[Sidrops] Re: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024)
"Lubashev, Igor" <ilubashe@akamai.com> Wed, 22 May 2024 13:43 UTC
Return-Path: <ilubashe@akamai.com>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D1CFC1B164C; Wed, 22 May 2024 06:43:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.992
X-Spam-Level:
X-Spam-Status: No, score=-1.992 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U4jkJYvf_t5P; Wed, 22 May 2024 06:42:58 -0700 (PDT)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [67.231.157.127]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32765C180B53; Wed, 22 May 2024 06:42:58 -0700 (PDT)
Received: from pps.filterd (m0409411.ppops.net [127.0.0.1]) by m0409411.ppops.net-00190b01. (8.18.1.2/8.18.1.2) with ESMTP id 44MCFuqf017927; Wed, 22 May 2024 14:42:57 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h= from:to:subject:date:message-id:references:in-reply-to :content-type:mime-version; s=jan2016.eng; bh=wI/80W5I+tQKrayYwZ MIoxnLfsD4oG3feJLA9lew6JU=; b=YtJH5pj0nTyjzPDsnyuJqQDL2wYQjqsfsi PEjeGsytgJvFE/lcnJ6Nah1U9A2mUAWZcUIdO1v+6LPdAsrxWajXbzlcBirSaV9c 4R/DxkGNwYeY7oBoLwZLPTf4MB0QxE9l9rdFYIaLINnmr7iSgMo16ZoPG/SmWIa8 qvDs1m4KOozQjgNGAYJE0yqyvpnmO9l+EoiCVwFih/qz5ZBZZpkh/X3TDlriyJ20 SeQQoKaEiKVBNJhC4EYJJ92bKXRDp6dltrbcDxl1sYuchuTRKCvPdP2x7AIqF3wP 5DtdeRKpARrQGVA6W/DxhQsojIKfx/Dk6F+mgTwNEDgTeNmP1w+A==
Received: from prod-mail-ppoint7 (a72-247-45-33.deploy.static.akamaitechnologies.com [72.247.45.33] (may be forged)) by m0409411.ppops.net-00190b01. (PPS) with ESMTPS id 3y8pfwst6u-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 22 May 2024 14:42:56 +0100 (BST)
Received: from pps.filterd (prod-mail-ppoint7.akamai.com [127.0.0.1]) by prod-mail-ppoint7.akamai.com (8.17.1.19/8.17.1.19) with ESMTP id 44MB5J9t007539; Wed, 22 May 2024 09:42:56 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.206]) by prod-mail-ppoint7.akamai.com (PPS) with ESMTPS id 3y6qnx7fcd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 22 May 2024 09:42:55 -0400
Received: from ustx2ex-dag4mb3.msg.corp.akamai.com (172.27.50.202) by ustx2ex-dag4mb7.msg.corp.akamai.com (172.27.50.206) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.34; Wed, 22 May 2024 06:42:55 -0700
Received: from ustx2ex-dag4mb3.msg.corp.akamai.com ([172.27.50.202]) by ustx2ex-dag4mb3.msg.corp.akamai.com ([172.27.50.202]) with mapi id 15.02.1258.034; Wed, 22 May 2024 06:42:55 -0700
From: "Lubashev, Igor" <ilubashe@akamai.com>
To: Keyur Patel <keyur=40arrcus.com@dmarc.ietf.org>, "sidrops@ietf.org" <sidrops@ietf.org>, "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
Thread-Topic: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024)
Thread-Index: AQHaqm7YngWOUGzeEUmaVQKZf+T99bGjPovQ
Date: Wed, 22 May 2024 13:42:55 +0000
Message-ID: <9d4d099dcdf042538fb92872ce357dd8@akamai.com>
References: <D20B81DD-3BAB-41F2-A1B5-5EE9553820E7@arrcus.com>
In-Reply-To: <D20B81DD-3BAB-41F2-A1B5-5EE9553820E7@arrcus.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.27.118.139]
Content-Type: multipart/alternative; boundary="_000_9d4d099dcdf042538fb92872ce357dd8akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.650,FMLib:17.12.28.16 definitions=2024-05-22_06,2024-05-22_01,2024-05-17_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxlogscore=999 adultscore=0 suspectscore=0 spamscore=0 bulkscore=0 malwarescore=0 phishscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2405010000 definitions=main-2405220091
X-Proofpoint-GUID: PrtDsJeHvnpixQ1wD2yiEgafBJxO7uhu
X-Proofpoint-ORIG-GUID: PrtDsJeHvnpixQ1wD2yiEgafBJxO7uhu
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.650,FMLib:17.12.28.16 definitions=2024-05-22_07,2024-05-22_01,2024-05-17_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 clxscore=1011 adultscore=0 bulkscore=0 suspectscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 malwarescore=0 priorityscore=1501 impostorscore=0 lowpriorityscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2405010000 definitions=main-2405220092
Message-ID-Hash: FMKD3LBOCSQM3TGM6UDM5BKFRZ56PSV4
X-Message-ID-Hash: FMKD3LBOCSQM3TGM6UDM5BKFRZ56PSV4
X-MailFrom: ilubashe@akamai.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Sidrops] Re: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024)
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>
(Replying to the correct thread now) I’ve read the draft, focusing mostly on section "6. BGP Security Threats Addressed by SPL-ROV" -- the problems SPL wants to solve that are not solved by ROA and ASPA. I see threat 4 as the real concern here without a widespread ASPA adoption. Just for that I support the adoption. It is especially important to solve thread 4 if we are recommending adding ASNs to ROA for direct server return cases for SAV purposes (for algorithms like BAR-SAV). I do have questions about the rest of the threats mentioned. Threats 1, 2, and 5 are "If someone is forging some announcements, do not let them blame it on my AS". Is this “AS reputation” a big concern? Protecting against threats 1 and 5 does not help protect any packets from being misrouted/hijacked (and no IP space is being hijacked in threat 2 to begin with), since the malicious AS can pick any other ASN as the origin. It is just about not letting my AS show up as the "origin", right? Threats 2 and 4 can be mostly solved by ASPA (but only if providers also maintain ASPA entries, transitively, so it is a tall order). Threat 3 can be solved by ROA, but that may be not under AS’s control. It is really an AS protecting against its own mistakes. -Igor From: Keyur Patel <keyur=40arrcus.com@dmarc.ietf.org> Sent: Monday, May 20, 2024 12:33 AM To: sidrops@ietf.org Subject: [Sidrops] Re: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024) Apologies. The call will end on June 3rd, 2024. Best Regards, Chris, Russ & Keyur From: Keyur Patel <keyur@arrcus.com<mailto:keyur@arrcus.com>> Date: Sunday, May 19, 2024 at 9:30 PM To: "sidrops@ietf.org<mailto:sidrops@ietf.org>" <sidrops@ietf.org<mailto:sidrops@ietf.org>> Subject: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 05/03/2024 (May 3 2024) Hi Folks, The authors have requested SIDROPS working group adoption call of “Signed Prefix List (SPL) Based Route Origin Verification and Operational Considerations” https://datatracker.ietf.org/doc/html/draft-sriram-sidrops-spl-verification-00<https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/html/draft-sriram-sidrops-spl-verification-00__;!!GjvTz_vk!XJq45dgfY2vTeN3ZypjIExVRlPsFsb_6nUuGexuJplnJGhUr96u7XCIMSdU2acD4lW7qlHYrybGrnQ-zIKTXdGQJZn67MA$>. Please send your comments to the list. The adoption call will end on May 3rd, 2024. Best Regards, Chris, Russ & Keyur
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Keyur Patel
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Lubashev, Igor
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Borchert, Oliver (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Lancheng Qin
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Amir Herzberg
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Tim Bruijnzeels
- [Sidrops] Re: WG Adoption call for draft-sriram-s… junzhang
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… gengnan
- [Sidrops] Re: WG Adoption call for draft-sriram-s… gengnan
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Libin Liu
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Yangyang Wang
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: Closed - WG Adoption call for draft… Keyur Patel
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Ties de Kock