[Sidrops] Protocol Action: 'Manifests for the Resource Public Key Infrastructure (RPKI)' to Proposed Standard (draft-ietf-sidrops-6486bis-11.txt)
The IESG <iesg-secretary@ietf.org> Thu, 07 April 2022 21:45 UTC
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: sidrops@ietf.org
Delivered-To: sidrops@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1])
by ietfa.amsl.com (Postfix) with ESMTP id 0AFB73A17CD;
Thu, 7 Apr 2022 14:45:43 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 7.46.0
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, draft-ietf-sidrops-6486bis@ietf.org,
morrowc@ops-netman.net, rfc-editor@rfc-editor.org, sidrops-chairs@ietf.org,
sidrops@ietf.org, warren@kumari.net
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <164936794301.19440.50545341424289931@ietfa.amsl.com>
Date: Thu, 07 Apr 2022 14:45:43 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/Vh1e2YlKcnCICuii2fGRDTEoOMU>
Subject: [Sidrops] Protocol Action: 'Manifests for the Resource Public Key
Infrastructure (RPKI)' to Proposed Standard
(draft-ietf-sidrops-6486bis-11.txt)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>,
<mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>,
<mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Apr 2022 21:45:44 -0000
The IESG has approved the following document: - 'Manifests for the Resource Public Key Infrastructure (RPKI)' (draft-ietf-sidrops-6486bis-11.txt) as Proposed Standard This document is the product of the SIDR Operations Working Group. The IESG contact persons are Warren Kumari and Robert Wilton. A URL of this Internet Draft is: https://datatracker.ietf.org/doc/draft-ietf-sidrops-6486bis/ Technical Summary This document defines a "manifest" for use in the Resource Public Key Infrastructure (RPKI). A manifest is a signed object (file) that contains a listing of all the signed objects (files) in the repository publication point (directory) associated with an authority responsible for publishing in the repository. For each certificate, Certificate Revocation List (CRL), or other type of signed objects issued by the authority that are published at this repository publication point, the manifest contains both the name of the file containing the object and a hash of the file content. Manifests are intended to enable a relying party (RP) to detect certain forms of attacks against a repository. Specifically, if an RP checks a manifest's contents against the signed objects retrieved from a repository publication point, then the RP can detect "stale" (valid) data and deletion of signed objects. This document is an update (-bis) to RFC 6486. Working Group Summary There was quite a long and thorough discussion of this document in the WG. With a large sea change in management of the Manifest and publication-point data repositories proposed and agreed-upon by the group and authors. Document Quality This is a -bis for an existing document, there is quite a bit of deployed infrastructure / implementations of the prior document, and most have now shifted to this new document as a response to some operational issues experienced in the field. Personnel Document Shepherd (DS): Chris Morrow (morrowc@ops-netman.net) Responsible AD (RAD!!!): Warren Kumari (warren@kumari.net)