[Sidrops] Protocol Action: 'Manifests for the Resource Public Key Infrastructure (RPKI)' to Proposed Standard (draft-ietf-sidrops-6486bis-11.txt)

The IESG <iesg-secretary@ietf.org> Thu, 07 April 2022 21:45 UTC

Return-Path: <iesg-secretary@ietf.org>
X-Original-To: sidrops@ietf.org
Delivered-To: sidrops@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 0AFB73A17CD; Thu, 7 Apr 2022 14:45:43 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 7.46.0
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, draft-ietf-sidrops-6486bis@ietf.org, morrowc@ops-netman.net, rfc-editor@rfc-editor.org, sidrops-chairs@ietf.org, sidrops@ietf.org, warren@kumari.net
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <164936794301.19440.50545341424289931@ietfa.amsl.com>
Date: Thu, 07 Apr 2022 14:45:43 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/Vh1e2YlKcnCICuii2fGRDTEoOMU>
Subject: [Sidrops] Protocol Action: 'Manifests for the Resource Public Key Infrastructure (RPKI)' to Proposed Standard (draft-ietf-sidrops-6486bis-11.txt)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Apr 2022 21:45:44 -0000

The IESG has approved the following document:
- 'Manifests for the Resource Public Key Infrastructure (RPKI)'
  (draft-ietf-sidrops-6486bis-11.txt) as Proposed Standard

This document is the product of the SIDR Operations Working Group.

The IESG contact persons are Warren Kumari and Robert Wilton.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidrops-6486bis/





Technical Summary

  This document defines a "manifest" for use in the Resource Public Key
   Infrastructure (RPKI).  A manifest is a signed object (file) that
   contains a listing of all the signed objects (files) in the
   repository publication point (directory) associated with an authority
   responsible for publishing in the repository.  For each certificate,
   Certificate Revocation List (CRL), or other type of signed objects
   issued by the authority that are published at this repository
   publication point, the manifest contains both the name of the file
   containing the object and a hash of the file content.  Manifests are
   intended to enable a relying party (RP) to detect certain forms of
   attacks against a repository.  Specifically, if an RP checks a
   manifest's contents against the signed objects retrieved from a
   repository publication point, then the RP can detect "stale" (valid)
   data and deletion of signed objects.

 This document is an update (-bis) to RFC 6486.

Working Group Summary

There was quite a long and thorough discussion of this document in the WG. With a large sea change in management of the Manifest and publication-point data repositories proposed and agreed-upon by the group and authors.

Document Quality

   This is a -bis for an existing document, there is quite a bit of deployed infrastructure / implementations of the prior document, and most have now shifted to this new document as a response to some operational issues experienced in the field.


Personnel

Document Shepherd (DS): Chris Morrow (morrowc@ops-netman.net)
Responsible AD (RAD!!!):  Warren Kumari (warren@kumari.net)