Re: [Sidrops] mft version field issue (Was: I-D Action: draft-ietf-sidrops-6486bis-05.txt)

Stephen Kent <stkent@verizon.net> Sat, 10 July 2021 19:01 UTC

Return-Path: <stkent@verizon.net>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B3CC3A19F3 for <sidrops@ietfa.amsl.com>; Sat, 10 Jul 2021 12:01:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.439
X-Spam-Level:
X-Spam-Status: No, score=-2.439 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.338, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verizon.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kaLTiY9TimK1 for <sidrops@ietfa.amsl.com>; Sat, 10 Jul 2021 12:01:10 -0700 (PDT)
Received: from sonic315-21.consmr.mail.ne1.yahoo.com (sonic315-21.consmr.mail.ne1.yahoo.com [66.163.190.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D6C73A16B7 for <sidrops@ietf.org>; Sat, 10 Jul 2021 12:00:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=verizon.net; s=a2048; t=1625943654; bh=8QPGKziq1BIDXylwIMoA390JQPJwlju2h9+m6YMohns=; h=Subject:To:References:From:Date:In-Reply-To:From:Subject:Reply-To; b=Q9zyYiXQlNuajMuhLKIg9UhAlmDJF0P7rgwZ/G6wYmxtE9ueOL8hya/4pXZmXBshVQyEpHWiqBHQeB445tD++5ddeMnmIMBn3eZ4sf2UmabobpuFFgyrzYPvj4iSaZnl7WOxfAF7mUmYGvWwtcXpviZ9o6PS2iVq9tnaz+a/zvjmqFgazBkZ3h5bB1H+gQnmjLBX3H7DzmewR0D77wB2ctOl/O/UUOtClG6/TmCyYysMNpxxed1kVRTpEZwFHkMecaSmTgNN3V/YNHHsOqZBx6CtNK9gf2xEUjbhS+Q1d6ttoXItjn34Sf5FOZ7EbKjDiMlA322VlLsNjLtaxj7qXQ==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1625943654; bh=3zSqEOkePqpTtOc9u7DE5f3ZoQ0A1H7R7XtMY4ooFX8=; h=X-Sonic-MF:Subject:To:From:Date:From:Subject; b=rPkzw0Wpn2ffO6rG07QhrAf37cGz+uOiKJtdyMNgQWbFQoUeNQohmVDJhdkxXjUU/z0YY+WF5so3RwLTxrJ/2FVha/xh908GvhzGYp7IGKS8MRH2TBz8KnoTjxF06arVW8O2C92Ii3ktgrp0bfNTEYTFOxSHQU/EVK6Okqw86MNfg3Yi4lvKApVGNMbc5UeHJEnJjHDgkmS5EXbv1UGplHmoPz52eYfMtrDpR6SnQl5rr3oryGuewciweuIhFi7WqmQFryCtRa/C8EtWDZLD2ilNmDVq3K6RymqPmvUch5XwU8RnN3ZITocZ81DAWSf0n4oRQy/ABOl4GivdQ9OGGA==
X-YMail-OSG: 2WOuWKwVM1lcHMe3T.1suYr8JZev6sokvHHt_9mi0WiFDYmw4kgYn_ACnu69o8p dzwaiislBB_Pg7FZYcm_XEQvWJcMaj66xaMwsaVLGkv_05RGIEJ.OH96_nWAenwLS8Uv0nPCsNwO j.XMN3FmtZ.37WU43iNqhQrFzoAZ_Yqg9nIciPeyCLxOriXlUs.wvjYmNHWKNK9VfPwkg.xRjTXy VShUVk0KpwtNAxUt8FMu3ty8WLXvwGYoh39m6ypmr_dqBfNiq9vn.PRWIwyWCkgOWWP8NYeU2WyF E1r49mGLUu_FP5blhu1B463qLmipADRCk_BRPcpRrN.8yPUflOGIUp53nlYovK2gvTz6wbf.Xr4A jXixZHiQCvEoN58y6Pz4k6V4FMIDAV3_TXFtE8s3.k8l_wfoOfEFh2lHKpZ6TCDR0rOJyoW1XBas WMDWLkxIongiCy6ffpqW8ib8j3PJUwnMfNtJtSCCQD1X4hkOBsfwl.wKBhfQaVFG7acbKA6D6nPB 3D327BtYtVRobV4joWs4pYmCoZY.91R5F5Dra1jh4nQHXW4VzxOBJJV25mZVnLp5MseX9o64AeZS B9E4p6rDBJp5K9Fs7OhbzE9cFlEsYK6ZqrfyzcDVpspiyKFFgjR8FmaCHDrSuiHTE4akoJTR4CV9 KxQWyX5dJvnjkX5Z9DcNIcQ7GyAy5vX_d4MQOx5PbQe78TrL9pJ0RAoyg.lgfxGKikxC4vSm4Bgs LIYge8c8k3Oy98iTMteunRApX_ooj2ltYTlMyCAI9.5hph5I27k4zDujhWXyLKPdVccJaPuw1ExI IBxogII7Z8PFNMBDeR6KC9RO9Pi4HX4FDFGpeQftKEAedDpKefO73jBBaFR2cghjvKK3FIdhx.kY aYKq2nwaBj1DLOXKRKDcchWaItuyXiqvWsKxCRIckcZwgDvq.g4tbk3_Hc9Etbok8Rgfpe5xfxF3 gMuob_9qBC7NHLr72u3pQLz.9XV3eNLHKkxJd_iHaiuYQ.VWsppY25F0810S8_GUis8TcEYawPO2 cU2dq91JE7H2DiP8lCrxsrHUh0qTaMiA06fYQVaqQt2WynGrcBmj77qQKLfY3pp6i8fUAw8N15a. Odr4nfEhtNlKF3x59gzG5XoGOH9ZivQvowydw7mQhDRF7IgbCrxXhO6_Jz5rRqQI29.LL.ujkerh y8MPRHBwDg1nW__w8PHjvsk.WSSqrdJbkZ7Td_kY.g1l4mALMB7X5obeEWsYX2Z4qGEWnknU_OYs FTmOxLou3M_P1_nea4HaIjNgDNW9Y610J1a8MdSfcQVhFxzF3J3TKax7clP5Jx_g90p7dibMqn2L 2qV0H1HMiQUcZvjw2v4ikuW.KkgESU8Dde7yns1AUgfaHPALvre_3.2uGi88mvCKeytl1QRsy6kr fJptd7nrp9Q7ydyExRMJYt_3NmHWniqp0aX6tfovPFsqlbS5B8_GbUmM2.Q_GeEHNApAXo5pguue kAXK45vJ.dd_P0JNypGjBPs4lCdw7Is8jhVh5VK5p5dXEWsvtvBdb.SyH_KPniB8GcchdM0ukeUE pJiJgmO0EMOQ7SD0tgwUSWoIDANs9i1KNS5G_GX8Z8dts6BCJaeolk4YWj8RK4Hdn3_XIz9CeIWq o4eq22QeJCouXtfDLYy8jQhqIMcSzDfG3NInxIgGaTY6IAjFF81g05A5us9mbpkLcj8X9yjQhPds kIIqHp.lExrb0ttWCkzK7hh1P7fZY5IpLvS79SKza4uJyyeuCWP39FPcPMdAjX.bKbJo4mZGFVU1 tG1tvlHiMp1hli2R_2_1U_jLMNua9k3njJRaxwhD244Fk9ucCeVlp5rX4sPlNDMJnWQgbO7bV9xa dn8WMsHB4t.vhRQhGZYICbfV7ULmGcWIBI3t6TZpsOZaUpEDb0sa3NWTRP_FzfqFTdJJM71t_9GB zlIWLxSYuizEIOgODGZdBLTVXqex0CjUNjwhHj1xKfwfeIwH3Sci9RfyEvYIQ8KkwOSNZpHWW9.6 PhPI_IjmvHHNalcMV_qZsFJF8Qdw6u03QDiO8gFJis2_l9ewueMhK.IXXRbpB7Q4yj4839x5CVcA DhXlFbpqJ_7FJL5NX1IPBhWS7Ar4QMO3GMeCGv90zUSCqVvs3CJUtKKPozRVzfV7JCVZE6Gclz02 SRC8U9lr.mAtc9UXrPkIsxa1cP7fTt.D9J.x9VZJB9EwZsxsRry6b.n6wdJybKshqApyR5ifxBhf h5Q3F9_tuy3RSrOWbv3FWMB2BAgd02xzqKDRz5Z9LX4.7DMH6JfAXQn2fF7QPvAd_wygk_Ry0ECh OdWKiUdicbxI7DnXQurv4lA7j8EoZ4Y26hgXUFDYfRs6VCIGW9avDItDJD2LEPnE90jrPF86OvNi ly1.5YF4mfcuF3vvr2RnbmACJ7KaY3SH2XWAwOaMDiETEKZl0Eel1Dj6R7SJdmWaZ9FCzG.GdYd. XMC8d19WRCYwEOUybyLKFzLOkRa2LPY9FLw--
X-Sonic-MF: <stkent@verizon.net>
Received: from sonic.gate.mail.ne1.yahoo.com by sonic315.consmr.mail.ne1.yahoo.com with HTTP; Sat, 10 Jul 2021 19:00:54 +0000
Received: by kubenode547.mail-prod1.omega.bf1.yahoo.com (VZM Hermes SMTP Server) with ESMTPA ID ab90bd83e10f5c970d8b98cb91cd96d4; Sat, 10 Jul 2021 19:00:48 +0000 (UTC)
To: sidrops@ietf.org
References: <YOnj0sIs8ecU7uCG@snel>
From: Stephen Kent <stkent@verizon.net>
Message-ID: <17a30b20-ce2e-b424-b56c-162c120e2ca9@verizon.net>
Date: Sat, 10 Jul 2021 15:00:47 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.0) Gecko/20100101 Thunderbird/78.11.0
MIME-Version: 1.0
In-Reply-To: <YOnj0sIs8ecU7uCG@snel>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
X-Mailer: WebService/1.1.18469 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.aol
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/y0tezeC9p8PMNEJYAEfEBHlICb0>
Subject: Re: [Sidrops] mft version field issue (Was: I-D Action: draft-ietf-sidrops-6486bis-05.txt)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 10 Jul 2021 19:01:18 -0000

Job,
> (spinning off a new thread)
>
> On Sat, Jul 10, 2021 at 12:01:32PM -0400, Russ Housley wrote:
>> The point of the version field is to help know what to do when you
>> stumble.
> I'm starting to suspect that: RFC 6486 section 4.4
>
>      "MUST check version of the rpkiManifest is 0"
>
> .. should've been along the lines of:
>
>      "MUST be set to version 0, and MUST be ignored when validating"
>
> I checked a few RPs and it seems that most RPs will consider a Manifest
> invalid if it contains a version field, because of the 4.4 language.

And they would be behaving properly if they did so.

Ignoring the version field would not be consistent with IETF policies 
employed in many, many RFCs.

> At this point in time the 'version' field in Manifests is not usable as
> a transition mechanism towards anything.
see my reply to your earlier message, which describes how one might 
accomplish such a transition.

Steve