Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

Di Ma <madi@zdns.cn> Tue, 27 June 2023 02:22 UTC

Return-Path: <madi@zdns.cn>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DAFDC15109C for <sidrops@ietfa.amsl.com>; Mon, 26 Jun 2023 19:22:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level:
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wWjkWHjpyqbW for <sidrops@ietfa.amsl.com>; Mon, 26 Jun 2023 19:22:48 -0700 (PDT)
Received: from smtpbg150.qq.com (smtpbg150.qq.com [18.132.163.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 69653C14F738 for <sidrops@ietf.org>; Mon, 26 Jun 2023 19:22:45 -0700 (PDT)
X-QQ-mid: bizesmtp78t1687832560twp5kx9m
Received: from smtpclient.apple ( [120.237.18.56]) by bizesmtp.qq.com (ESMTP) with id ; Tue, 27 Jun 2023 10:22:39 +0800 (CST)
X-QQ-SSF: 00400000000000Z0Z000000A0000000
X-QQ-FEAT: znfcQSa1hKbQgS1GRDVXOgzLbhCcYNKHZXwthZ3N3q9YW7+ecozhpdN96PdJo kagvWduVIp8sXcLgQB9kDBy+Fphmc4D2ial6UaH83Nz/tccsmtwMzlV1IfJKIj25Wi8Wyk0 +QfxQJheCOfU0dcn84UzQGHHuQ3Y9T173RAaUfWoIrQ+jhDIhw8wjdxPBupjihhh+SrGd3u KXrHgco0xPqNlAs0psWPsEX66bp2R8PmNcQ6soMWWE2M68luZRTcyrkxXMGJuvKpA4kGz9N rAV7iFJltmbE9R5G+hEn0sKYdt7ljZKwR1j6kJ/VRDCQFm0jh3s1Lxf/MTikdYO4y1/YasU /Q0WiuzCFlhB/xatx5cHyTIbzAbPQGae6B/o2vaSdCXDL8zGHIXrgU30AIGJNqhDikMTibW
X-QQ-GoodBg: 2
X-BIZMAIL-ID: 32012353624496478
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.600.7\))
From: Di Ma <madi@zdns.cn>
In-Reply-To: <684C565C-9DE9-4D5C-828C-94BE239331EC@vigilsec.com>
Date: Tue, 27 Jun 2023 10:22:28 +0800
Cc: Tom Harrison <tomh@apnic.net>
Content-Transfer-Encoding: quoted-printable
Message-Id: <644EC9F3-1D1E-476D-922A-7A299AEACECD@zdns.cn>
References: <168621843689.33017.6897451444105786551@ietfa.amsl.com> <ZIGogKIH4Srb8Nxt@snel> <ZJTBONuAsZutJoRp@TomH-802418> <ZJf7FGzRct1EOIjH@snel> <684C565C-9DE9-4D5C-828C-94BE239331EC@vigilsec.com>
To: SIDR Operations WG <sidrops@ietf.org>
X-Mailer: Apple Mail (2.3731.600.7)
X-QQ-SENDSIZE: 520
Feedback-ID: bizesmtp:zdns.cn:qybglogicsvrgz:qybglogicsvrgz6a-1
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/UbyrUgsG8RPF978tXeVhcwc87iU>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Jun 2023 02:22:52 -0000

Thanks go to Tom for this test demo.

I can decode it with RPSTIR2.

Di


> 2023年6月27日 04:22,Russ Housley <housley@vigilsec.com> 写道:
> 
> 
> 
>> On Jun 25, 2023, at 4:30 AM, Job Snijders <job=40fastly.com@dmarc.ietf.org> wrote:
>> 
>> On Fri, Jun 23, 2023 at 07:46:32AM +1000, Tom Harrison wrote:
>>>> If you generate test objects, please share them with the group!
>>> 
>>> The test APNIC implementation has been updated for version 15 of this
>>> document.  See
>>> https://github.com/APNIC-net/rpki-aspa-demo/blob/main/t/objects/AS1000.asa
>>> for an example object.
>> 
>> Thanks Tom, I can decode it.
>> 
>> $ rpki-client -f t/objects/AS1000.asa
>> File:                     t/objects/AS1000.asa
>> Hash identifier:          ta2FNhCaRt5BSVEXqTj56rrSyFUs0akYTK8lAMT+e9U=
>> Subject key identifier:   B3:88:AF:77:36:2E:35:35:C3:C9:CA:A8:FA:87:1C:4A:92:07:44:36
>> Certificate issuer:       /CN=ta
>> Certificate serial:       0A
>> Authority key identifier: EF:84:0D:58:C2:92:C5:58:5D:06:45:4C:88:4D:7C:5F:64:0B:D2:F4
>> Authority info access:    rsync://localhost:25934/repo/EF840D58C292C5585D06454C884D7C5F640BD2F4.cer
>> Subject info access:      rsync://localhost:25934/ta/an-object.asa
>> Signing time:             Sun 25 Jun 2023 00:27:09 +0000
>> ASPA not before:          Sun 25 Jun 2023 00:27:09 +0000
>> ASPA not after:           Mon 24 Jun 2024 00:27:09 +0000
>> Customer ASID:            1000
>> Provider set:             AS: 1025
>> Validation:               Failed, unable to get local issuer certificate
>> 
>> Kind regards,
>> 
>> Job
> 
> Thanks Tom.  I was able to use my updated pyasn1 module to decode it too.
> 
> Russ
> 
> _______________________________________________
> Sidrops mailing list
> Sidrops@ietf.org
> https://www.ietf.org/mailman/listinfo/sidrops
>