Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-signing-time-03.txt
Russ Housley <housley@vigilsec.com> Mon, 22 January 2024 20:26 UTC
Return-Path: <housley@vigilsec.com>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E50D8C1519A4 for <sidrops@ietfa.amsl.com>; Mon, 22 Jan 2024 12:26:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level:
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yfbDBjW-DdHk for <sidrops@ietfa.amsl.com>; Mon, 22 Jan 2024 12:26:35 -0800 (PST)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8390EC1519A2 for <sidrops@ietf.org>; Mon, 22 Jan 2024 12:26:35 -0800 (PST)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id DAB891C8A3E; Mon, 22 Jan 2024 15:26:34 -0500 (EST)
Received: from smtpclient.apple (unknown [96.241.2.243]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id C52B51B7EEF; Mon, 22 Jan 2024 15:26:34 -0500 (EST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <63F0483D-596B-42BC-A1E0-86D15D64F547@ripe.net>
Date: Mon, 22 Jan 2024 15:26:24 -0500
Cc: sidrops <sidrops@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <ED3DD126-72AE-463C-8B11-B27FA1EF8A87@vigilsec.com>
References: <170561454824.54895.360140302624981870@ietfa.amsl.com> <ZamgKc5PTJPDcISD@snel> <C10EC4E3-9A59-4BBA-B5DC-DB4680AD0B0D@ripe.net> <ZapR2qVBAu7lECFB@snel> <7547BE09-8FF6-40F4-BC6E-388BAEFE6CD6@ripe.net> <ZapoTxRlSvSSVqk_@snel> <5AF9DD6B-A4F0-4C20-9E0E-62144D013D44@ripe.net> <ZaqF_7W-EMiYljxd@snel> <63F0483D-596B-42BC-A1E0-86D15D64F547@ripe.net>
To: Ties de Kock <tdekock@ripe.net>, Job Snijders <job@fastly.com>
X-Mailer: Apple Mail (2.3731.700.6)
X-Scanned-By: mailmunge 3.11 on 66.39.134.11
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/o0_Pp4-AcqPDlS9Q1qAgoDw0PJ0>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-signing-time-03.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jan 2024 20:26:40 -0000
Thanks for the flurry of messages discussing this document. Please post a new version of the document. Once that appears, we can begin a WG Last Call. For the SIDRops Chairs, Russ > On Jan 19, 2024, at 9:28 AM, Ties de Kock <tdekock@ripe.net> wrote: > > Hi Job, > >> On 19 Jan 2024, at 15:23, Job Snijders <job@fastly.com> wrote: >> >> On Fri, Jan 19, 2024 at 02:19:57PM +0100, Ties de Kock wrote: >>>> Aren't all bets off when implementations are noncompliant? :-) >>>> >>>> I think I agree with the gist of what you're saying, but I'm not >>>> entirely sure what to add that's not already covered by existing >>>> literature. >>> >>> Let’s add the local improvement somewhere in the doc, maybe security >>> considerations? “the status quo is that most implementations are not compliant >>> with RFC 6019, this causes signing time to be ambiguous when interoperating >>> between implementations" >> >> How about this? >> >> https://github.com/job/draft-sidrops-cms-signing-time/commit/9f43dfa84f7293dc547d46154f0f5296fd5533fe >> >> ----------------------------------------- >> 5. Security Considerations >> >> No requirement is imposed concerning the correctness of the signing >> time attribute. It does not provide reliable information on the time >> the signature was produced and it bears no relevance for seamless >> switchover between RRDP and rsync. >> >> While the Security Considerations in [RFC6019] mandate that the >> signing-time and binary-signing-time attributes, if both present, >> MUST provide the same date and time; a potential for ambiguity is >> removed by restricting the RPKI Signed Object profile to have only >> one field to store the purported signing time. >> ----------------------------------------- > > Nice one. For me this expresses the the motivation for this more clearly in this > document. > > -Ties
- [Sidrops] I-D Action: draft-ietf-sidrops-cms-sign… internet-drafts
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Job Snijders
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Ties de Kock
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Job Snijders
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Ties de Kock
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Job Snijders
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Ties de Kock
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Job Snijders
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Ties de Kock
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Russ Housley
- Re: [Sidrops] I-D Action: draft-ietf-sidrops-cms-… Job Snijders