[Sidrops] Re: BGPSec certificate validity period
"Dale W. Carder" <dwcarder@es.net> Mon, 20 October 2025 17:08 UTC
Return-Path: <dwcarder@es.net>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 24B55785BD18 for <sidrops@mail2.ietf.org>; Mon, 20 Oct 2025 10:08:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=es.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H8thaqOAr6qN for <sidrops@mail2.ietf.org>; Mon, 20 Oct 2025 10:08:18 -0700 (PDT)
Received: from mail-io1-xd2c.google.com (mail-io1-xd2c.google.com [IPv6:2607:f8b0:4864:20::d2c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 84B9A785B545 for <sidrops@ietf.org>; Mon, 20 Oct 2025 10:04:51 -0700 (PDT)
Received: by mail-io1-xd2c.google.com with SMTP id ca18e2360f4ac-940d2b701a3so180571639f.0 for <sidrops@ietf.org>; Mon, 20 Oct 2025 10:04:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=es.net; s=esnet-google; t=1760979885; x=1761584685; darn=ietf.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=GEPJLWdfy3qAFL4HLBXmD6X4Q/EfooDKjiGdl8sGs7w=; b=kwa4l/dZ9++qGgNLojY6WJG7OkML/VXvSXMFwv6g6lEsSwh5FfalkV7+VaowW7qRgh iaXN3fiQ6grPJ3ALX9Lz0FDPcsnjV4ClXsNhjALZidxlRMiIdXvZrYkkX7DYTZvcJMNT lh/d+/lkwCoQKkbpDqf1yriA09F8cYEXpEFK21Vk0YPCcelWQQNHqTps95k3KUIiMVkC r5lIPioxhJ/1QCa6DQSdH8DX5OVMl/Fp8/88A+Yf8DzMbS+u52d/cTaAFFZKDFtngGg8 bz/YFdwhdJuCHEpOBh0Zzi2bhaxMFQXsR3adOZ5AA/SBBd9ImRI+su4SJbsqk1lrJAtL USrw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1760979885; x=1761584685; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=GEPJLWdfy3qAFL4HLBXmD6X4Q/EfooDKjiGdl8sGs7w=; b=qvne7Qyhxh/UKI1CcIE/2h5e0pbr3Ou2MYpNa+BVMN2QYY8A3P5HslYj2ic3RufIg/ MJp9MsIxNOE4/NRfQdWbhzXLkvI98w9CY0wvWFgywaRXjlAmdYMMiNlkSBd0ylLXTHOQ 1nPhWZ6buXxKFF+/PyA+/jiwtQ+I6AdUvQ6MqTMQXmCxTcoxks6XL+71Yx6x2TRGOfbe aWOhesBzdweYPGJsnX8cN3sQs4mfdshRTxC8iH5e3984aBHaZgvZo5weu6eLhbyJQkoa KqgwCdp2h0bsjYm7qMUSa2KDtSUrqP3+EN8qKzeshf6tlZ08xytymu3/n0jvjExiNsRd zzgw==
X-Forwarded-Encrypted: i=1; AJvYcCUnn0l2U15VQd8P5zdCJE3wg4eVJw81IluSTUgZ/zR2ftnZ9iJLp0sff9j+aY5szQttvPBTnhz7@ietf.org
X-Gm-Message-State: AOJu0YwIRKz2lqe/QCF0iOeAwtlv1773EoUUEjlTu2vNWL/k41ukBByg dy0TOSAebDNNAkS0b0EzE3Es0YmfViZJPSys8Ta2wN6lg+Uu4pPp79arghKHEdlJaVROB9DoCfw TYQjMKyXJg/Rv9FvvYRS9RZ2X1xqHN8JgmmqEktKTEajpxlGFZfwkRCIjm5GXP3WCpy9khyJwsS M398McmM0URmsXXp0z0u+BtQmrPpGhWg==
X-Gm-Gg: ASbGncvOFp0yzFe12APPzg2M7tfp+n2CtL47I8ABLdShGcAWY2kmVXnU3wKpmxKiFDC 4s8Nzs1nrJSJ7Lh/vPqZ5uDM4rFpZMio9ndbUPk7tEMpiGrZaPoK5LxxpYjTRg5mXAqK/gZ+J0G /ZBFby/sVLthCfCi7RmFjDQuu0BKPPumV4Gw4hD4yNTlgoGE16XvWndLOU5gOicAtAUxiSBTh2D ZnMIdX3S1/WVuuZegg8ptN3hd6pi6EZUvJWMfCssF3B6gtzeRovn1gOEGFt+XDmW00SeCYTE8nX jM/kbeg3+KwkgFB78tmlvydtq4w9odENPZNhk5dyzi0Ttuto70fNjXbL2HOvDJM9HEKqDr9YZwe YX5BsbEWclhyJzTnH4RMFc4FU+a75vppIc4Or82svrSPQybUKtgHwdWi0fqJ1CMzxx9FVcAoMPr HUcv7ALbddiwc=
X-Google-Smtp-Source: AGHT+IEIM+x4P7ivRMdxGak2Nm3Bny/9GQ1h5LCGTEs14m8OyOwUdPwveKppfwfudp8xuJ62bATBUw==
X-Received: by 2002:a05:6602:6d14:b0:940:d327:8fd6 with SMTP id ca18e2360f4ac-940d3279111mr1013404939f.7.1760979884414; Mon, 20 Oct 2025 10:04:44 -0700 (PDT)
Received: from localhost ([2600:6c44:5f7f:b901:f846:815:9f29:a164]) by smtp.gmail.com with UTF8SMTPSA id 8926c6da1cb9f-5a8a976d081sm3080618173.53.2025.10.20.10.04.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Oct 2025 10:04:43 -0700 (PDT)
Date: Mon, 20 Oct 2025 12:04:42 -0500
From: "Dale W. Carder" <dwcarder@es.net>
To: Russ Housley <housley@vigilsec.com>
Message-ID: <aPZrqkCqClB58Dra@dwc-studio.local>
References: <CAGPuK+6Xs=Zu-vWohihma0UuW+3e4o_GhqZA_H-oNHgUb8MwkQ@mail.gmail.com> <060C7D32-4543-4E54-B902-A506A3137642@vigilsec.com> <CAKr6gn3nfxTfThbRS_2=TxnLcjrTYWFe5k+ic8VfYjtJ=H5SYw@mail.gmail.com> <33247145-EB2C-4E1A-B208-E97E47A82792@vigilsec.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <33247145-EB2C-4E1A-B208-E97E47A82792@vigilsec.com>
Message-ID-Hash: 3AKGRKIRNTZTEYFLWUKLHDRX6KMW267D
X-Message-ID-Hash: 3AKGRKIRNTZTEYFLWUKLHDRX6KMW267D
X-MailFrom: dwcarder@es.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: George Michaelson <ggm@algebras.org>, IETF SIDRops <sidrops@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Re: BGPSec certificate validity period
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/zYz515H47TQZrXEM1EF1czHtS3Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>
Thus spake Russ Housley (housley@vigilsec.com) on Thu, Oct 16, 2025 at 04:36:33PM -0400: > George: > > How often does the NOC want to push a new certificate to the router? It's worth pointing out there are other reasons to manage certificates on routers, for example all of the devices on our network have managed TLS certs for gRPC network management (gNMI) these are headed towards 47 days or whatever the latest number is. The infrastructure to maintain that is likely comparable to this effort, but I don't think we have the same issue here motivating short lifetimes (CRL essentially being nonfunctional). Dale > > On Oct 16, 2025, at 4:33 PM, George Michaelson <ggm@algebras.org> wrote: > > > > If the Web is moving to short lifetimes and the mechanism is automated, are there specific positive reasons to anchor BGPsec issuance as a long lifetime event? > > > > It would help enormously (in my opinion) to have a "because .." statement tied to the assertion of a lifetime. > > > > G > > > > On Fri, 17 Oct 2025, 2:39 am Russ Housley, <housley@vigilsec.com <mailto:housley@vigilsec.com>> wrote: > >> Mikhail: > >> > >> > RIPE NCC is working on BGPSec support in our RPKI backend to allow > >> > users to manage BGPSec signing requests and generate router > >> > certificates from them. > >> > > >> > One of the questions that has come up in the meantime is: what should > >> > be the validity period of router certificates? > >> > > >> > - RFC 8209 doesn't mention the validity period at all. > >> > - RFC 8634 does mention it, but doesn't recommend a value. It just > >> > states: “The validity period for these certificates is typically > >> > expressed in the CA’s CPS document.” I am inclined to interpret this > >> > as meaning that the router certificate validity period should match > >> > that of the corresponding CA certificate. > >> > >> I think you are free to specify a validity period in the CPS, but it can extend beyond the validity period of the parent CA certificate. > >> > >> > >> > - I have also seen two different LLMs hallucinate a 35-days validity > >> > period referring to some (might be completely made up) older draft, I > >> > haven’t found any reference to that myself though. > >> > >> The WebPKI is pushing toward 35 days. I suspect that the LLM does not know the difference between the WebPKI and the RPKI, but I could be hallucinating too ;-) > >> > >> > So, is there a consensus on router certificate validity periods? > >> > >> I do not believe that this has been discussed here before, so there is no consensus. > >> > >> Russ > >> > >> _______________________________________________ > >> Sidrops mailing list -- sidrops@ietf.org <mailto:sidrops@ietf.org> > >> To unsubscribe send an email to sidrops-leave@ietf.org <mailto:sidrops-leave@ietf.org> > > _______________________________________________ > > Sidrops mailing list -- sidrops@ietf.org > > To unsubscribe send an email to sidrops-leave@ietf.org > > _______________________________________________ > Sidrops mailing list -- sidrops@ietf.org > To unsubscribe send an email to sidrops-leave@ietf.org
- [Sidrops] BGPSec certificate validity period Mikhail Puzanov
- [Sidrops] Re: BGPSec certificate validity period Job Snijders
- [Sidrops] Re: BGPSec certificate validity period Russ Housley
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Russ Housley
- [Sidrops] Re: BGPSec certificate validity period Job Snijders
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Dirk Doesburg
- [Sidrops] Re: BGPSec certificate validity period George Michaelson
- [Sidrops] Re: BGPSec certificate validity period Tim Bruijnzeels
- [Sidrops] Re: BGPSec certificate validity period Dale W. Carder