Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

Martin Hoffmann <martin@nlnetlabs.nl> Tue, 13 June 2023 13:02 UTC

Return-Path: <martin@nlnetlabs.nl>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5B86C14CE5E for <sidrops@ietfa.amsl.com>; Tue, 13 Jun 2023 06:02:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nlnetlabs.nl
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9qCw3tn-8YzU for <sidrops@ietfa.amsl.com>; Tue, 13 Jun 2023 06:02:03 -0700 (PDT)
Received: from outbound.soverin.net (outbound.soverin.net [IPv6:2a10:de80:1:4091:b9e9:2212:0:1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E001C151064 for <sidrops@ietf.org>; Tue, 13 Jun 2023 06:02:02 -0700 (PDT)
Received: from smtp.soverin.net (c04smtp-lb01.int.sover.in [10.10.4.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by outbound.soverin.net (Postfix) with ESMTPS id 4QgTGb54Wqz7s; Tue, 13 Jun 2023 13:01:59 +0000 (UTC)
Received: from smtp.soverin.net (smtp.soverin.net [10.10.4.99]) by soverin.net (Postfix) with ESMTPSA id 4QgTGb1s3XzL1; Tue, 13 Jun 2023 13:01:59 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=nlnetlabs.nl; s=soverin; t=1686661319; bh=tuWMXR6cyfLyzbgNqSvLbj7sj58h1bhDIV3lLN96bHY=; h=Date:From:To:Cc:Subject:In-Reply-To:References:From; b=vmx1DLEEvyg99MmyT/ZKeLaVgtUkdac3nXio01OI198Q7QG+GtDToVtmctFVzZmLr +mRCEK0l7S7hlsnCpkgGoFT8YcHMUy9EDzK+dy7MCWvx5n4RKnTV39BONq74wsdIAF aeecn8LH7cpsTinGujAp49tgaLjnzhpcNlmNVRJf6ObFXwMRWseBjB97wfMldYlm+Z nHVsAPkEGoInWb/b379hwESq5re7MC/bjIAG6BhV988bUNYuLnQ09NVPJWd+AXzb/Y ePL82UBiISZk8nL6IU2G3H8iMTir58MmOgZf81XkBKQXsaIs/njCoK8HReayqSq5iS bZBJHoPuSr6dg==
Date: Tue, 13 Jun 2023 15:01:56 +0200
X-Soverin-Authenticated: true
From: Martin Hoffmann <martin@nlnetlabs.nl>
To: Russ Housley <housley@vigilsec.com>
Cc: Ties de Kock <tdekock@ripe.net>, Job Snijders <job=40fastly.com@dmarc.ietf.org>, sidrops@ietf.org
Message-ID: <20230613150156.29022a0e@glaurung.nlnetlabs.nl>
In-Reply-To: <26E1759F-08FA-430D-8F89-BDC6C3DC4B9D@vigilsec.com>
References: <168621843689.33017.6897451444105786551@ietfa.amsl.com> <ZIGogKIH4Srb8Nxt@snel> <20230608181440.33d6926f@glaurung.nlnetlabs.nl> <0C543A94-F70E-4A40-8350-C98FAAB5A9B5@vigilsec.com> <D100381E-6498-4EAD-B056-18F89836C097@ripe.net> <96D52BC8-C3BA-43C8-90E1-DD2621C2292F@vigilsec.com> <20230613094413.364aaa8c@smaug.local.partim.org> <26E1759F-08FA-430D-8F89-BDC6C3DC4B9D@vigilsec.com>
Organization: NLnet Labs
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/VJOnOB3MffvEXd6aqriiT7Qc-8s>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jun 2023 13:02:07 -0000

Russ Housley wrote:
> 
> I do not think we want to have decode failures if the INTEGERS are
> not in sort order.

I agree, but in the past the consensus in this group has been to
rigorously reject objects that have something wrong with them. By that
consensus, an ASPA with unsorted provider ASNs would be rejected on
grounds of violating the MUST further down. In which case it might as
well be rejected during decoding.

  -- Martin