Re: [Sidrops] WGLC: draft-ietf-sidrops-https-tal-03 - ENDS 22 June 2018

Job Snijders <job@instituut.net> Sun, 10 June 2018 09:25 UTC

Return-Path: <job@instituut.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 21803130E2B for <sidrops@ietfa.amsl.com>; Sun, 10 Jun 2018 02:25:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.609
X-Spam-Level:
X-Spam-Status: No, score=-2.609 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, T_DKIMWL_WL_MED=-0.01, UNPARSEABLE_RELAY=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=instituut-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uWq7cjuGCvR3 for <sidrops@ietfa.amsl.com>; Sun, 10 Jun 2018 02:25:14 -0700 (PDT)
Received: from mail-wm0-x22c.google.com (mail-wm0-x22c.google.com [IPv6:2a00:1450:400c:c09::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C3F80130E2A for <sidrops@ietf.org>; Sun, 10 Jun 2018 02:25:11 -0700 (PDT)
Received: by mail-wm0-x22c.google.com with SMTP id r15-v6so9730356wmc.1 for <sidrops@ietf.org>; Sun, 10 Jun 2018 02:25:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=instituut-net.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=vidd3bRtNMHPJ9U6YP95rhOKiT50WI+lKWoAAcFyBPE=; b=bfII9rcN2nGnCXPMd7OPipjRFmIrPGzezmuidV4ta+OWj4hcLWKGvpAllAAigRWPCo m2FuODtoEw43d3JZ4cJQOH7rZz5sLYGLNxdJqI/O0+1XSiRz7L+5xdyOOOSbE9ZJ+OX6 SK42mo/n6R8oiVFf92dYJ5chpjJfsZfVJu2w1elv1uYQ2GCad+aOq5VWhiKx0+4UjAAc 4LttoAo6hxvkXOQMZnB24FtGF/f3JbFsNBU1GOERKxM6aWF6hyANuvmsV4/TDza3edzX hmn2FLd+zoGPjVIKADY1NPcf1X7dHQvE9x/3tGHowLuLItG6b3MjnjHzrZ0Iw9CS6T6D mtsQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=vidd3bRtNMHPJ9U6YP95rhOKiT50WI+lKWoAAcFyBPE=; b=pCe51WVlXXQMKuK0bvdKciQSK6JtWyNXJ64ny1fgQGyJ8bANm5Bmz55aJL0Fq4YWC0 00OMmswAR57lTKNUNwy9VnWjmIumIx+9iuCk8y9eMXR18SL3SrgQI8On97k9VTxVF/+M H7X9m1iBNTsZQJY7E8BmhgvuNUJr5rKon1JmaWiWkIZplcus65ZPaP01YRIlQe/zkoFg iyOhk3g1vQAHm55zX/q8dDy2e7o6g2iyf2SJXm90T/Az7lS6qDCi4h5acHP+owcyXw23 79TQZ4wGOKw3yprVU8JMXmb4+gVQs5U0XcodbZDTdxTebPPstxmE42aZtHfsQPzhqJ4E l6vw==
X-Gm-Message-State: APt69E09eNE4/sDHkRl5+4wQlrXZ6R9mVInZi3m2m6tWdOOhlMtx0Ogo 98IHRDB+igXwNVb/UlPQGHVRn93QLfE=
X-Google-Smtp-Source: ADUXVKIjEciiXYFS7xkg1KZwWvu/DszZUSQwxCVSCL9fbGPcs79r+hbatJArSvVn9US9R5DaK2g9vA==
X-Received: by 2002:a50:8ad5:: with SMTP id k21-v6mr5181142edk.36.1528622710127; Sun, 10 Jun 2018 02:25:10 -0700 (PDT)
Received: from vurt.meerval.net (vurt.meerval.net. [192.147.168.22]) by smtp.gmail.com with ESMTPSA id h2-v6sm7831298edq.6.2018.06.10.02.25.08 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Sun, 10 Jun 2018 02:25:09 -0700 (PDT)
Received: from localhost (vurt.meerval.net [local]) by vurt.meerval.net (OpenSMTPD) with ESMTPA id c019836a; Sun, 10 Jun 2018 09:25:08 +0000 (UTC)
Date: Sun, 10 Jun 2018 09:25:08 +0000
From: Job Snijders <job@instituut.net>
To: Chris Morrow <morrowc@ops-netman.net>
Cc: sidrops@ietf.org, sidrops-chairs@ietf.org, sidrops-ads@ietf.org
Message-ID: <20180610092508.GB30348@vurt.meerval.net>
References: <yj9ozi05fl3t.wl-morrowc@ops-netman.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <yj9ozi05fl3t.wl-morrowc@ops-netman.net>
X-Clacks-Overhead: GNU Terry Pratchett
User-Agent: Mutt/1.10.0 (2018-05-17)
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/qYzipszOlSLo6FHSNrG7iak8GUU>
Subject: Re: [Sidrops] WGLC: draft-ietf-sidrops-https-tal-03 - ENDS 22 June 2018
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Jun 2018 09:25:15 -0000

On Fri, Jun 08, 2018 at 09:45:10AM -0400, Chris Morrow wrote:
> The authors of: draft-ietf-sidrops-https-tal-03 would like the WG to
> consider a WGLC of their document, abstract:
> 
>   "This document defines a Trust Anchor Locator (TAL) for the Resource
>    Public Key Infrastructure (RPKI).  This document obsoletes RFC 7730
>    by adding support for HTTPS URIs in a TAL."
> 
> Please have a read through the document and send along
> comments/questions/additions/subtractions so the authors can amend if
> required with the intent to move this document along the proper path
> in short order.

Read. I support publication.

Nits:

1/ "one of more" should perhaps be "one or more"?

2/  OLD: "However, a MITM can perform withhold or replay attacks
targeting a Relying Party and keep the Relying Party from learning about
an update CA certificate."

PERHAPS: "However, a MITM attack can be performed to prevent the Relying
Party from learning about an updated CA certificate."

Kind regards,

Job