Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

Ties de Kock <tdekock@ripe.net> Fri, 09 June 2023 13:28 UTC

Return-Path: <tdekock@ripe.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF35EC1519BA; Fri, 9 Jun 2023 06:28:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level:
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ripe.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0yPQ3ZRfr808; Fri, 9 Jun 2023 06:28:31 -0700 (PDT)
Received: from mail-mx-2.ripe.net (mail-mx-2.ripe.net [IPv6:2001:67c:2e8:11::c100:1312]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F563C14CE42; Fri, 9 Jun 2023 06:28:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ripe.net; s=s1-ripe-net; h=To:Message-Id:Cc:Date:From:Subject:Mime-Version:Content-Type ; bh=PpqrIejDkRnAlwjAHMJwteqHUeq2mCCqGz+GS1iYt4o=; b=jCkT6yqE/h97RCHSYlTff6S1 xAyJwnrwxmVCneYcOJvpyHw8615rQ/cPRNq+HFfCHQ2hhRDfNWVU+8ehfKY91bUEzq7meMWwoFxYN BV/qgp4lL9o6Xb5Ee67xdLRlV1lsPyyiEntsoLLFULJ2sYEz/3vdqHiuw8fGmpK658gAE1+pZr0Lf eAERryo1IXhdWPoLHtB1lN5wRs5cJSq3zyKSmDbdGHzpoZNZknmpUiQ54Yz//P6JsHbzOP3FItwqW meWekqr+R4S+47Iga6cp7KQLhY2JwZSS7uRVE4rMQyZv7OkiHE20YtBy65m4gMvyU8yDngxh5Fo1a bDNcbR3Zxg==;
Received: from allealle.ripe.net ([2001:67c:2e8:23::c100:170c]:60540) by mail-mx-2.ripe.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <tdekock@ripe.net>) id 1q7cAH-008jCe-1h; Fri, 09 Jun 2023 13:28:29 +0000
Received: from sslvpn.ripe.net ([193.0.20.230] helo=smtpclient.apple) by allealle.ripe.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <tdekock@ripe.net>) id 1q7cAH-0004f7-1H; Fri, 09 Jun 2023 13:28:29 +0000
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.600.7\))
From: Ties de Kock <tdekock@ripe.net>
In-Reply-To: <0C543A94-F70E-4A40-8350-C98FAAB5A9B5@vigilsec.com>
Date: Fri, 09 Jun 2023 16:28:18 +0300
Cc: Martin Hoffmann <martin@nlnetlabs.nl>, Job Snijders <job=40fastly.com@dmarc.ietf.org>, sidrops@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <D100381E-6498-4EAD-B056-18F89836C097@ripe.net>
References: <168621843689.33017.6897451444105786551@ietfa.amsl.com> <ZIGogKIH4Srb8Nxt@snel> <20230608181440.33d6926f@glaurung.nlnetlabs.nl> <0C543A94-F70E-4A40-8350-C98FAAB5A9B5@vigilsec.com>
To: Russ Housley <housley@vigilsec.com>
X-Mailer: Apple Mail (2.3731.600.7)
X-RIPE-Signature: 059faafd1cc22ebb05e1592c815fe1e1b7a7fd1cf259e0619f650ad0d14b1e12
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/fY0C0LxpzCSUaisL5aBSzIQZUIs>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Jun 2023 13:28:35 -0000

Hi Russ,

> On 9 Jun 2023, at 15:57, Russ Housley <housley@vigilsec.com> wrote:
> 
> 
> 
>> On Jun 8, 2023, at 12:14 PM, Martin Hoffmann <martin@nlnetlabs.nl> wrote:
>> 
>> Job Snijders wrote:
>>> 
>>> The internet-draft changes is best viewed by comparing -13 and -15:
>>> https://author-tools.ietf.org/iddiff?url1=draft-ietf-sidrops-aspa-profile-13&url2=draft-ietf-sidrops-aspa-profile-15
>> 
>> | ProviderASSet ::= SEQUENCE (SIZE(1..MAX)) OF ASID
>> 
>> This should probably be a SET rather than a SEQUENCE? This gives you no
>> duplicates and a canonical DER encoding for free.
> 
> Martin:
> 
> DER encoding of a SET requires a sort.  DER encoding of a SEQUENCE preserves the sender's order.  So, while I agree with your observation about the semantics, I'd rather avoid the sort.

We have
> The elements of providers MUST be ordered in ascending numerical  order.

In the text. My understanding of how a DER encoded SET is that this would imply
this order. Is this correct?

Kind regards,
Ties