Re: [Sidrops] adopt draft-ymbk-sidrops-rpki-has-no-identity please

Mikael Abrahamsson <swmike@swm.pp.se> Wed, 24 March 2021 06:19 UTC

Return-Path: <swmike@swm.pp.se>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D82D3A245A for <sidrops@ietfa.amsl.com>; Tue, 23 Mar 2021 23:19:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=swm.pp.se
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EA3UVQt2DAuK for <sidrops@ietfa.amsl.com>; Tue, 23 Mar 2021 23:19:43 -0700 (PDT)
Received: from uplift.swm.pp.se (ipv6.swm.pp.se [IPv6:2a00:801::f]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC2743A245C for <sidrops@ietf.org>; Tue, 23 Mar 2021 23:19:42 -0700 (PDT)
Received: by uplift.swm.pp.se (Postfix, from userid 501) id 0E05DB4; Wed, 24 Mar 2021 07:19:33 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=swm.pp.se; s=mail; t=1616566773; bh=5edyDF863BT0zosaDG+9nd2JiwAxgbPp5Az7TeTMZ5o=; h=Date:From:To:cc:Subject:In-Reply-To:References:From; b=0y7xoz4Ra8RI+3cCIPlq976XAxIzTuPa3EQFC0HFVn9XPtf6iehu84Z8Om1cj/qDb xACqGnscvGll3o1BrlTaXHnlJA1YGCvB/AnnuaIftZ6npSk9yEBDGanTeKBs8qWqv4 FHFCB8kNv5waa1GPrOf35lIl881+vsMu8H3Vwg4s=
Received: from localhost (localhost [127.0.0.1]) by uplift.swm.pp.se (Postfix) with ESMTP id 09FD0B3; Wed, 24 Mar 2021 07:19:33 +0100 (CET)
Date: Wed, 24 Mar 2021 07:19:33 +0100
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: Randy Bush <randy@psg.com>
cc: George Michaelson <ggm@algebras.org>, SIDR Operations WG <sidrops@ietf.org>
In-Reply-To: <m2ft0lz0h3.wl-randy@psg.com>
Message-ID: <alpine.DEB.2.20.2103240715470.21528@uplift.swm.pp.se>
References: <m2ft0sgwfy.wl-randy@psg.com> <alpine.DEB.2.20.2103231615441.21528@uplift.swm.pp.se> <m2pmzpz41r.wl-randy@psg.com> <CAKr6gn2BWm0ZwuqwLc=g7FXgqbt0eqJ3tWJW7BzP=vEn6qCEcA@mail.gmail.com> <m2mtutz3s4.wl-randy@psg.com> <CAKr6gn2YM+5+3BMPUPM0O-C_VP5dprQyOyXkxvAKDhP7tfDbyQ@mail.gmail.com> <m2im5hz2qt.wl-randy@psg.com> <CAKr6gn3m6aBV_PkZQQfnEg2R5M92kfJhvGfAiu-3XW++bdR=1A@mail.gmail.com> <m2ft0lz0h3.wl-randy@psg.com>
User-Agent: Alpine 2.20 (DEB 67 2015-01-07)
Organization: People's Front Against WWW
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"; charset="US-ASCII"
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/v52Jx933P2aEyX90zUUxNHjlRCs>
Subject: Re: [Sidrops] adopt draft-ymbk-sidrops-rpki-has-no-identity please
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Mar 2021 06:19:48 -0000

On Tue, 23 Mar 2021, Randy Bush wrote:

> from the sec cons
>
>    When a document is signed with the private key associated with a
>    RPKI certificate, the signer is speaking for the INRs, the IP
>    address space and Autonomous System (AS) numbers, in the
>    certificate.  This is not an identity; this is an authorization.

Agreed.

Are you opposing the use of RPKI for signing LOAs, because I don't see the 
document affecting the use of RPKI for RSC for signing LOAs.

The document says it doesn't prove identity. Correct. We all seem to agree 
on that. Now what?

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se