[Sidrops] Re: Call for WG Adoption of draft-snij-sidrops-constraining-rpki-trust-anchors

Marco Marzetti <marco@lamehost.it> Tue, 27 January 2026 14:42 UTC

Return-Path: <marco@lamehost.it>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2DA37ADBD7AC for <sidrops@mail2.ietf.org>; Tue, 27 Jan 2026 06:42:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=lamehost-it.20230601.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vNbGM4gk-lR3 for <sidrops@mail2.ietf.org>; Tue, 27 Jan 2026 06:42:40 -0800 (PST)
Received: from mail-dy1-x132e.google.com (mail-dy1-x132e.google.com [IPv6:2607:f8b0:4864:20::132e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 85BC4ADBD7A5 for <sidrops@ietf.org>; Tue, 27 Jan 2026 06:42:40 -0800 (PST)
Received: by mail-dy1-x132e.google.com with SMTP id 5a478bee46e88-2b71515d8adso5559503eec.1 for <sidrops@ietf.org>; Tue, 27 Jan 2026 06:42:40 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1769524959; cv=none; d=google.com; s=arc-20240605; b=JZEbwAmHg6bJGSYnUgebCuZrbj6+fv/9GjVsb4eWEH+6SXJ9yySgpCaEhZk1XJCn7B 54lSI/lL7OnZ14D7Us0ajGVrIuCaqgp/fGTrO3LjRB4+MO94bD5nGZrjbKbMZZVIfODf 85+em5dlvgKOqExVO4CfONeb0eJvQot8STklalB8nChGPZPPNe2iir7WJSzSvbiv9KC/ ZAS1YBYXdeWEuEonftw2z5e0sgjJdmeUSYSfWR/9DLSXRxsU0DepnOPPBfJ+oNe4QNg5 m5zx7YZgonlFPZIsyAstjCY8MeJUnj2+ovD4YYvEdvCUlsSpfBgwR4Q9/2QfUffMAwR7 QA/Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=QiOFS6WvwdJ+gcXjOwH7hgDLOWFjhSuG0BnK9LUVK9k=; fh=gsoTG7MZqlKyWYNGzjRaEGim5JSilqXV/z+3rdHC7+c=; b=Yzzh/f8eWWvjythlAh67NnjBcGpxlJfJbbqLYnAlIMpEDA/IuR+GLNcwxG8L1Ny2Z3 S88cLPy7dj884j0kQ/m9/fJAs45TZe+Ra+WPUtGAu7TdXa9/V3FPjYq2GJZTjI5EzWSy GhcEG1j2WfTtICwyBpDnTcBSdbW4OpUZSX99eEeK2rvoaU38ks/MZkPsFH/djG5JNrsW RnZvcZS245RhpjLWI6iwnFiqB6eLzL+ICX7rO03OBXMiiAan+5c+Yd0JGGOeSzk4NDR9 cCcXS+D/5PTTLogIR4Pmtd9MNJ7X4JWnpuXH+4X6q+IhUjYdGp635P8igb5VIWZ+yzu9 kZMg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lamehost-it.20230601.gappssmtp.com; s=20230601; t=1769524959; x=1770129759; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=QiOFS6WvwdJ+gcXjOwH7hgDLOWFjhSuG0BnK9LUVK9k=; b=Aetkndptym7+2N0iTBR3Ibhp9ZQvXbjX7a9jX0105pxCI3OHOTKqnb9vS6TB2R7FvO ck4IJKL0axPO6IjhfV/YfDWQn2z4NEaGkv6Nv4VFVj4j9AJq87mtzDm1IdQA92eSJbgj tsUGVl68huVTzaPOQ+bQ4EGqoWWY3SRlQYLYhQbf1unBgsmruSPxE/2fNIPFJ6FeSAV6 cZNXlj5ATKA7FZJpQBXYCw0nIh/x395xPYpEFF2bJUiQUCrxA2GIWqwHk9VQofOfEBjV Dou3yvyctuZbdS/HDF5edm71uE9Q/lr6EkWc7dyPWHI1F1jodguSucDC+nNgEZyL6WGg HtZw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769524959; x=1770129759; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=QiOFS6WvwdJ+gcXjOwH7hgDLOWFjhSuG0BnK9LUVK9k=; b=hnQ3SuLPQs0FOPINiXxq+FJN2MBEGEQZUh34leYCzNcdSD4N0zNmMXlb/RQ6WrAwEu rxxvW5nN+n2elyD9BLUJj525j5U9FhT4T7aKMZ6qoxuSFhzUM5gqb6UTdCqJkO4eOA9V L1snXQ317npiFnN/2/iWu2Y59iNqCGKdF0m4W2cvawx3cXYJsgkFqKORD6MW+z5PeGxu 1z10BaPONE6YFIHgDEBSItbg3yFjbMBeOm2WJumBaie5+boNUDFpYxSM8Li4We65B8zG X0aW2FXRTYeNdVNH3OYoYu/bomVKv1IRx9b0eZeikSGuTBR3iMJ1iSjvmsKRD02Qnf6P id/Q==
X-Gm-Message-State: AOJu0Yz9T3JpTkgCW3nKys3oIWyQxbKMHodGR1ZjI797csd9jI8Iovlk 8uok+TCyrKtxwj8byDZSjHrQx68ZOyxh6EnK6nrWQ3HfWDsniuZ4HFIasdITAXe8nXTY/eLbBQm PoVZdIa2Rh+Kr8ijpNi3PUi8u4QK7BUb6N6n8PMUIo39Q1POwkxdPJPA=
X-Gm-Gg: AZuq6aK3zUR2gVzZNcWPsFMTptItU4qi1EMGMIEwL3LuZPo46DIg6qXKfFPptuK8fRS l+JoqiQ+2zkGRoyJdXxbYU4f9ALPMfg1032QNERckDgithn+vw3Z/77BH43Tb8jUH22ypyLKNfk 882fSLcdxyf2QV6MzFPdo05/8p+oP10pQ1bkMy6VoGm06Yhm5pr429w9e8EKC0B3yPcuFHYpDFN aFX7VN52ek5EjHHQnm4w8cvg/wcA8UqFtx7DcrMX98HXAqTsCLtAtt2JK1styFdKwM/pFhz0/ID RRia2+3024EXCR6Oy8oVFHVRJL4=
X-Received: by 2002:a05:7300:fd04:b0:2ac:2e71:90d with SMTP id 5a478bee46e88-2b78d869f62mr1187891eec.6.1769524959115; Tue, 27 Jan 2026 06:42:39 -0800 (PST)
MIME-Version: 1.0
References: <5C5B8F40-6E19-4082-89C0-3DDC0AB6364A@gigix.net>
In-Reply-To: <5C5B8F40-6E19-4082-89C0-3DDC0AB6364A@gigix.net>
From: Marco Marzetti <marco@lamehost.it>
Date: Tue, 27 Jan 2026 15:42:27 +0100
X-Gm-Features: AZwV_QitZsGw2eaIiukAUnRctpO_GUtD2YGH7UyuZvayCzncpXcwcJO20r2BreM
Message-ID: <CAO367rW9u9pMXKPP3YDP-Pbkwf02tHHOp50PU0MUjYB-C1F45Q@mail.gmail.com>
To: Luigi Iannone <ggx@gigix.net>
Content-Type: multipart/alternative; boundary="0000000000009c0a1406495fa26e"
Message-ID-Hash: LYXZV6HQ2LUQRWXTKWG6M55LYFMSGM6Z
X-Message-ID-Hash: LYXZV6HQ2LUQRWXTKWG6M55LYFMSGM6Z
X-MailFrom: marco@lamehost.it
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: SIDRops IETF <sidrops@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Re: Call for WG Adoption of draft-snij-sidrops-constraining-rpki-trust-anchors
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/SoBYxCyh1YhYmBKJTN76bopO8Ew>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>

I support the adoption of this document

On Mon, Jan 19, 2026 at 1:47 PM Luigi Iannone <ggx@gigix.net> wrote:

> All,
>
> The authors have asked the SIDROPS WG to adopt the document
> draft-snij-sidrops-constraining-rpki-trust-anchors (
> https://datatracker.ietf.org/doc/draft-snij-sidrops-constraining-rpki-trust-anchors/
> )
>
> Title: Constraining RPKI Trust Anchors
>
> Abstract:
>   This document describes an approach for Resource Public Key
>    Infrastructure (RPKI) Relying Parties (RPs) to impose locally
>    configured Constraints on cryptographic products subordinate to Trust
>    Anchors (TAs).  The ability to constrain a Trust Anchor operator's
>    effective signing authority to a limited set of Internet Number
>    Resources (INRs) allows Relying Parties to enjoy the potential
>    benefits of assuming trust - within a bounded scope.  The specified
>    approach and configuration format allow RPKI operators to communicate
>    efficiently about observations related to Trust Anchor operations.
>
>
> This email formally opens the two weeks Call for Adoption.
>
> If you are supporting adoption, please state so.
> If you have concerns, please detail them.
>
> Please voice your opinion for the SIDROPS WG adoption of this document by
> 2 February 2026.
>
> For the SIDROps WG Chairs,
> Luigi
> _______________________________________________
> Sidrops mailing list -- sidrops@ietf.org
> To unsubscribe send an email to sidrops-leave@ietf.org
>


-- 
Marco