Re: [Sidrops] I-D Action: draft-ietf-sidrops-https-tal-05.txt

George Michaelson <ggm@algebras.org> Fri, 12 October 2018 06:53 UTC

Return-Path: <ggm@algebras.org>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53B6E130DE2 for <sidrops@ietfa.amsl.com>; Thu, 11 Oct 2018 23:53:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=algebras-org.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yZf2LpXWKovX for <sidrops@ietfa.amsl.com>; Thu, 11 Oct 2018 23:53:36 -0700 (PDT)
Received: from mail-wr1-x42e.google.com (mail-wr1-x42e.google.com [IPv6:2a00:1450:4864:20::42e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A763130DFD for <sidrops@ietf.org>; Thu, 11 Oct 2018 23:53:36 -0700 (PDT)
Received: by mail-wr1-x42e.google.com with SMTP id e4-v6so12195377wrs.0 for <sidrops@ietf.org>; Thu, 11 Oct 2018 23:53:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=algebras-org.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=99ha/pfrpJkIEpzsmDJg2dgPfyJJQzupLKQCqkqYrCI=; b=JNqB3lub1aoiLmOGVuoBLHlGxkDyNEa45mG3Q0YzMkuUbu+zZ+q5wHuLJshkQzj2UB s6qjwH4WUEg2j6InQcile9SC29dWZFyucnpwsDNRrV9dCUYniYMuXyQn0NyTgi6c08es 3ytH1FkHA+gAp8Mgw9+MPrJEMcrvVTFqlAeJ09p6FEzHH+EBjWKmr1bpvevVLZsGM5qP XYHoCS5XREpFG0FyrGF+t18HB2e728o1ToE1gdDNRmCDkQXYcmZOZiPn6mb3UAw0SoZx kj06j5VUIzK/On2WXj+kVJRljoae/MEhfxYxklh3nx0f6vHBGuR4fn+2HAETASkTWZmF Zauw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=99ha/pfrpJkIEpzsmDJg2dgPfyJJQzupLKQCqkqYrCI=; b=G8gfpRkCfEsAuj6ts8TkTm7kNLFtnJgsAYlgAs6LshvGTjemAt90MbS+Yv2OYbmQvZ 3h/x8Rt75t0r3jYtQCAKZ/rgOvHYEeA7CA6/vhs4f9ZBUU+SXQSSJFkPFCQYoq0BYc/S zTAd8EujLfj9qy2uq3RYlj0q5pEPYBNdTJbxEjjJynmLoW5haTTK/8T7lYoJ7YTD6FlN /MiXAsKMyvtKIBGcARcsP+1j1yjMzmhrBPOXDCRaBTJD8Yb64jrSYqxUjGxQhVBbTshb Cur5UVwgpzBPohHrGhH4YL8d1ETn8REzZDWa96vChWPZm51WltSpLcu+SmW2oFvRv0Np nJZA==
X-Gm-Message-State: ABuFfogQYO5h8Npad1rJA+GgYQGjs9O1UmxQ1h0132fSNxlGtYn6hFdZ nLlKpWeN8lbWSgUC5d8OlCbpRhTl35Fgqrrl3tma5w==
X-Google-Smtp-Source: ACcGV61N2ohU+Rtrmme4RlMrGMc7VH0YooBh3drTnfd0XwK9+Dun6HREQ7WDC31YMASzI99HNSDP4WFu2//U7ZCdDPM=
X-Received: by 2002:adf:b211:: with SMTP id u17-v6mr3915421wra.180.1539327214480; Thu, 11 Oct 2018 23:53:34 -0700 (PDT)
MIME-Version: 1.0
References: <153925494724.11328.7326464820425639379@ietfa.amsl.com> <D9837A46-79FF-4702-AAF0-E892D6689C07@nlnetlabs.nl> <CACWOCC_j-Un5VFAmW10diynYFz_GX2tgzBaY1c-gEzDo=C19Qw@mail.gmail.com>
In-Reply-To: <CACWOCC_j-Un5VFAmW10diynYFz_GX2tgzBaY1c-gEzDo=C19Qw@mail.gmail.com>
From: George Michaelson <ggm@algebras.org>
Date: Fri, 12 Oct 2018 08:53:22 +0200
Message-ID: <CAKr6gn1SejDbZwFG4mSs-XKiwzZLQ+0c8AY65kiQ-Y0o2nk8XA@mail.gmail.com>
To: Job Snijders <job@ntt.net>
Cc: tim@nlnetlabs.nl, SIDR Operations WG <sidrops@ietf.org>, i-d-announce@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/wpxI4vu7vlTNe8va8CkuQH-sVhw>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-https-tal-05.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Oct 2018 06:53:41 -0000

We need to deploy processes for TAL and repository fetch and
synchronisation which can move to CDN. As it stands, the design of the
repository fetch systems is heading to single points of failure
because Rsync is a very poor fit for anycast distribution (no
commercial entities I know of are offering it as a service, where all
of them offer HTTP(S) as a matter of course)

Please can we close on this draft, because its the simple, obvious
change to permit the TAL to be formally distributed by scaleable
mechanisms, and helps point a way out of what I feel is a major
operational design flaw.

The comments section has potential for people who are trapped behind
legal disclaimer issues. I understand some of you feel paying
attention to this is wrong, but it does not (to my mind) directly harm
the overall intend of the proposal to adopt HTTP(S) as a
carrier/transport to the data.

(speaking as a co-author)

-George
On Fri, Oct 12, 2018 at 12:33 AM Job Snijders <job@ntt.net> wrote:
>
> Hi,
>
> The comment character will *maybe* help unblock some distribution issues that some are facing in the North American region.
>
> Kind regards,
>
> Job
>
> On Thu, Oct 11, 2018 at 19:59 Tim Bruijnzeels <tim@nlnetlabs.nl> wrote:
>>
>> Dear WG,
>>
>> I asked for last call on a previous version of this document back in April, but it got stuck somehow
>>
>> However, this version -05 now includes an optional comments section at the start of the TAL file, which was suggested to me off list. The idea is that this section can be used to provide some additional information to operators.
>>
>> I want to ask the WG to consider first. If there are no major concerns then I will ask the co-chairs to initiate last call.
>>
>> Kind regards,
>>
>> Tim
>>
>>
>>
>>
>> > On 11 Oct 2018, at 12:49, internet-drafts@ietf.org wrote:
>> >
>> >
>> > A New Internet-Draft is available from the on-line Internet-Drafts directories.
>> > This draft is a work item of the SIDR Operations WG of the IETF.
>> >
>> >       Title           : Resource Public Key Infrastructure (RPKI) Trust Anchor Locator
>> >       Authors         : Geoff Huston
>> >                         Samuel Weiler
>> >                         George Michaelson
>> >                         Stephen Kent
>> >                         Tim Bruijnzeels
>> >       Filename        : draft-ietf-sidrops-https-tal-05.txt
>> >       Pages           : 10
>> >       Date            : 2018-10-11
>> >
>> > Abstract:
>> >  This document defines a Trust Anchor Locator (TAL) for the Resource
>> >  Public Key Infrastructure (RPKI).  This document obsoletes RFC 7730
>> >  by adding support for HTTPS URIs in a TAL.
>> >
>> >
>> > The IETF datatracker status page for this draft is:
>> > https://datatracker.ietf.org/doc/draft-ietf-sidrops-https-tal/
>> >
>> > There are also htmlized versions available at:
>> > https://tools.ietf.org/html/draft-ietf-sidrops-https-tal-05
>> > https://datatracker.ietf.org/doc/html/draft-ietf-sidrops-https-tal-05
>> >
>> > A diff from the previous version is available at:
>> > https://www.ietf.org/rfcdiff?url2=draft-ietf-sidrops-https-tal-05
>> >
>> >
>> > Please note that it may take a couple of minutes from the time of submission
>> > until the htmlized version and diff are available at tools.ietf.org.
>> >
>> > Internet-Drafts are also available by anonymous FTP at:
>> > ftp://ftp.ietf.org/internet-drafts/
>> >
>> > _______________________________________________
>> > Sidrops mailing list
>> > Sidrops@ietf.org
>> > https://www.ietf.org/mailman/listinfo/sidrops
>>
>> _______________________________________________
>> Sidrops mailing list
>> Sidrops@ietf.org
>> https://www.ietf.org/mailman/listinfo/sidrops
>
> _______________________________________________
> Sidrops mailing list
> Sidrops@ietf.org
> https://www.ietf.org/mailman/listinfo/sidrops