtx+RkIuK+Q+ctC5/JtB09slg1w/B+ND8jd6IISJgRs4CrZ9UmXTJ18PnTDvdUH67Onw7VA1l91Aei1SIWow1SnC5ZUYr7GNk6oe8irwf1HRJsn390Q9tH5znWWpSzreVKDDkkyQHb/V7yC4xNa2yX/ihrZwjhK4CBVGGOnPbO9hWWDui8YIBnLEcRLGB8S/xTTrokbvlrneIq7ux2hBHbE1xeHLI0t81PtsmtV6pf9mVFa59rrs4Ccv9G8YSmz9V6gqKPQMzvvJ3vmDpZ/25owjTrofG7v0ARX4Wsd1Mb5Uc6c8oG1gjsopSNKeYWAMxCi8I8zijS2zleSHJOjLly1ctBZk8B5O0nfWfN7a3C3wBzC8YtrPLWaFQPbCEANoVJATGEPytsj8KaZS3ZpAo/U9kKWQkcitv+VSvMSyf5H4KYWDLhSibOUoH+4Xq8wFLPg4Y8g46ggiwhwXV5feUnez3V8IsXxl7AJ9
X-OriginatorOrg: workonline.africa
X-MS-Exchange-CrossTenant-Network-Message-Id: b28881ce-9787-4579-ad34-08db2f687cd6
X-MS-Exchange-CrossTenant-AuthSource: AS8P190MB1078.EURP190.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Mar 2023 08:43:22.4401 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: b4e811d5-95e8-453a-b640-0fba8d3b9ef7
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: DHoUii0PLRJ5VVpe1ZUbnUT+K3lm19rpnOv6OX5SPZk5yL8YD+LhVk5XM6D1ToXde3QF84bzWBjwlOI06IZy+Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0P190MB1705
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/PowMbyQgtLl0yXoDrQmpbBWvqRg>
Subject: Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Mar 2023 08:43:35 -0000

Hi all,

On 03/27, Claudio Jeker wrote:
> On Fri, Mar 24, 2023 at 11:35:35AM +1100, Aftab Siddiqui wrote:
> > Hi Job,
> > 
> > 
> > >
> > > >      *   To make it clear “AS 0 ASPA MUST only have AS 0 as Provider
> > > >          AS”, it doesn’t clearly mention that “normal” ASPA (non AS 0
> > > >          ASPA) MUST NOT have AS 0 in the Provider AS.
> > > >      *   In the absence of point ‘b’ what if AS 0 is added as Provider
> > > >          AS in the ‘normal’ ASPA?
> > >
> > > I'm a bit unclear on what is meant with the above two points, can you
> > > further clarify?
> > >
> > 
> > As per the definition "An ASPA object showing only AS 0 as a provider AS is
> > referred to as an AS0 ASPA." i.e. {CAS, AS(0)}
> > Any ASPA which is not "AS 0 ASPA" is referred to in the draft as "normal
> > ASPA" but it doesn't say that normal ASPA can't have AS 0 in the provider
> > AS. i.e. {CAS, AS(139038), AS(0)}. Yes, there is no reason to have AS 0 in
> > the provider AS but make it clear in the draft.
>  
> Adding AS0 to any ASPA object with other ASID in the SPAS is not altering
> the outcome. {CAS, [AS(139038), AS(0)]} and {CAS, [AS(139038)]} are
> equivalent. The big unsolved question is if the profile spec should limit
> this alternative encoding (with the RP software enforcing that MUST).

This point is key. Disallowing AS0 in PAS, other than in the case that
it is the only item doesn't actually change any behaviour or fix
anything.

The only benefit that I can see is that we guarantee a single canonical
representation.

Enforcing this in the ASN.1 of the profile can (I think) be done, but
would significantly complicate the module. I'm not convinced this is a
price worth paying.

I do not think that we should introduce new normative restrictions that
are *not* described by the ASN.1.

Cheers,

Ben