Re: [Sidrops] I-D Action: draft-ietf-sidrops-route-server-rpki-light-02.txt

Job Snijders <job@instituut.net> Tue, 25 July 2017 17:35 UTC

Return-Path: <job@instituut.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DB656131E75 for <sidrops@ietfa.amsl.com>; Tue, 25 Jul 2017 10:35:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=instituut-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wLgBYvujmj0m for <sidrops@ietfa.amsl.com>; Tue, 25 Jul 2017 10:35:24 -0700 (PDT)
Received: from mail-wm0-x236.google.com (mail-wm0-x236.google.com [IPv6:2a00:1450:400c:c09::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0A5F1131E73 for <sidrops@ietf.org>; Tue, 25 Jul 2017 10:35:23 -0700 (PDT)
Received: by mail-wm0-x236.google.com with SMTP id c184so58344964wmd.0 for <sidrops@ietf.org>; Tue, 25 Jul 2017 10:35:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=instituut-net.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=56wDMJI7Cr0hDUG/CzUbbsMnZC1KqEHY2NY6DsyEqwI=; b=WvpxgqlVLg4m3ntL/Cujt5nASsegbWmF5U6Uf2Lssm0To/F36iHG5Ru1SikAWG+d06 +Z+/yRfuQAYj+BD3SywnxKGBVDknagjU95gwYQ06OJDViBz6+0bg1P66XzQM3f1QzFib ESqBHnqye6XLiHkaXqnbYy0ghOLd1UyKp4J3FDEj/IdVdqbVgxsP740eZL2wHvjxsJF/ oe+46wENNaz36e5gRaGjmVnMseiNgvk8PVo1JnEwuhbmQOH3cZblPRhLszbfxvhtNpjt ACZwTUAluQuS1krlW6TFtDp4lVDTfjRp3NDCw59aC4QJkoOHUOpnEoJYLvTL4k0VnN7C Gehw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=56wDMJI7Cr0hDUG/CzUbbsMnZC1KqEHY2NY6DsyEqwI=; b=APRKnnmrrbAEhCCS8RZN+KPVlDj8U02KmaNTA/gTVNL8CvZvrufjTVloc78sdMivdA n1yJ9Jm/NnkUqTodC6cMo00ZENxScgg7J/4ipbVjwKElZcoGolticeBNRAtrtaeaf7am ENXUe52Pw1kXsLg1U3Nrr+DAKMUiAkyKor+RhXtXqqX2IyVkO7XQ8nshn0Rpjskxlvgh PfOGt53f/TofhNTqsh6ubC5bW6EA3BaVbO2rQC4ScrZoSbVHn5hHOZxCIe9s43rMq48h qMkkCsDLxGZtu1NkMUKHXyFREl99sPz7ISQ+ug7zT9e2IUHd1/IXQEP8Lw6J5g3GBcj+ ZvAw==
X-Gm-Message-State: AIVw111uLdC+4ph/4037q45M42epO72rS07lM6PhTDHcWFnyRkoiOhEZ HaSed4pqc4EIfzlC
X-Received: by 10.28.185.210 with SMTP id j201mr8218698wmf.52.1501004122253; Tue, 25 Jul 2017 10:35:22 -0700 (PDT)
Received: from localhost ([2001:67c:208c:10:7065:5e1b:6a46:2fbb]) by smtp.gmail.com with ESMTPSA id q27sm14204337wrc.94.2017.07.25.10.35.21 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 25 Jul 2017 10:35:21 -0700 (PDT)
Date: Tue, 25 Jul 2017 19:35:16 +0200
From: Job Snijders <job@instituut.net>
To: "Jakob Heitz (jheitz)" <jheitz@cisco.com>
Cc: Aris Lambrianidis <aristidis.lambrianidis@ams-ix.net>, "sidrops@ietf.org" <sidrops@ietf.org>, "draft-ietf-sidrops-route-server-rpki-light@ietf.org" <draft-ietf-sidrops-route-server-rpki-light@ietf.org>, Nick Hilliard <nick@foobar.org>
Message-ID: <20170725173516.q5lyiybdikctvfyr@Vurt.local>
References: <149192729348.15702.14003842869826829117@ietfa.amsl.com> <8EB8DB53-793E-4269-8CF4-6BAB1D2B76B6@de-cix.net> <B3BC1C5C-27AE-4809-82B6-297D090CEF0C@ams-ix.net> <5971FE7B.6060607@foobar.org> <F1D60787-5C00-46EF-BADE-8E68ECDEB506@ams-ix.net> <20170725152640.o2kqovryesai3ysh@hanna.meerval.net> <1fb673f586c74af8992c9b5c6a19333d@XCH-ALN-014.cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <1fb673f586c74af8992c9b5c6a19333d@XCH-ALN-014.cisco.com>
X-Clacks-Overhead: GNU Terry Pratchett
User-Agent: NeoMutt/20170714 (1.8.3)
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/ubx-7saCFYK_-3uvJxKooI4jAP8>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-route-server-rpki-light-02.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Jul 2017 17:35:27 -0000

On Tue, Jul 25, 2017 at 05:27:01PM +0000, Jakob Heitz (jheitz) wrote:
> You accept the community only from those you trust. Internal or external.

A challenge with any new transitive (extended) well-known community is
that until the thing is standardised, people don't know what to filter
and chances are the thing can just pass through anything. There even are
BGP implementations in which you cannot delete unknown extended
communities, so you'd have to wait until you receive a software update
before you can scrub those specific new types.

I don't encourage blanket community scrubbing either. So we have to be
careful when introducing new codepoints associated with specific
semantics.

Kind regards,

Job