[Sidrops] Re: BGPSec certificate validity period
George Michaelson <ggm@algebras.org> Thu, 16 October 2025 20:33 UTC
Return-Path: <ggm@algebras.org>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2E38D7543547 for <sidrops@mail2.ietf.org>; Thu, 16 Oct 2025 13:33:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=algebras-org.20230601.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sp3LhsbzzakN for <sidrops@mail2.ietf.org>; Thu, 16 Oct 2025 13:33:40 -0700 (PDT)
Received: from mail-ed1-x534.google.com (mail-ed1-x534.google.com [IPv6:2a00:1450:4864:20::534]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CCB56754348C for <sidrops@ietf.org>; Thu, 16 Oct 2025 13:33:16 -0700 (PDT)
Received: by mail-ed1-x534.google.com with SMTP id 4fb4d7f45d1cf-63b9da57cecso2112313a12.0 for <sidrops@ietf.org>; Thu, 16 Oct 2025 13:33:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=algebras-org.20230601.gappssmtp.com; s=20230601; t=1760646796; x=1761251596; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=+63nGWAeF0wB88IVpCKnXStKtvB821U0qsWqajRoMu8=; b=fXRvowGxdkweagc1owCFbiF1r7/ixB1IByxifxTd418q3efke0aIrODY/gJSoXfo+i Md/l1O6J1KA8tC16iKYuNthSXpCpBhuY64Q1l0MUnQghoL9DUge9D1ROkD8+jRY4TjPC TcubxTPC4uy/ZgDXuxAK2aaJ+Gxo25B6jc5drhGbUFojgxmg/kZK7nixR22O6E67aOYY GHW5uOdrJ+r3YAGCHy6eFJw7lMcpWj9u88SBX8aqZFO9+mpIeGa2WBJKnLL2S7gXL+3A aCz//Tii8ANSAmeFDKptjbRvsFLaKzYiWBFGvfyvFayBfu+YsuPOBuMl2I1Bt7+TArZO +hSw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1760646796; x=1761251596; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=+63nGWAeF0wB88IVpCKnXStKtvB821U0qsWqajRoMu8=; b=ce8r06shTUiHzqhWimkDQ2kEApWiuYB4ZUa9xj3chSW7+KMCZjubNMMDH5mmcaIFBa LI9MozUDAaRl7VLrSSNNKw6q2q2nqw2bsN6b9E3nZ1pmrJ4cYtzcuZ/zXc+R01DUaNLC SEEq8DfwjsSx1jycCyMLNHJvgArJhRlMw7jstH0AGcGKQQJ/CG3JkT/gJ1FjKPEnU9ty 3Lc5WHSfi/dI4DEBEKHKIzzgXpOUEP7whIEM3KdvwRJUDe9QR/97aU0A1I/IUWzn1fxT bDMk1OsgjpTrgT2ytyyTT/ho7GPskKeN4s5EiBRkkDMQ3zRDw8Ltpp5owe2PYZKsvCTF Bogw==
X-Gm-Message-State: AOJu0Yx4xjq8YdxXi0VBV3cDv5RYykcKT9Tc9n+65XEaYP7YHXTFB2Dt cGXAQrV1xXGY1yFdPipJS0Ij8XafiDQpCJMUAXeGlohOyz9iKoO+bJJEbyoNTCj/Eno+lakEHKt 4Bae+ocGitXwmkbGZ1NNLPf4RQsmKcSucMClhlADUL1DS9SZaH0kh
X-Gm-Gg: ASbGncuSBlJWwlOA9RxnRMIpHjpL96WPgGJ0/zikb+UwEqTxbB43RBuhFqcUQl/MIhK ejkx7/oDWAJjG0k0qZm1OTFzNhGVkVbXb9A7XRi8GZDvYQJ+BEiYuU2CuBHKpVsPndOQl9etc0i /aLxYsxchxdEoUzsMHfoNPScNwHgKGn0DkOGOW67uxHpuagaN3xuWUqS/pt4PrFUvQTlvf1h722 etwAw2Tmas+x1x5nsTSSrXMjx85ZJ/2Kn8Ip8GFe+OuRh92DxTkojUDAIekQLpiHpuN3dqVSnC7 A5exxHdM5RnJNwmlMJHqJiBT3elJW+A1byGmJ1WLeLFKorHwO1HxHEEsWlVGeAXDQo4dbhrDqb0 EaQVR
X-Google-Smtp-Source: AGHT+IGpQerNLsXQDuQjObFhoKb1J9W/Ci8diLvrDIRHQhDVWtKs6sN0vYMJtL/SYAJfE1GYbn/UZHtoI0wHiDwyNmI=
X-Received: by 2002:a05:6402:2686:b0:63c:1a7b:b3bb with SMTP id 4fb4d7f45d1cf-63c1f631befmr1177094a12.1.1760646795453; Thu, 16 Oct 2025 13:33:15 -0700 (PDT)
MIME-Version: 1.0
References: <CAGPuK+6Xs=Zu-vWohihma0UuW+3e4o_GhqZA_H-oNHgUb8MwkQ@mail.gmail.com> <060C7D32-4543-4E54-B902-A506A3137642@vigilsec.com>
In-Reply-To: <060C7D32-4543-4E54-B902-A506A3137642@vigilsec.com>
From: George Michaelson <ggm@algebras.org>
Date: Fri, 17 Oct 2025 06:33:04 +1000
X-Gm-Features: AS18NWAz4pWFvuVaya8qQxuvbHuT3Q2KqcC9bpS85kf90M9cfCNwBGTcZBlplPc
Message-ID: <CAKr6gn3nfxTfThbRS_2=TxnLcjrTYWFe5k+ic8VfYjtJ=H5SYw@mail.gmail.com>
To: IETF SIDRops <sidrops@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d1762b06414c862d"
Message-ID-Hash: QCB5WKNL4AHE2LIRSDRPU4YTWZJB323N
X-Message-ID-Hash: QCB5WKNL4AHE2LIRSDRPU4YTWZJB323N
X-MailFrom: ggm@algebras.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Re: BGPSec certificate validity period
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/cDCW7cqT__L3ksN-MoX7MxzB0V4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>
If the Web is moving to short lifetimes and the mechanism is automated, are there specific positive reasons to anchor BGPsec issuance as a long lifetime event? It would help enormously (in my opinion) to have a "because .." statement tied to the assertion of a lifetime. G On Fri, 17 Oct 2025, 2:39 am Russ Housley, <housley@vigilsec.com> wrote: > Mikhail: > > > RIPE NCC is working on BGPSec support in our RPKI backend to allow > > users to manage BGPSec signing requests and generate router > > certificates from them. > > > > One of the questions that has come up in the meantime is: what should > > be the validity period of router certificates? > > > > - RFC 8209 doesn't mention the validity period at all. > > - RFC 8634 does mention it, but doesn't recommend a value. It just > > states: “The validity period for these certificates is typically > > expressed in the CA’s CPS document.” I am inclined to interpret this > > as meaning that the router certificate validity period should match > > that of the corresponding CA certificate. > > I think you are free to specify a validity period in the CPS, but it can > extend beyond the validity period of the parent CA certificate. > > > > - I have also seen two different LLMs hallucinate a 35-days validity > > period referring to some (might be completely made up) older draft, I > > haven’t found any reference to that myself though. > > The WebPKI is pushing toward 35 days. I suspect that the LLM does not > know the difference between the WebPKI and the RPKI, but I could be > hallucinating too ;-) > > > So, is there a consensus on router certificate validity periods? > > I do not believe that this has been discussed here before, so there is no > consensus. > > Russ > > _______________________________________________ > Sidrops mailing list -- sidrops@ietf.org > To unsubscribe send an email to sidrops-leave@ietf.org >
- [Sidrops] BGPSec certificate validity period Mikhail Puzanov
- [Sidrops] Re: BGPSec certificate validity period Job Snijders
- [Sidrops] Re: BGPSec certificate validity period Russ Housley
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Russ Housley
- [Sidrops] Re: BGPSec certificate validity period Job Snijders
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Dirk Doesburg
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Tim Bruijnzeels
- [Sidrops] Re: BGPSec certificate validity period Dale W. Carder