
From nobody Mon Oct  5 11:03:45 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55DDE1B29F9 for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 11:03:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3r7F4Ai6s8bK for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 11:03:43 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 04B8F1B3207 for <sidr@ietf.org>; Mon,  5 Oct 2015 11:03:42 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 2983128B003D for <sidr@ietf.org>; Mon,  5 Oct 2015 14:03:41 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 01ABE1F8035; Mon,  5 Oct 2015 14:03:40 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_4D5EF2B5-6651-4902-AFBA-C834A8932782"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Mon, 5 Oct 2015 14:03:40 -0400
Message-Id: <E91F4D62-1FB4-4AFE-B07D-34019EAB031F@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/r8qpMaWE_2lNlTvWULmc1eZHKtM>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] draft-ietf-sidr-rfc6490-bis-04 - " Revised I-D Needed "
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Oct 2015 18:03:44 -0000

--Apple-Mail=_4D5EF2B5-6651-4902-AFBA-C834A8932782
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The draft draft-ietf-sidr-rfc6490-bis-04 was approved by the IESG, =
provided the comments received during IETF Last Call were addressed.

The IETF Last Call comments were noted to the sidr list in =
http://www.ietf.org/mail-archive/web/sidr/current/msg07208.html.

As wg co-chair, I am satisfied that wg has consensus is to adopt =93Option=
 #2=94 [ (allow but do not mandate line breaks)] as mentioned in the =
message that brought up the problem =
[http://www.ietf.org/mail-archive/web/sidr/current/msg07164.html].

The draft authors are requested to submit a revised version of the draft =
including this response.   That would get the draft to publication.

In the initial message, the following text was suggested.  The draft =
authors may use this as they wish.

2. Permit but don't require newlines.  For example, change Section 2.1
  item #3 from:

    3)  a subjectPublicKeyInfo [RFC5280] in DER format [X.509],
        encoded in Base64 (see Section 4 of [RFC4648].

  to:

    3)  a subjectPublicKeyInfo [RFC5280] in DER format [X.509],
        encoded in Base64 (see Section 4 of [RFC4648]).  To avoid
        long lines, <CRLF> or <LF> line breaks MAY be inserted into
        the Base64 encoded string.

=97Sandy, speaking as co-chair

--Apple-Mail=_4D5EF2B5-6651-4902-AFBA-C834A8932782
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWErt8AAoJEHplpQeet0IZfswP/072tOmkhrQGdjIvSIufSoG5
J5jUkk1yzIPnmM5ROn2Lu44bz1gMMgvGYDqj57VMZvKaIBRcMRGdeTvr1Q4AFJmi
h7138fDALHgbW4qv8QzbGNzxZiVPqwr0OQn2KgWUmLfLRzUdiuWUJc4D9aw48hxg
MsWlDXbZgUuV7dvwrp4iWtWWhWs0KyIlU7+6R45wt+v9XQeBrkfDDNqjsNYwS7ak
S2BswzCjn5w/6oX/GxMo002XnOZDVq8KaKk3ikh1t3B+FgqHR9JjuNJDN1XLHYgw
S3OYTDo5jkZIzicxj4lRPnWeoaJGkGOUiQWqLAOwH/6QSHvM3uveqjgpdzaTUBne
0yV/LUOEXC9HxKX/w7DfTA8PuPtCuMX+S0i5zgPrKsiRH32Zs8n7O2b9NGTR5wtQ
072/d93HhyZFh9MmsJE5AT3jmhemIU+BooQZcgm9WkLN0FPyz80HpBfEAmHp309V
QJEbrgLl6eO02S0B+qQ33p3krYUJXXAMl2cdQFVMxfUwIOvf1uYIikH6J/yyGQci
2BKxdma1jknlil2ZL0j+V3dh/UYDIWxveUuHlIZaIHev+pASuJaO8V9LSGTvqAnW
0NSq7aVgqs33RpDRePWRvXu8qcQOVjOQMvNtUalLTMVp2EZfveV75zIym9sUBY8b
0ORTQEccWi/Y7PhGEmSj
=NhBs
-----END PGP SIGNATURE-----

--Apple-Mail=_4D5EF2B5-6651-4902-AFBA-C834A8932782--


From nobody Mon Oct  5 12:24:21 2015
Return-Path: <fcransto@cisco.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF8181B4B29 for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 12:24:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.081
X-Spam-Level: 
X-Spam-Status: No, score=-14.081 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_HTML_MOSTLY=0.428, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, TVD_SPACE_RATIO=0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gjqW3-H3LRwv for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 12:24:18 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0BB171B3451 for <sidr@ietf.org>; Mon,  5 Oct 2015 12:24:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2290; q=dns/txt; s=iport; t=1444073056; x=1445282656; h=from:to:subject:date:message-id:mime-version; bh=4DjW+0tMAUeEsZjXcX7VYXghEQIt/G6CRoGGIo2/f3w=; b=gAc1lB171o6sFqTGyGND3+UT0mR2DtOZ4TcFvSlJSwVBN6egF+5Cygrm wYFH9W4Lvf+8Pau46jcFVuoE12IlKImcPH/lOTSsoPGlnk09uWqNnbVfa V6Z++cq+Gg761l8J2Mvj7cFDxDhWBjK2c9TPFDG+GAFHEieacXYjrYzVT Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CDEQC4zRJW/49dJa1egXoFAVpNVHS3YoYtAQ2BWoY+gRQ4FAEBAQEBAQF/BwSEKxkUIT0BDHMBHwcBBBsVBIgNmWqkDQEBAQEGAQEBAQEBHIZzjj4FlXwBjQ+OdIx1AR8BAUKEAogqgQYBAQE
X-IronPort-AV: E=Sophos;i="5.17,640,1437436800";  d="scan'208,217";a="194811771"
Received: from rcdn-core-7.cisco.com ([173.37.93.143]) by alln-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 05 Oct 2015 19:24:15 +0000
Received: from XCH-RCD-010.cisco.com (xch-rcd-010.cisco.com [173.37.102.20]) by rcdn-core-7.cisco.com (8.14.5/8.14.5) with ESMTP id t95JOE2N001035 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <sidr@ietf.org>; Mon, 5 Oct 2015 19:24:14 GMT
Received: from xch-rcd-009.cisco.com (173.37.102.19) by XCH-RCD-010.cisco.com (173.37.102.20) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Mon, 5 Oct 2015 14:24:13 -0500
Received: from xch-rcd-009.cisco.com ([173.37.102.19]) by XCH-RCD-009.cisco.com ([173.37.102.19]) with mapi id 15.00.1104.000; Mon, 5 Oct 2015 14:24:13 -0500
From: "Frank Cranston (fcransto)" <fcransto@cisco.com>
To: "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: unsubscribe
Thread-Index: AdD/o2ZsR22fJ6rISeWxOu0nQXx4Tw==
Date: Mon, 5 Oct 2015 19:24:13 +0000
Message-ID: <7c9be94df2cf45edaac4dc9eea5ff124@XCH-RCD-009.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.82.217.107]
Content-Type: multipart/alternative; boundary="_000_7c9be94df2cf45edaac4dc9eea5ff124XCHRCD009ciscocom_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/_GszronofQCFM__UuJSl6gc2ARI>
Subject: [sidr] unsubscribe
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Oct 2015 19:24:20 -0000

--_000_7c9be94df2cf45edaac4dc9eea5ff124XCHRCD009ciscocom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

unsubscribe



--_000_7c9be94df2cf45edaac4dc9eea5ff124XCHRCD009ciscocom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">unsubscribe<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,sans-serif;color:#222222"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_7c9be94df2cf45edaac4dc9eea5ff124XCHRCD009ciscocom_--


From nobody Mon Oct  5 13:36:09 2015
Return-Path: <david@mandelberg.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A7D251B4FD4 for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 13:36:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level: 
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X2OWobhkQc2n for <sidr@ietfa.amsl.com>; Mon,  5 Oct 2015 13:36:06 -0700 (PDT)
Received: from nm16-vm6.access.bullet.mail.bf1.yahoo.com (nm16-vm6.access.bullet.mail.bf1.yahoo.com [216.109.115.53]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEB581B4FDE for <sidr@ietf.org>; Mon,  5 Oct 2015 13:36:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1444077365; bh=Ekg3hHfzKWdeiXIkGQfUXWie6lLXM4rDeyyH731Xx/0=; h=Date:From:To:Subject:In-Reply-To:References:From:Subject; b=J1dyp9AsUUk264jVCOD/KZAqaK/Voy6I5+Km9B1c4V9bHW3X7bv+oFY1NqRwX/2X1URYNWXoscLmy//CH8qlCGK/JEiZdnu75Py3uGWzndpYYoIRX0SqenwjbxFy4JLPDFkL4ICN0PY2iKEqwaA2G/VsvUHJSOujjDDE//pDX4XhJiQvB2c+20FWuSAuB+YVkJIFE3nHzg0u9wXbKeRgkkXsxgnSLIaxaGf9vrdT5yk92bbGWZKYESi+PIfP8IGUFulKIRNC+d2DpFauN5TJfaJ3/EEcd1Sfosz24Bt88l7Zw+SQMfm0m/3AXEGJ9GYBaMnIifp18mTq+kvkVxXxbg==
Received: from [66.196.81.162] by nm16.access.bullet.mail.bf1.yahoo.com with NNFMP; 05 Oct 2015 20:36:05 -0000
Received: from [98.138.104.99] by tm8.access.bullet.mail.bf1.yahoo.com with NNFMP; 05 Oct 2015 20:36:05 -0000
Received: from [127.0.0.1] by smtp119.sbc.mail.ne1.yahoo.com with NNFMP; 05 Oct 2015 20:36:04 -0000
X-Yahoo-Newman-Id: 966392.71261.bm@smtp119.sbc.mail.ne1.yahoo.com
X-Yahoo-Newman-Property: ymail-3
X-YMail-OSG: c3pijMAVM1m21SMWTyXGW2PfNPIkb6d_Z_rLgshHEJGh3gC gOGwbwSv591uMnRSwTJZqLKaK98pF2bQQcGFl1MhBVwYDl8Dz6ynb.Ara76G kRkW6YLcQGxBnjLWDbQPkDxcIYsLHSC4QKZ_sG9zp522JLDzwDG1Q.cJ8ivz EhT6G8QX_QsrByvfHTNG.GJnf9DvHZABtIsxbg.isrL5pTFVArkIodO.TDlj lP_ul2egzGDGAM7KJdx92E0rlfxZLtWxT28Ymc.n27QM3QRiS5xh97.HDH4V Ccl3bGp47ZTTz47wBSMfajBYJLMIXmCI0AzISmyGr4d1W6ecJl6_abHdV93i k4rJzIAcbxbxESy.7Vy4DDgGXJjJ1jCnrP.1A45l6EEP5gYAAVjOaM8SHuN5 NJGhCpeZ2Tj4THMXz4V1aPZH63VKvWxSNdHaXVWqwULLXdHv1Psi2N7JEe7M aHfbbN3OPDby47bSZvO.QWGQJivnCzn1V3Ie8fqcmkcvqBgVoLwOEuAmZY.I G8geqaUbjc22Zb4rS_C8btdPgowW0gRz3wrYaEQ--
X-Yahoo-SMTP: 4kJJK.qswBDPuwyc5wW.BPAQqNXdy5j09UNyeAS0pyOQ708-
Received: from secure.mandelberg.org (c-76-24-31-176.hsd1.ma.comcast.net [76.24.31.176]) by uriel.mandelberg.org (Postfix) with ESMTPSA id CFE7F1C6033 for <sidr@ietf.org>; Mon,  5 Oct 2015 16:36:03 -0400 (EDT)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Date: Mon, 05 Oct 2015 16:36:03 -0400
From: David Mandelberg <david@mandelberg.org>
To: <sidr@ietf.org>
In-Reply-To: <D008D28C-FC51-4AB7-9F73-C2435408AED6@ieca.com>
References: <555F436F.3080003@bbn.com> <2BF75857-6A5F-4260-B13B-0B9F6CE3FD98@ieca.com> <197E8AEA-D554-4DB4-885E-CFD55EF9E774@ripe.net> <m2wpx7pes6.wl%randy@psg.com> <55C4D7C8.4000401@bbn.com> <97B4FBD1-BCE6-4D37-BC0C-07A211347FBF@ieca.com> <55CA4901.4010007@bbn.com> <D008D28C-FC51-4AB7-9F73-C2435408AED6@ieca.com>
Message-ID: <c6af9ec70934494a2e0dd965c3fe753b@mail.mandelberg.org>
X-Sender: david@mandelberg.org
User-Agent: Roundcube Webmail/0.7.2
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/He0IRVvAFeb31EHozuFL8qwtwJk>
Subject: Re: [sidr] preventing SKI collisions
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Oct 2015 20:36:07 -0000

On 2015-09-16 10:38, Sean Turner wrote:
> Okay so I think we=E2=80=99re in agreement here that we don=E2=80=99t w=
ork on #3 now,
> but I=E2=80=99m also thinking that we should leave #1 and #2 alone for =
now.
> If we think a SHA-1 hash for the RPKI=E2=80=99s KIs are good enough now=
, then
> it sounds like it's also good enough for BGPsec.  It seems really odd
> that we do something different in BGPsec than what is done in the=20
> rest
> of the RPKI.  So, I=E2=80=99m proposing that:

I was about to argue that BGPsec's requirements for KIs are inherently=20
different than the rest of the RPKI's requirements for KIs, but then I=20
realized that I only thought that way because I'm implementing the=20
relying party side of things and not the BGPsec-enabled router side. So=20
I now agree with you that we can leave #1 and #2 alone for now, but only=20
if we do #4 (which I just made up):

4. Add text warning relying parties to detect malicious CAs that cause=20
too many KI collisions, and blacklist those CAs. Similarly, warn routers=20
and/or rpki-rtr caches to detect AS numbers with too many public keys=20
sharing the same SKI, and blacklist those AS numbers.

In both router certs and other RPKI certs, the KIs are used as an=20
optimization in the selection of a public key (BGPsec) or certificate=20
(RPKI) to use for BGPsec validation (BGPsec) or certificate path=20
validation (RPKI). If there are too many KI collisions, then this=20
optimization stops working well, and it's possible for a malicious CA to=20
DoS a router (router cert SKI collisions) or relying party (CA cert SKI=20
collisions). In either case, the DoS could be prevented by reducing the=20
probability of collisions (your #1-3), or by detecting and ignoring the=20
malicious CA (my #4).

By the way, I think your #1 might be easier than my #4, but either one=20
would prevent the issue Richard discovered.

--=20
David Eric Mandelberg / dseomn
http://david.mandelberg.org/


From nobody Tue Oct  6 05:30:24 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1E1D1B4041 for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 05:30:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UFzL70LDODKt for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 05:30:22 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E5EB1B403F for <sidr@ietf.org>; Tue,  6 Oct 2015 05:30:22 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 9B13028B0041; Tue,  6 Oct 2015 08:30:21 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 61B7F1F8035; Tue,  6 Oct 2015 08:30:21 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_3BA0288B-1CAA-4002-9F5F-23BFBB63D4C4"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <c6af9ec70934494a2e0dd965c3fe753b@mail.mandelberg.org>
Date: Tue, 6 Oct 2015 08:30:27 -0400
Message-Id: <99B857CD-DF02-4751-880A-E6D1283CF3BE@tislabs.com>
References: <555F436F.3080003@bbn.com> <2BF75857-6A5F-4260-B13B-0B9F6CE3FD98@ieca.com> <197E8AEA-D554-4DB4-885E-CFD55EF9E774@ripe.net> <m2wpx7pes6.wl%randy@psg.com> <55C4D7C8.4000401@bbn.com> <97B4FBD1-BCE6-4D37-BC0C-07A211347FBF@ieca.com> <55CA4901.4010007@bbn.com> <D008D28C-FC51-4AB7-9F73-C2435408AED6@ieca.com> <c6af9ec70934494a2e0dd965c3fe753b@mail.mandelberg.org>
To: David Mandelberg <david@mandelberg.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/9vCoSpFkUW49jxe9oCy55kzivSM>
Cc: sidr@ietf.org, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] preventing SKI collisions
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Oct 2015 12:30:24 -0000

--Apple-Mail=_3BA0288B-1CAA-4002-9F5F-23BFBB63D4C4
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

Speaking as regular ol=92 member only.

On Oct 5, 2015, at 4:36 PM, David Mandelberg <david@mandelberg.org> =
wrote:

> On 2015-09-16 10:38, Sean Turner wrote:
>> Okay so I think we=92re in agreement here that we don=92t work on #3 =
now,
>> but I=92m also thinking that we should leave #1 and #2 alone for now.
>> If we think a SHA-1 hash for the RPKI=92s KIs are good enough now, =
then
>> it sounds like it's also good enough for BGPsec.  It seems really odd
>> that we do something different in BGPsec than what is done in the =
rest
>> of the RPKI.  So, I=92m proposing that:
>=20
> I was about to argue that BGPsec's requirements for KIs are inherently =
different than the rest of the RPKI's requirements for KIs, but then I =
realized that I only thought that way because I'm implementing the =
relying party side of things and not the BGPsec-enabled router side. So =
I now agree with you that we can leave #1 and #2 alone for now, but only =
if we do #4 (which I just made up):
>=20
> 4. Add text warning relying parties to detect malicious CAs that cause =
too many KI collisions, and blacklist those CAs. Similarly, warn routers =
and/or rpki-rtr caches to detect AS numbers with too many public keys =
sharing the same SKI, and blacklist those AS numbers.

I=92m ok with =93warn=94, but =93blacklist=94 is a bit strong for me.  =
If you mean stop using that CA, i.e. remove all objects produced by that =
CA, then the whole tree under that CA would fall off the planet.  I =
think that=92s a potentially large cone of consequence and I believe it =
should be undertaken by brains, not code.

I=92d prefer a warning in the security considerations section and a =
recommendation to alert the operator.

=97Sandy, speaking as just a regular ol=92 member

--Apple-Mail=_3BA0288B-1CAA-4002-9F5F-23BFBB63D4C4
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWE77jAAoJEHplpQeet0IZpWkP/369fKJ7DybR6G6EpLei7ATO
svzNG5E+lo0ZPqVhbPnWe4mwre13apsrHDHzOrH/TGRyNe6TJDvUyPfILtLVo6X8
NgsAIOq3HYydCcVM+zEujGwXBg6PSAOzi22yWy6qtn4FUReD19m9ge4Uk7W5Ay3V
UxdQxBRWBdAi0cjcWqlhg4TONZW/DRak7wZS+sps5HxD/pFXeBAFKcMec1E4BQNZ
AxnzfAMIjMv4Ji5hwbMtDb1kl29zWyaLJrhJCXcHADEq3t8KGDXwFmcS6NhxjoX3
9VIpNKg4vBPyujpD/u/6yqX9r9bex+qx9FYQiOWfyj7UAkHmP+lnzkcnSuJ/RIYw
t8C25LTol1kx9aKg+lrsaBcTwuNSP5sSQV5pl9Oi2l6um3NABbEDOOiejENKswGi
kX4D0oYcFCcdM9wQaKawCk+i4Mw9KB5NHc1X6uoMZDvyHAEBoxWUYQts+b9jtgNl
MhoB8G6mwsml1TmHG6etb7H8VuoeP5MZuJUA7qIXRKbwdopm73DlkAl12Nxga5el
hRnEGNs5QTAMoXPDazwcJJL3aBdA6yHzTD4FfoXuLwLvByw8J++5g3C24kqE/wY5
jD9eGKilnFsntDKpSLyQGkrc3loSEmlXEjaX2Ho1a3k8/yNkdJtgqxr7ektRFPo1
Z3wh3NGSni3L83UPvD9h
=aeWf
-----END PGP SIGNATURE-----

--Apple-Mail=_3BA0288B-1CAA-4002-9F5F-23BFBB63D4C4--


From nobody Tue Oct  6 07:35:31 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 43BCA1B4077; Tue,  6 Oct 2015 07:35:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mapO8ax9VXTF; Tue,  6 Oct 2015 07:35:29 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 591E71B4089; Tue,  6 Oct 2015 07:35:26 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.4.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151006143526.10775.43421.idtracker@ietfa.amsl.com>
Date: Tue, 06 Oct 2015 07:35:26 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/RBRENbg2SQsyL9EBWqZ7jzSwQpE>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rpki-rtr-rfc6810-bis-06.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Oct 2015 14:35:30 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : The Resource Public Key Infrastructure (RPKI) to Router Protocol
        Authors         : Randy Bush
                          Rob Austein
	Filename        : draft-ietf-sidr-rpki-rtr-rfc6810-bis-06.txt
	Pages           : 33
	Date            : 2015-10-06

Abstract:
   In order to verifiably validate the origin Autonomous Systems and
   Autonomous System Paths of BGP announcements, routers need a simple
   but reliable mechanism to receive Resource Public Key Infrastructure
   (RFC 6480) prefix origin data and router keys from a trusted cache.
   This document describes a protocol to deliver validated prefix origin
   data and router keys to routers.

   This document describes version 1 of the rpki-rtr protocol.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-rtr-rfc6810-bis/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rpki-rtr-rfc6810-bis-06

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpki-rtr-rfc6810-bis-06


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Oct  6 07:39:45 2015
Return-Path: <sra@hactrn.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 38E281B4092 for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 07:39:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EIxdbSWYfu8I for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 07:39:43 -0700 (PDT)
Received: from adrilankha.hactrn.net (adrilankha.hactrn.net [147.28.0.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A88D1B4091 for <sidr@ietf.org>; Tue,  6 Oct 2015 07:39:43 -0700 (PDT)
Received: from minas-ithil.hactrn.net (c-24-34-34-101.hsd1.ma.comcast.net [24.34.34.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "nargothrond.hactrn.net", Issuer "Grunchweather Associates" (verified OK)) by adrilankha.hactrn.net (Postfix) with ESMTPS id 21D843982A for <sidr@ietf.org>; Tue,  6 Oct 2015 14:39:36 +0000 (UTC)
Received: from minas-ithil.hactrn.net (localhost [IPv6:::1]) by minas-ithil.hactrn.net (Postfix) with ESMTP id 16C2F1C2CC4C for <sidr@ietf.org>; Tue,  6 Oct 2015 10:38:51 -0400 (EDT)
Date: Tue, 06 Oct 2015 10:38:51 -0400
From: Rob Austein <sra@hactrn.net>
To: sidr@ietf.org
In-Reply-To: <20151006143526.10775.43421.idtracker@ietfa.amsl.com>
References: <20151006143526.10775.43421.idtracker@ietfa.amsl.com>
User-Agent: Wanderlust/2.15.5 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset=US-ASCII
Message-Id: <20151006143851.16C2F1C2CC4C@minas-ithil.hactrn.net>
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/tX3UTmRZIAsZkMXyqT14b9iUgNs>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-rtr-rfc6810-bis-06.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Oct 2015 14:39:44 -0000

Updated per instructions from WG chair:

"updates RFC 6810" => "obsoletes RFC 6810"

and brief summary of changes since RFC 6810.


From nobody Tue Oct  6 17:50:48 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A4C51A8785 for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 17:50:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xgi1yDng2qHD for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 17:50:45 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 33BB71A877F for <sidr@ietf.org>; Tue,  6 Oct 2015 17:50:45 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 8847E28B0041; Tue,  6 Oct 2015 20:50:44 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 4339A1F8035; Tue,  6 Oct 2015 20:50:42 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_C0F5731B-7964-4CC5-8DCE-58AB31CC992D"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <20151006143851.16C2F1C2CC4C@minas-ithil.hactrn.net>
Date: Tue, 6 Oct 2015 20:50:32 -0400
Message-Id: <ABEC23B2-FF01-46F7-8AC5-F0D5F807FDE9@tislabs.com>
References: <20151006143526.10775.43421.idtracker@ietfa.amsl.com> <20151006143851.16C2F1C2CC4C@minas-ithil.hactrn.net>
To: Rob Austein <sra@hactrn.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/c5NPfiU2Ockra8SQUrGxt4_Buko>
Cc: sidr@ietf.org, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-rtr-rfc6810-bis-06.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 00:50:46 -0000

--Apple-Mail=_C0F5731B-7964-4CC5-8DCE-58AB31CC992D
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


On Oct 6, 2015, at 10:38 AM, Rob Austein <sra@hactrn.net> wrote:

> Updated per instructions from WG chair:

True.  Newest document shepherd writeup asks for this info.

=97Sandy, speaking as wg co-chair

>=20
> "updates RFC 6810" =3D> "obsoletes RFC 6810"
>=20
> and brief summary of changes since RFC 6810.
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


--Apple-Mail=_C0F5731B-7964-4CC5-8DCE-58AB31CC992D
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFGxgAAoJEHplpQeet0IZPv4P/1ncFHOdMSvqoPRc8f74r8zf
5dy2XKhvnrPf31Rn/b7q4Z1JcwVhquECoaKRFV1FinxZv/TlkoVbIv0bjwSz42P2
PdZBYlTgfqm/IlKDIX3jf1Zka59+sW5NDs4GEIESt+elmuF+LNmDEFK7N658zgCf
xFmcOBRq/7muHZIDSgLfr5Un+UKQgdNmdjwmFEYZko/navmz8BAxzxxDVBOqSyzh
jARkUjWIWCSv9b7huGv122Is+jsyU0wwYclWW5Pm2cktBqFDdpOk7cMem3OOSn/t
A2xjPSsMdEW0wxR927vFzhMHy9kvya/zxhBpAuB//oanC8Q+OUcfbGU3hgEuNWha
vv3LrrCZK+JJGbm7Kr7KhO7f2/TdeYpsbjjke89fWqY0PFhf0ULa1wi225pdxEeJ
hx3QJb+zqHksneO9fJcMW1B6zqEMJO0uk7GvwvQkE/PCBh3ulHv6O+lJZ2ucl0mg
tzaEZG517e5G/L+NVbuBxwI7Pjz2I45dWc/bNn9NBEOIPJsM7lpdKdO44B1xpqrP
YzIrFb9HSMAz9/NPaiYNOlMdybrPxKWSRHqb7RjCULcDpUmG1FJrVxTzRi3w7aWi
9fto2s1IqWE5z8QLVjqzXKundQfNxwr9gdNLWEViopXaBTUeaxbO4P45+VXkftFG
+itZ/WJGZ4pfKfNaiRnF
=ScaT
-----END PGP SIGNATURE-----

--Apple-Mail=_C0F5731B-7964-4CC5-8DCE-58AB31CC992D--


From nobody Tue Oct  6 18:31:53 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E91DC1B4282 for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 18:31:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4Z40ZD_yg_Df for <sidr@ietfa.amsl.com>; Tue,  6 Oct 2015 18:31:50 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A16991B4280 for <sidr@ietf.org>; Tue,  6 Oct 2015 18:31:50 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id E061C28B0041 for <sidr@ietf.org>; Tue,  6 Oct 2015 21:31:49 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 5C5E01F8035; Tue,  6 Oct 2015 21:31:49 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_CAB88850-B181-4BD5-9CB8-BC4E2AB54E75"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <m2613ca3kf.wl%randy@psg.com>
Date: Tue, 6 Oct 2015 21:31:40 -0400
Message-Id: <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>
References: <SN1PR09MB079938B1A44171328C0B16CA846A0@SN1PR09MB0799.namprd09.prod.outlook.com> <D20B8CAC.45839%dougm@nist.gov> <CY1PR09MB079376AC097FDDB73531814184690@CY1PR09MB0793.namprd09.prod.outlook.com> <m2613ca3kf.wl%randy@psg.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Pnegayf6AVfiBOBJ1YTnfMIriYg>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] draft-ietf-sidr-bgpsec-protocol-13's security guarantees
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 01:31:52 -0000

--Apple-Mail=_CAB88850-B181-4BD5-9CB8-BC4E2AB54E75
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


This conversation seems to have come to a close.

The wg chairs see wg consensus as follows:

The problem is real enough to merit a protocol change.

The change is to cover more raw info in the signatures, rather than =
signature chaining only, along the lines of
http://www.ietf.org/mail-archive/web/sidr/current/msg07258.html
(see also the new archiving tool =
https://mailarchive.ietf.org/arch/msg/sidr/sXUj7lgieri0Wrv5PK5u7PfLtxc).

In addition, maintaining ordering was also noted as important to some
http://www.ietf.org/mail-archive/web/sidr/current/msg07261.html
http://www.ietf.org/mail-archive/web/sidr/current/msg07270.html
http://www.ietf.org/mail-archive/web/sidr/current/msg07271.html


The authors of draft-ietf-sidr-bgpsec-protocol-13 are requested to =
submit a revised version of the draft.

The changes are significant enough that the revised draft will go =
through a wglc, focussed on the changes for this issue, so shorter than =
normal.

=97Sandy, speaking as one of the wg co-chairs

--Apple-Mail=_CAB88850-B181-4BD5-9CB8-BC4E2AB54E75
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFHYDAAoJEHplpQeet0IZRn4QAMeecX/5Ac4DB07rAJyNcA1w
sMap+8Gc7z8l2/WIHsywEHBRxBMfV2bBH+VxGBLZ1Z43jc10lQ7C6ImvuqRTtD/X
canIX8Oh4QKn35t1XKq6ody5hHRUIu12Bmh+Begv1ddIkTMhvUEgM0F+B9HXlnM8
zBhrokjXX+cOEzaK+lV1af/+Vf35f+djSxK1aK1Hs78rJ1Rv/TufqRQWQ6dO623m
1E4wtTKLT0hkYhP3eQCxuWG9FNSs8DBEUeyPBz0EV6oER/ivHaVliZeZLGWMYEO/
N/4+TnqLL/MvkjnjSseJGe1vAsEba/oNDi0iX8c+VvJfN5bpBbcnxZztgh853Q1e
gLecEHupiEgH/ow0IFAo1U8CUBB9AnxOX5Gb3ClJiZibP18Pfrw/kzF5oYadmep7
sgXlf3aYwLw1i8VvWH/pWIg91TpZUEqPYXu6U/k+C3oVFvaEEvrYVt2X9oWGkoHP
UoRaHJ1PC6SOA7ifh4OVu2UCkrQ6/1gsZDBWZAjeLCry20rgmKu2yWGj1fEOTKx7
FJgw2LwD2eC4M1tfR5OsiHwzb2FNJJIbIqaMZtQMChbSwQR+vxZq9HYJ0gJ4RCQ9
0Jj1Ie/3htTrj09Kr2xk009WiaSS0RJqO1fnDqYMGgYswL1mK9pkhNxFpD4hEFgt
yUSVNsCrCLPYPS3D+LgP
=1cYd
-----END PGP SIGNATURE-----

--Apple-Mail=_CAB88850-B181-4BD5-9CB8-BC4E2AB54E75--


From nobody Wed Oct  7 06:23:11 2015
Return-Path: <sean@sn3rd.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 807B01A6F59 for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 06:22:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SMl9XfRB8d6f for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 06:22:49 -0700 (PDT)
Received: from mail-qg0-x22f.google.com (mail-qg0-x22f.google.com [IPv6:2607:f8b0:400d:c04::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DAAF11A6F42 for <sidr@ietf.org>; Wed,  7 Oct 2015 06:22:48 -0700 (PDT)
Received: by qgez77 with SMTP id z77so14833251qge.1 for <sidr@ietf.org>; Wed, 07 Oct 2015 06:22:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=content-type:mime-version:subject:from:in-reply-to:date :content-transfer-encoding:message-id:references:to; bh=oIBGgHJX11yfAVgUVTXP5KyJwvS5jn1LRwBgtngbep4=; b=HjXKWIGjen394LLzdS8nne//F+eDVpQzRyAblQIIwmYHhpHTZ0tg/iY1Ct/snSzQxN 6BTXscYOYDjDOdOSwGRWLSsmui07FwTZeh0sIjmB55LJfeKI/7zoZ1B36KpiuUr5IRhY wsEYDsTxANvSi2ZgZ2Ho9iWB7zSuFnUU9lb/M=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:content-transfer-encoding:message-id:references:to; bh=oIBGgHJX11yfAVgUVTXP5KyJwvS5jn1LRwBgtngbep4=; b=d5wCgjVK3VSYTWiwwwUue+bXFUwrXLdGvmnKuGZ6ovjjSVnreba8IKeKkHTOJCsGOv 6mfGmGcRTC97DlimbN+t626o96F9I926LTniA9f4T0TUCZr9KlnR3BEYKsS4M8Pr6yKd Z04v8U39MtKE3+lilDtjoRw1vm/RysDXDP5uTV1Fod24vfGFjL0H7v4k54b1uM1WWO75 nSFlDsZudbUF1zKUJvPlxjTCWapNgOQgOPez7+QvXcwLJwUX8BQNFUSC32JNvpiVMeND eUOO2m/AjOmhk7r9lrehmevPeLeac7mApAoEg6u62W2BMkUMPnL/Nh3BK/ipOAfwzIcj MaZQ==
X-Gm-Message-State: ALoCoQlYIjXBrRjKwakZQQOljUgCGoKBFI+ojlM0wxwx6rLLLstsIlI75Lyq71YTQR7itV8+L4qX
X-Received: by 10.140.33.225 with SMTP id j88mr1382562qgj.30.1444224168021; Wed, 07 Oct 2015 06:22:48 -0700 (PDT)
Received: from [5.5.33.66] (vpn.snozzages.com. [204.42.252.17]) by smtp.gmail.com with ESMTPSA id 200sm16176438qhh.26.2015.10.07.06.22.46 for <sidr@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 07 Oct 2015 06:22:47 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <99B857CD-DF02-4751-880A-E6D1283CF3BE@tislabs.com>
Date: Wed, 7 Oct 2015 09:22:40 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <C6707353-65E9-49B2-8D50-F317127EA7F8@sn3rd.com>
References: <555F436F.3080003@bbn.com> <2BF75857-6A5F-4260-B13B-0B9F6CE3FD98@ieca.com> <197E8AEA-D554-4DB4-885E-CFD55EF9E774@ripe.net> <m2wpx7pes6.wl%randy@psg.com> <55C4D7C8.4000401@bbn.com> <97B4FBD1-BCE6-4D37-BC0C-07A211347FBF@ieca.com> <55CA4901.4010007@bbn.com> <D008D28C-FC51-4AB7-9F73-C2435408AED6@ieca.com> <c6af9ec70934494a2e0dd965c3fe753b@mail.mandelberg.org> <99B857CD-DF02-4751-880A-E6D1283CF3BE@tislabs.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/1OjmvHZrZqh6sykWg6pEjMg27Kc>
Subject: Re: [sidr] preventing SKI collisions
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 13:22:50 -0000

On Oct 06, 2015, at 08:30, Sandra Murphy <sandy@tislabs.com> wrote:

> Speaking as regular ol=92 member only.
>=20
> On Oct 5, 2015, at 4:36 PM, David Mandelberg <david@mandelberg.org> =
wrote:
>=20
>> On 2015-09-16 10:38, Sean Turner wrote:
>>> Okay so I think we=92re in agreement here that we don=92t work on #3 =
now,
>>> but I=92m also thinking that we should leave #1 and #2 alone for =
now.
>>> If we think a SHA-1 hash for the RPKI=92s KIs are good enough now, =
then
>>> it sounds like it's also good enough for BGPsec.  It seems really =
odd
>>> that we do something different in BGPsec than what is done in the =
rest
>>> of the RPKI.  So, I=92m proposing that:
>>=20
>> I was about to argue that BGPsec's requirements for KIs are =
inherently different than the rest of the RPKI's requirements for KIs, =
but then I realized that I only thought that way because I'm =
implementing the relying party side of things and not the BGPsec-enabled =
router side. So I now agree with you that we can leave #1 and #2 alone =
for now, but only if we do #4 (which I just made up):
>>=20
>> 4. Add text warning relying parties to detect malicious CAs that =
cause too many KI collisions, and blacklist those CAs. Similarly, warn =
routers and/or rpki-rtr caches to detect AS numbers with too many public =
keys sharing the same SKI, and blacklist those AS numbers.
>=20
> I=92m ok with =93warn=94, but =93blacklist=94 is a bit strong for me.  =
If you mean stop using that CA, i.e. remove all objects produced by that =
CA, then the whole tree under that CA would fall off the planet.  I =
think that=92s a potentially large cone of consequence and I believe it =
should be undertaken by brains, not code.
>=20
> I=92d prefer a warning in the security considerations section and a =
recommendation to alert the operator.

Yep let=92s just put a warning in the security considerations and alert =
the operator.

spt=


From nobody Wed Oct  7 06:23:30 2015
Return-Path: <randy@psg.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D4DB1A6F42 for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 06:23:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NAeZ9Kx-I9Nk for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 06:23:07 -0700 (PDT)
Received: from ran.psg.com (ran.psg.com [IPv6:2001:418:8006::18]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 81D7B1A6F59 for <sidr@ietf.org>; Wed,  7 Oct 2015 06:23:07 -0700 (PDT)
Received: from localhost ([127.0.0.1] helo=ryuu.psg.com) by ran.psg.com with esmtp (Exim 4.82) (envelope-from <randy@psg.com>) id 1ZjogT-0002lD-J8; Wed, 07 Oct 2015 13:23:05 +0000
Date: Wed, 07 Oct 2015 09:23:06 -0400
Message-ID: <m2a8rudd8l.wl%randy@psg.com>
From: Randy Bush <randy@psg.com>
To: Sandra Murphy <sandy@tislabs.com>
References: <99B857CD-DF02-4751-880A-E6D1283CF3BE@tislabs.com> <B3292CA9-99E4-4191-A057-A150BBC23CA0@sn3rd.com>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/2nnAdXrimCOBv7lSqlRUbQSb7GE>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] preventing SKI collisions
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 13:23:08 -0000

> I'd prefer a warning in the security considerations section and a
> recommendation to alert the operator.

please.  and put this to bed already.

randy


From nobody Wed Oct  7 08:07:05 2015
Return-Path: <mlepinski.ietf@gmail.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B26751A0171 for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 08:06:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M_3pf0lOFUVq for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 08:06:41 -0700 (PDT)
Received: from mail-ob0-x22c.google.com (mail-ob0-x22c.google.com [IPv6:2607:f8b0:4003:c01::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF3BC1A9301 for <sidr@ietf.org>; Wed,  7 Oct 2015 08:06:40 -0700 (PDT)
Received: by obbda8 with SMTP id da8so15460467obb.1 for <sidr@ietf.org>; Wed, 07 Oct 2015 08:06:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=9g4qkN7R2bVWtnXICL6b4tcmMgAaYXITgj513eLynI4=; b=Kj1RxBuOdj/QcyfOwkXHO89QTexfiarPPrHdewD9Q6VdanLAlXhUP583Zo+SF31bVe SPDwLnDYiZ0MpxxkcJLFGZX0lbnNl92mIjY6YGSUzGJTSica4nUxnLeTUbNKnRm4ysUu hIlw85pQDbilRjGB6R9gb4pJoQvZFE4P39Dev+9jUA2OWKN/EfhzphmyJPBH0gs0T8P9 36zs5ISJCJAAgbjHjl/Bw/KTlCRS7Q65ZKkTk1r/duiPI2PbZMoAbzIMtOs1Tnc+LVOc Kkov1kYCxsKDZw5wiSYTmv7vBeWnIrplgQiO5ZrW3motJnehUal/NIa/cIVgkH7C8fMC lVBA==
MIME-Version: 1.0
X-Received: by 10.182.53.229 with SMTP id e5mr1000564obp.68.1444230400135; Wed, 07 Oct 2015 08:06:40 -0700 (PDT)
Received: by 10.202.198.22 with HTTP; Wed, 7 Oct 2015 08:06:40 -0700 (PDT)
In-Reply-To: <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>
References: <SN1PR09MB079938B1A44171328C0B16CA846A0@SN1PR09MB0799.namprd09.prod.outlook.com> <D20B8CAC.45839%dougm@nist.gov> <CY1PR09MB079376AC097FDDB73531814184690@CY1PR09MB0793.namprd09.prod.outlook.com> <m2613ca3kf.wl%randy@psg.com> <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>
Date: Wed, 7 Oct 2015 11:06:40 -0400
Message-ID: <CANTg3aCvdCKY+BfJ9G0dtJpQth=ckud=pmYyY4rKJh_V2A+7fQ@mail.gmail.com>
From: Matthew Lepinski <mlepinski.ietf@gmail.com>
To: Sandra Murphy <sandy@tislabs.com>
Content-Type: multipart/alternative; boundary=089e0111d7a0f9568b05218517fa
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/kegL5O-0SgyO72R5JskHK4l0aE8>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] draft-ietf-sidr-bgpsec-protocol-13's security guarantees
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 15:06:43 -0000

--089e0111d7a0f9568b05218517fa
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Thanks to David for identifying this problem initially and to everyone else
who contributed to this discussion.

I am happy to update the document to reflect the working group consensus.
My goal is to get a revised version of the document to the working group
sometime late next week (e.g. Oct 17).

- Matt Lepinski

On Tue, Oct 6, 2015 at 9:31 PM, Sandra Murphy <sandy@tislabs.com> wrote:

>
> This conversation seems to have come to a close.
>
> The wg chairs see wg consensus as follows:
>
> The problem is real enough to merit a protocol change.
>
> The change is to cover more raw info in the signatures, rather than
> signature chaining only, along the lines of
> http://www.ietf.org/mail-archive/web/sidr/current/msg07258.html
> (see also the new archiving tool
> https://mailarchive.ietf.org/arch/msg/sidr/sXUj7lgieri0Wrv5PK5u7PfLtxc).
>
> In addition, maintaining ordering was also noted as important to some
> http://www.ietf.org/mail-archive/web/sidr/current/msg07261.html
> http://www.ietf.org/mail-archive/web/sidr/current/msg07270.html
> http://www.ietf.org/mail-archive/web/sidr/current/msg07271.html
>
>
> The authors of draft-ietf-sidr-bgpsec-protocol-13 are requested to submit
> a revised version of the draft.
>
> The changes are significant enough that the revised draft will go through
> a wglc, focussed on the changes for this issue, so shorter than normal.
>
> =E2=80=94Sandy, speaking as one of the wg co-chairs
>
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr
>
>

--089e0111d7a0f9568b05218517fa
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thanks to David for identifying this problem initially and=
 to everyone else who contributed to this discussion.<div><br></div><div>I =
am happy to update the document to reflect the working group consensus. My =
goal is to get a revised version of the document to the working group somet=
ime late next week (e.g. Oct 17).</div><div><br></div><div>- Matt Lepinski<=
/div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Tue=
, Oct 6, 2015 at 9:31 PM, Sandra Murphy <span dir=3D"ltr">&lt;<a href=3D"ma=
ilto:sandy@tislabs.com" target=3D"_blank">sandy@tislabs.com</a>&gt;</span> =
wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><br>
This conversation seems to have come to a close.<br>
<br>
The wg chairs see wg consensus as follows:<br>
<br>
The problem is real enough to merit a protocol change.<br>
<br>
The change is to cover more raw info in the signatures, rather than signatu=
re chaining only, along the lines of<br>
<a href=3D"http://www.ietf.org/mail-archive/web/sidr/current/msg07258.html"=
 rel=3D"noreferrer" target=3D"_blank">http://www.ietf.org/mail-archive/web/=
sidr/current/msg07258.html</a><br>
(see also the new archiving tool <a href=3D"https://mailarchive.ietf.org/ar=
ch/msg/sidr/sXUj7lgieri0Wrv5PK5u7PfLtxc" rel=3D"noreferrer" target=3D"_blan=
k">https://mailarchive.ietf.org/arch/msg/sidr/sXUj7lgieri0Wrv5PK5u7PfLtxc</=
a>).<br>
<br>
In addition, maintaining ordering was also noted as important to some<br>
<a href=3D"http://www.ietf.org/mail-archive/web/sidr/current/msg07261.html"=
 rel=3D"noreferrer" target=3D"_blank">http://www.ietf.org/mail-archive/web/=
sidr/current/msg07261.html</a><br>
<a href=3D"http://www.ietf.org/mail-archive/web/sidr/current/msg07270.html"=
 rel=3D"noreferrer" target=3D"_blank">http://www.ietf.org/mail-archive/web/=
sidr/current/msg07270.html</a><br>
<a href=3D"http://www.ietf.org/mail-archive/web/sidr/current/msg07271.html"=
 rel=3D"noreferrer" target=3D"_blank">http://www.ietf.org/mail-archive/web/=
sidr/current/msg07271.html</a><br>
<br>
<br>
The authors of draft-ietf-sidr-bgpsec-protocol-13 are requested to submit a=
 revised version of the draft.<br>
<br>
The changes are significant enough that the revised draft will go through a=
 wglc, focussed on the changes for this issue, so shorter than normal.<br>
<br>
=E2=80=94Sandy, speaking as one of the wg co-chairs<br>
<br>_______________________________________________<br>
sidr mailing list<br>
<a href=3D"mailto:sidr@ietf.org">sidr@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br>
<br></blockquote></div><br></div>

--089e0111d7a0f9568b05218517fa--


From nobody Wed Oct  7 08:20:45 2015
Return-Path: <morrowc@ops-netman.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 28CEC1A92FB; Wed,  7 Oct 2015 08:20:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.221
X-Spam-Level: 
X-Spam-Status: No, score=0.221 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_MISMATCH_NET=0.611, HOST_MISMATCH_COM=0.311, RCVD_IN_DNSWL_LOW=-0.7] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3kJRYImVi8Ee; Wed,  7 Oct 2015 08:20:24 -0700 (PDT)
Received: from uu.ops-netman.net (maild1.aptea.com [206.112.93.193]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D048D1AC3C4; Wed,  7 Oct 2015 08:20:21 -0700 (PDT)
Received: from mail.ops-netman.net (unknown [208.76.12.119]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by uu.ops-netman.net (Postfix) with ESMTPS id 74AFBC009D; Wed,  7 Oct 2015 15:20:20 +0000 (UTC)
Received: from morrowc-glaptop4.roam.corp.google.com.ops-netman.net (dhcp-220-102.meetings.nanog.org [199.187.220.102]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mail.ops-netman.net (Postfix) with ESMTPSA id E7987880FD3; Wed,  7 Oct 2015 15:20:18 +0000 (UTC)
Date: Wed, 07 Oct 2015 11:20:17 -0400
Message-ID: <yj9owpuyaeoe.wl%morrowc@ops-netman.net>
From: Chris Morrow <morrowc@ops-netman.net>
To: sidr-chairs@ietf.org,sidr@ietf.org
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/24.3 Mule/6.0 (HANACHIRUSATO)
Organization: Operations Network Management, Ltd.
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/pePr2qmbOYFv6yCGM6_AGV4sWOo>
Subject: [sidr] Agenda Items Request - Yokohama
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 15:20:25 -0000

Howdy folks,
We'll be in Yokohama in meeting rooms... so we should have agenda items.
Speak up now pls for meeting topics!

-chris
co-chair


From nobody Wed Oct  7 08:23:52 2015
Return-Path: <morrowc@ops-netman.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E13921A924A; Wed,  7 Oct 2015 08:23:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jPqTLv52YAOO; Wed,  7 Oct 2015 08:23:38 -0700 (PDT)
Received: from uu.ops-netman.net (morrowc-1-pt.tunnel.tserv13.ash1.ipv6.he.net [IPv6:2001:470:7:36e::2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAB281AC3E8; Wed,  7 Oct 2015 08:23:38 -0700 (PDT)
Received: from mail.ops-netman.net (unknown [208.76.12.119]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by uu.ops-netman.net (Postfix) with ESMTPS id 06BC5C038B; Wed,  7 Oct 2015 15:23:38 +0000 (UTC)
Received: from morrowc-glaptop4.roam.corp.google.com.ops-netman.net (dhcp-220-102.meetings.nanog.org [199.187.220.102]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mail.ops-netman.net (Postfix) with ESMTPSA id B3300880E75; Wed,  7 Oct 2015 15:23:37 +0000 (UTC)
Date: Wed, 07 Oct 2015 11:23:37 -0400
Message-ID: <yj9ovbaiaeiu.wl%morrowc@ops-netman.net>
From: Chris Morrow <morrowc@ops-netman.net>
To: sidr-chairs@ietf.org,sidr@ietf.org
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/24.3 Mule/6.0 (HANACHIRUSATO)
Organization: Operations Network Management, Ltd.
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/kvIiR2nsdwJS-0fcCLwKBfkC_Aw>
Subject: [sidr] WG Adoption: draft-dseomn-sidr-slurm
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 15:23:40 -0000

Howdy WG folks!
the adoption call for:
  draft-dseomn-sidr-slurm

is long since past, but I think despite the mild reply set, taking the
work on seems acceptable to the WG, let's re-issue a re-named draft
and discuss more on the list.

Authors pls follow the 'publish new draft' process, thanks!

-Chris


From nobody Wed Oct  7 08:32:29 2015
Return-Path: <morrowc@ops-netman.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81D9C1AC40C; Wed,  7 Oct 2015 08:32:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ecc8wbOGbIPN; Wed,  7 Oct 2015 08:32:08 -0700 (PDT)
Received: from uu.ops-netman.net (morrowc-1-pt.tunnel.tserv13.ash1.ipv6.he.net [IPv6:2001:470:7:36e::2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB1961AC40B; Wed,  7 Oct 2015 08:32:08 -0700 (PDT)
Received: from mail.ops-netman.net (unknown [208.76.12.119]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by uu.ops-netman.net (Postfix) with ESMTPS id 00EC3C086B; Wed,  7 Oct 2015 15:32:08 +0000 (UTC)
Received: from morrowc-glaptop4.roam.corp.google.com.ops-netman.net (dhcp-220-102.meetings.nanog.org [199.187.220.102]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mail.ops-netman.net (Postfix) with ESMTPSA id B3B78881144; Wed,  7 Oct 2015 15:32:07 +0000 (UTC)
Date: Wed, 07 Oct 2015 11:32:06 -0400
Message-ID: <yj9osi5mae4p.wl%morrowc@ops-netman.net>
From: Chris Morrow <morrowc@ops-netman.net>
To: sidr-chairs@ietf.org,sidr@ietf.org
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/24.3 Mule/6.0 (HANACHIRUSATO)
Organization: Operations Network Management, Ltd.
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/D40t4uarCx-JH-QOHjj4XsGvSrE>
Subject: [sidr] WGLC:  draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 15:32:10 -0000

Howdy WG folks,
Please consider this your warning/notice that the WGLC has been started for:

  draft-ietf-sidr-bgpsec-overview

Abstract:
  "This document provides an overview of a security extension to the
   Border Gateway Protocol (BGP) referred to as BGPsec.  BGPsec improves
   security for BGP routing."

Please give this a read, send comments if there are any, and let us
know if this is prepared for publication request.

Thanks!

-chris
co-chair


From nobody Wed Oct  7 14:24:09 2015
Return-Path: <sean@sn3rd.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 716061B3103 for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 14:24:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yEf5z5HVWzVk for <sidr@ietfa.amsl.com>; Wed,  7 Oct 2015 14:24:05 -0700 (PDT)
Received: from mail-qg0-x229.google.com (mail-qg0-x229.google.com [IPv6:2607:f8b0:400d:c04::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 732081B30FC for <sidr@ietf.org>; Wed,  7 Oct 2015 14:24:05 -0700 (PDT)
Received: by qgt47 with SMTP id 47so26487635qgt.2 for <sidr@ietf.org>; Wed, 07 Oct 2015 14:24:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=MaB0XXdvU+WuX6iX4LKgXA7ox/SrFT7eN7zK6Eu78Ts=; b=XJLp9QItjOPgkmg/6KS24q8+oeWRY3GajfI3w4RIg0mJZ6qEJLckRjB9UMOtwq7nVf fy29Z6GvxTE/h2hgIXqVgwJpY8hWXXR9CdlUOy+pHZeCPu6CDKf31mH1bsoc838507vK mpXKxfYQzT1XTlel3sy9S8d2JV72ToB1bAc08=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=MaB0XXdvU+WuX6iX4LKgXA7ox/SrFT7eN7zK6Eu78Ts=; b=REj1Hu1RIffsSFYeGpssdeaIBRtdmyzg2cwPeZpTLVkGlbyNkY3pPbFumI73Pa16m1 1iQYOxJ3QDQ6ii7xFYG+Q4iu4FSYC3PhTl6y5gKEGTGBSiIRPdJTZgrEeaEeqtSHjW9p wcu4blZO77/LhS+vqVtdR/DnVHGy9g0mT0pEWI08r4U3FMzp3beyu/RDbOXs5aksdVGz T8nDXimT9JkZ4izyfco66gA8DgHo7XbCO38dUBbQZsbd2geLnq9OwuM0RAEhZ3AHRjyJ MM8Uc7ug857uf7asanU1k/c0Xx5jfbIVibmRAVgCYMj/iLTFIMZX/mB8fJ3Cv5k9V2IT aUjw==
X-Gm-Message-State: ALoCoQnJnfQkr6D+wm4NPg3hJMJgQwaouscXOv92ucfVvBMWoF/UV/AuqtsZabMcXB2TUIh4S1tH
X-Received: by 10.140.196.77 with SMTP id r74mr4432363qha.23.1444253044610; Wed, 07 Oct 2015 14:24:04 -0700 (PDT)
Received: from [5.5.33.73] (vpn.snozzages.com. [204.42.252.17]) by smtp.gmail.com with ESMTPSA id b127sm16971677qhc.46.2015.10.07.14.24.03 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 07 Oct 2015 14:24:04 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <yj9osi5mae4p.wl%morrowc@ops-netman.net>
Date: Wed, 7 Oct 2015 17:24:01 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/fRUzvmblyyLyWCfxhTHCyMa3ui0>
Cc: sidr-chairs@ietf.org
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2015 21:24:07 -0000

We=92ll need to figure out what to do about the I-D.sidr-as-migration =
reference it=92s in the =93IESG Dead=94 state.

I guess s3.2 is going to match whatever updates are made to =
bgpsec-protocol-14.

spt

On Oct 07, 2015, at 11:32, Chris Morrow <morrowc@ops-netman.net> wrote:

>=20
> Howdy WG folks,
> Please consider this your warning/notice that the WGLC has been =
started for:
>=20
>  draft-ietf-sidr-bgpsec-overview
>=20
> Abstract:
>  "This document provides an overview of a security extension to the
>   Border Gateway Protocol (BGP) referred to as BGPsec.  BGPsec =
improves
>   security for BGP routing."
>=20
> Please give this a read, send comments if there are any, and let us
> know if this is prepared for publication request.
>=20
> Thanks!
>=20
> -chris
> co-chair
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Thu Oct  8 02:14:26 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FAB41A8F35; Thu,  8 Oct 2015 02:14:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ncgVaHz1KgeM; Thu,  8 Oct 2015 02:14:24 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BF9D51A8F34; Thu,  8 Oct 2015 02:14:24 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 3499428B0041; Thu,  8 Oct 2015 05:14:23 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id A67371F8035; Thu,  8 Oct 2015 05:14:22 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_04B9FF65-C0E9-41CF-BFF9-071D008E040A"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com>
Date: Thu, 8 Oct 2015 05:14:20 -0400
Message-Id: <22F64DA2-03A5-4B52-A897-B591A4EC01FB@tislabs.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com>
To: Sean Turner <sean@sn3rd.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/mD1FJrQghAB_Fg17-AIN13xMwA4>
Cc: sidr wg list <sidr@ietf.org>, sidr-chairs@ietf.org, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 09:14:26 -0000

--Apple-Mail=_04B9FF65-C0E9-41CF-BFF9-071D008E040A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


On Oct 7, 2015, at 5:24 PM, Sean Turner <sean@sn3rd.com> wrote:

> We=92ll need to figure out what to do about the I-D.sidr-as-migration =
reference it=92s in the =93IESG Dead=94 state.

Thanks for the heads up, we=92ll investigate with the AD.

=97Sandy, speaking as wg co-chair

>=20
> I guess s3.2 is going to match whatever updates are made to =
bgpsec-protocol-14.

>=20
> spt
>=20
> On Oct 07, 2015, at 11:32, Chris Morrow <morrowc@ops-netman.net> =
wrote:
>=20
>>=20
>> Howdy WG folks,
>> Please consider this your warning/notice that the WGLC has been =
started for:
>>=20
>> draft-ietf-sidr-bgpsec-overview
>>=20
>> Abstract:
>> "This document provides an overview of a security extension to the
>>  Border Gateway Protocol (BGP) referred to as BGPsec.  BGPsec =
improves
>>  security for BGP routing."
>>=20
>> Please give this a read, send comments if there are any, and let us
>> know if this is prepared for publication request.
>>=20
>> Thanks!
>>=20
>> -chris
>> co-chair
>>=20
>> _______________________________________________
>> sidr mailing list
>> sidr@ietf.org
>> https://www.ietf.org/mailman/listinfo/sidr
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


--Apple-Mail=_04B9FF65-C0E9-41CF-BFF9-071D008E040A
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFjPyAAoJEHplpQeet0IZaaIP/j66s5/z98gFWiQsWOHq4d2c
ttcLmZ9sgViBOcgWWcv2w5/+OrWekX7dvu2D7jz53jxD8qIYnf8eMmv3FUwj4yY3
O/bGp1NJaZ/NxbfnyF1/q0sGhC4lP4pLvqNHYpoiP+qguJHn/037VR7sXOMKuc00
mdVclmbCQhmJsElu0NWo2fptqK1Sftl5OmIvIjnmopdZkK3ytzpvGvU3OaznHpIv
lUZpNfVtlV2pfWAI+zacD0B1akctlwSMc0HOqmftpihtbvuVjCRLDd52FdTOj3KC
3OZhy/ibjKH/7OGlwyB+IBYbHCT5m/B2FEIxsUHt0SjQCxRMTf8Rj410bS7uhLL9
nDGV9gAW/yPNS8JzrG/GTtg/srEuvE3jLVrJKcOM4P1Yw8plI1hWzH02nbBz7fXB
+PJJS/+lx/gjRDOkgOmfrxNDVwqD/P5jpDzq5wN24HYvJ/FWld5u2xccmrh/PwWA
DHGr675mVLx0EOphasYI79nCzBxATY1MzcjnyeIQ66cV72aFFv5ipszuLZ2jl5Qn
A6t9mf+O8UNJhbIFqW/foTWEUS5iMLgcFwKEswaM4s9iJDkvca/nsvBTxKGS+F+w
/Z2Gq/BxpI0j2DMphkQojbyFIOjbn/Ve1GSZes/hawzUti/dR9z+y3qTlscIKcO7
eRCEY6NB6tZDRBDqGTV0
=gSAk
-----END PGP SIGNATURE-----

--Apple-Mail=_04B9FF65-C0E9-41CF-BFF9-071D008E040A--


From nobody Thu Oct  8 02:45:34 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DAA8E1A9051 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 02:45:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yE7lRIio52hU for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 02:45:32 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 71FAB1A9048 for <sidr@ietf.org>; Thu,  8 Oct 2015 02:45:32 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id B13E628B003D; Thu,  8 Oct 2015 05:45:31 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 5C5AB1F8035; Thu,  8 Oct 2015 05:45:31 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_7CE8A010-FB1B-4361-8219-3800B528F426"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com>
Date: Thu, 8 Oct 2015 05:45:35 -0400
Message-Id: <554A2136-4D85-4C02-B572-C5C1008DD348@tislabs.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com>
To: Sean Turner <sean@sn3rd.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/OOGZg8qvvbw8TTL2vhKlMQZkBxo>
Cc: sidr wg list <sidr@ietf.org>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 09:45:34 -0000

--Apple-Mail=_7CE8A010-FB1B-4361-8219-3800B528F426
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

Speaking as regular ol=92 member
On Oct 7, 2015, at 5:24 PM, Sean Turner <sean@sn3rd.com> wrote:

> We=92ll need to figure out what to do about the I-D.sidr-as-migration =
reference it=92s in the =93IESG Dead=94 state.
>=20
> I guess s3.2 is going to match whatever updates are made to =
bgpsec-protocol-14.
>=20

Looking at that section, I think it matches the planned updates to the =
bgpsec protocol.

Ironically, I think it matches the planned updates more directly than it =
matches the current state of the bgpsec protocol, depending on how you =
read the exact wording.

     .  BGPsec_Path contains 3 signatures :
          o  Signature from AS 1 protecting

             192.0.2/24, AS 1 and AS 2

This will still be true in the updates, no problem.

          o  Signature from AS 2 protecting

             Everything AS 1's signature protected, and AS 3

Right now, the bgpsec protocol=92s signature from AS 2 covers the =
signature from AS 1, not =93Everything AS 1=92s signature protected=94.  =
Of course, by induction, that protects =93Everything AS 1=92s signature =
protected=94.  So not wrong, just indirectly true.

The intent as I understand it of the updates to the bgpsec protocol are =
to make the signature from AS 2 cover and directly protect =93Everything =
AS 1=92s signature protected=94.

IMHO.  You are an author, so=85..

=97Sandy, speaking as regular ol=92 member

--Apple-Mail=_7CE8A010-FB1B-4361-8219-3800B528F426
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFjs/AAoJEHplpQeet0IZj8oQAIM9jYmurEunACaSlm7BOPpf
Xu8M/+9st7KcGZZmeK99p9M49t2ye4dntn+2N9MdBuEr474GKHiBvtUQyjoTPOm9
SPKx2qS//9FAZJVgQc7RyRiB+VUeVN7rKhwzKbuguUv425ryAupMz0h5P0ze2os0
njRPGtH25XilSPwYcZkIdNEHCBdpQkBbnUaxyEiN9zBYBIhGcGQfUsWSxHNvWhLk
zmAVNtbLs1jSfkrmE6Vd9D++Exqrk8TMUe2WhSvtWwe3hDT+LNAp1NReHiQ64f1E
c+J09+EdvpSI0ysnaI+iCjQFYvrgiMQNruxphTUlq5BM+NxxuUS3fPFG1GSKQ4c0
KCnemGaOkStM3ZsLXldZbL+mNKwE6mDVuOTiUvkuPkaGwe+o86XOp/H4nKkvx8Go
Mo1lke7wEaZgRPA/FnM1gM0iW9D9w9AXY8JrWTrlZ+Tk/6Ncs3B9rrSDw3IEAgrT
sVQ0M/HV8+NxDlnRAepgz1CbDfJzq9mr437g03IUreKkKC7e0+R555ldz8bdtS17
PAQ4olIWkft5wkor7ghM0ynC8J6Ib/jHJ2mrlGTejyO73T5i1vwSGMNEV4DE8OCx
XMdrHgYE2kmDnS0TvNPztrbyZqp9skEv/OtMHgnJ7KkE/TddlT0MWfB3ZDfYUIFi
9PvwjVNadhBfpnKpF15C
=brxR
-----END PGP SIGNATURE-----

--Apple-Mail=_7CE8A010-FB1B-4361-8219-3800B528F426--


From nobody Thu Oct  8 06:54:29 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E2D711B33E8; Thu,  8 Oct 2015 06:54:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4CuN_pgPf6AA; Thu,  8 Oct 2015 06:54:26 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 961911B3407; Thu,  8 Oct 2015 06:54:26 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id ED2B728B0046; Thu,  8 Oct 2015 09:54:25 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id A9DD91F8035; Thu,  8 Oct 2015 09:54:25 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_25DEF612-5BAF-4883-95DF-74AC1188A1C8"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <22F64DA2-03A5-4B52-A897-B591A4EC01FB@tislabs.com>
Date: Thu, 8 Oct 2015 09:54:25 -0400
Message-Id: <CA6807CB-F46E-4745-8E02-96D5CE5BC1D5@tislabs.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com> <22F64DA2-03A5-4B52-A897-B591A4EC01FB@tislabs.com>
To: Sean Turner <sean@sn3rd.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/7j2N6tk2Mw_3Rt1D3HuFWWFwQQI>
Cc: sidr wg list <sidr@ietf.org>, sidr-chairs@ietf.org, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 13:54:28 -0000

--Apple-Mail=_25DEF612-5BAF-4883-95DF-74AC1188A1C8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


On Oct 8, 2015, at 5:14 AM, Sandra Murphy <sandy@tislabs.com> wrote:

>=20
> On Oct 7, 2015, at 5:24 PM, Sean Turner <sean@sn3rd.com> wrote:
>=20
>> We=92ll need to figure out what to do about the I-D.sidr-as-migration =
reference it=92s in the =93IESG Dead=94 state.
>=20
> Thanks for the heads up, we=92ll investigate with the AD.

The answer from the AD is:

   The system changed it to Dead from "AD is Watching" when the draft =
expired.

   In any case, all "Dead" means is that the IESG is not tracking the =
document, not that we're in fact killing it.


=97Sandy

--Apple-Mail=_25DEF612-5BAF-4883-95DF-74AC1188A1C8
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFnWSAAoJEHplpQeet0IZHwMP/A/LvPNZOl3Uiw/zsdGTtEYX
KgNkgNLbDM0xURFgsMbWy4JbokMHx2vB6ZuiJ3gaMczZO+a922DtzneS3ekkRB7H
AqeV8wY8NmLfSor9U0zm8YFX0EQ+PbNBBpaFiwg5DdUD0xptUnYE2SxWqc1DLI+l
WiThrqs6Zy3glx2vnptsLW64GbF6L1Lnu3Z6C37/oCCzHClpnO5jckWHHKUvg6Dd
IQ2GjHkawcMdjsA3ipWPGGNKF3zfcFBAYGjQK+lp74mcqotzgkobqWlrpWRxGZew
tuDoA84Gz5nCBzArexE11vhoM9dKCQvmqUcGmFUoHh7xgC6GDrY33LZLKcoaF73v
iunqPd8ApqkcPrRp9MC/Iwxm4igDwi12Fd/Iu5CMPTfgGW/TLoa9hyQYG/inMLdM
BqoUGrDvGnWPEeGTxdEHeBAoXzWHVRpbsuPKhu5iqb0wTZdOYZYeK3uJSlJJo+fI
k52hucUSCbvRYWK6Mlp+Mtbe4zriwdCnuizISQNsJh0Q6QCsfooiUeQfwwFtOs9K
RqcqojJaBRrFBdjCFMuK6/qgyluINxRydxnG4PURvVk8+r/tVp+344AbBzy3yS07
zu7MZt6MOGjrD4kPgmPUXpyfj0elsmubr0hyrZM73rstBCuvPKFaCVNifYmnDk4s
L3ohtkxd1GqtRzKclR7k
=4dL9
-----END PGP SIGNATURE-----

--Apple-Mail=_25DEF612-5BAF-4883-95DF-74AC1188A1C8--


From nobody Thu Oct  8 11:56:46 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3429F1A9235 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 11:56:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yFXwCB-ea6ww for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 11:56:43 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CB3791A916E for <sidr@ietf.org>; Thu,  8 Oct 2015 11:56:43 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 2B84F28B0041 for <sidr@ietf.org>; Thu,  8 Oct 2015 14:56:43 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id CA5A11F8035; Thu,  8 Oct 2015 14:56:42 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_5F0B96F1-2C53-41FC-B440-604F4562B07E"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Thu, 8 Oct 2015 14:56:33 -0400
Message-Id: <C881A1D8-ADD9-4FE9-90D3-3C6DAA57C5EB@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/t5XCXHskPPbEUxgIRW-nDnRVfnI>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] comments on draft-ymbk-sidr-transfer-01???
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 18:56:45 -0000

--Apple-Mail=_5F0B96F1-2C53-41FC-B440-604F4562B07E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The draft draft-ietf-sidr-rpki-validation-reconsidered speaks forcefully =
of the potential for damage if a certificate over claims, i.e., claims =
more resources than its parent.  The draft discusses how that could =
result from a failure of timing in a transfer of resources.

In a presentation in the November 2014 IETF session on this topic, it =
was suggested that discussion of "a standard procedure for certificate =
management during resource transfer=94 and "current CA operational =
procedures for managing transfers=94 would help in the reconsideration =
of the validation algorithm.

A draft was submitted and discussed at the last meeting.  =
https://tools.ietf.org/html/draft-ymbk-sidr-transfer  But no comments =
have been received.

This is an important topic, folks, and deserves our attention.

Please do read the draft and comment.

=97Sandy

--Apple-Mail=_5F0B96F1-2C53-41FC-B440-604F4562B07E
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWFrxqAAoJEHplpQeet0IZez8QAIObXXHYqYhK4qXnwNsE7rKN
ZtHwIljbuv4Dim8bMuFiM/QqSoSHdGxoZpIaX9or8I++qNlzoh09OY0EgHf5KNC2
kxnxtqgHqerihKcPOLQZ4w3SmWcskT/y1IE0eNHGL70pyOu1kg8WfvGXCzc9QgJ0
S/9ewfhTtU+GeohhPtuSFtPlU8al3GLSt42A3FnGTo2uPSBOgrF6nACnlu0BaA5s
Z3PFffFcnKuEap7dwzTVbtKAKDBwhL5S7sU9Ky9TX1jPrTiAveQvc2WJYBYFtLEp
o1vgkxuFJTSwI82xk5pMwp54cl37FGb4nFHBc0O4ZICJV4N2yipCnlHW3QtlEmut
Tmlcasqd3x/SVLPsidP82k95x4zOGDJo0aKOcDyn0E/qSZ6xuUi4irJ7tzQ0+Fnx
8tnr5r9VidH/H5l1cB7sCmtOIBZuZEa1DnRAa19pE4Kd/z6pxSFdGWUI2r09yTvT
JNwUt7G8xzblClePSSGxIkATZVsc7/IMJEns2YoI1eqp2QYfxgxQPdjog8HeroIv
jnMmo3oPPVtTdybmAyIvDjCF2bNbejK+5n6KAZRKlOJjsLZM7HgcXdOMWh590Otu
ivMK7o8l5BpKx04SnauM8U5zQHmZbhwzmmsEC70oIK7W8AEtqwXs+BS1Uge2fbog
mSgZuh3PS1hRrxoQ+4ah
=GwKJ
-----END PGP SIGNATURE-----

--Apple-Mail=_5F0B96F1-2C53-41FC-B440-604F4562B07E--


From nobody Thu Oct  8 13:18:45 2015
Return-Path: <sra@hactrn.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14BF01ACD2B for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 13:18:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.71
X-Spam-Level: 
X-Spam-Status: No, score=-0.71 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_31=0.6, J_CHICKENPOX_41=0.6, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LCbkQyoI7JIf for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 13:18:42 -0700 (PDT)
Received: from adrilankha.hactrn.net (adrilankha.hactrn.net [147.28.0.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A22BD1ACD2A for <sidr@ietf.org>; Thu,  8 Oct 2015 13:18:42 -0700 (PDT)
Received: from minas-ithil.hactrn.net (c-24-34-34-101.hsd1.ma.comcast.net [24.34.34.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "nargothrond.hactrn.net", Issuer "Grunchweather Associates" (verified OK)) by adrilankha.hactrn.net (Postfix) with ESMTPS id 2B3553982A for <sidr@ietf.org>; Thu,  8 Oct 2015 20:18:42 +0000 (UTC)
Received: from minas-ithil.hactrn.net (localhost [IPv6:::1]) by minas-ithil.hactrn.net (Postfix) with ESMTP id A032B1C68DAD for <sidr@ietf.org>; Thu,  8 Oct 2015 16:17:51 -0400 (EDT)
Date: Thu, 08 Oct 2015 16:17:51 -0400
From: Rob Austein <sra@hactrn.net>
To: sidr@ietf.org
In-Reply-To: <C6707353-65E9-49B2-8D50-F317127EA7F8@sn3rd.com>
References: <555F436F.3080003@bbn.com> <2BF75857-6A5F-4260-B13B-0B9F6CE3FD98@ieca.com> <197E8AEA-D554-4DB4-885E-CFD55EF9E774@ripe.net> <m2wpx7pes6.wl%randy@psg.com> <55C4D7C8.4000401@bbn.com> <97B4FBD1-BCE6-4D37-BC0C-07A211347FBF@ieca.com> <55CA4901.4010007@bbn.com> <D008D28C-FC51-4AB7-9F73-C2435408AED6@ieca.com> <c6af9ec70934494a2e0dd965c3fe753b@mail.mandelberg.org> <99B857CD-DF02-4751-880A-E6D1283CF3BE@tislabs.com> <C6707353-65E9-49B2-8D50-F317127EA7F8@sn3rd.com>
User-Agent: Wanderlust/2.15.5 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Message-Id: <20151008201751.A032B1C68DAD@minas-ithil.hactrn.net>
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/wGki_B-5SwIl8y6VMonv2j9mSAU>
Subject: Re: [sidr] preventing SKI collisions
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 20:18:44 -0000

At Wed, 7 Oct 2015 09:22:40 -0400, Sean Turner wrote:
>=20
> On Oct 06, 2015, at 08:30, Sandra Murphy <sandy@tislabs.com> wrote:
>> On Oct 5, 2015, at 4:36 PM, David Mandelberg <david@mandelberg.org> wrot=
e:
>>>
>>> 4. Add text warning relying parties to detect malicious CAs that
>>> cause too many KI collisions, and blacklist those CAs. Similarly,
>>> warn routers and/or rpki-rtr caches to detect AS numbers with too
>>> many public keys sharing the same SKI, and blacklist those AS
>>> numbers.
>>=20
>> I?m ok with ?warn?, but ?blacklist? is a bit strong for me.  If you
>> mean stop using that CA, i.e. remove all objects produced by that
>> CA, then the whole tree under that CA would fall off the planet.  I
>> think that?s a potentially large cone of consequence and I believe
>> it should be undertaken by brains, not code.
>>=20
>> I?d prefer a warning in the security considerations section and a
>> recommendation to alert the operator.
>=20
> Yep let?s just put a warning in the security considerations and
> alert the operator.

Agreed.  "Blacklist" sounds too much like mandatory policy.
My RP, who are you to decide how much of its CPU time I should waste?


From nobody Thu Oct  8 13:57:52 2015
Return-Path: <kent@bbn.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E46B1ACE12 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 13:57:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.312
X-Spam-Level: 
X-Spam-Status: No, score=-2.312 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H5O32zGnaYaD for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 13:57:50 -0700 (PDT)
Received: from smtp.bbn.com (smtp.bbn.com [128.33.1.81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 317661ACD81 for <sidr@ietf.org>; Thu,  8 Oct 2015 13:57:50 -0700 (PDT)
Received: from ssh.bbn.com ([192.1.122.15]:60849 helo=COMSEC.fios-router.home) by smtp.bbn.com with esmtp (Exim 4.77 (FreeBSD)) (envelope-from <kent@bbn.com>) id 1ZkIG4-0002KE-FH for sidr@ietf.org; Thu, 08 Oct 2015 16:57:48 -0400
To: sidr@ietf.org
References: <C881A1D8-ADD9-4FE9-90D3-3C6DAA57C5EB@tislabs.com>
From: Stephen Kent <kent@bbn.com>
Message-ID: <5616D8CC.60709@bbn.com>
Date: Thu, 8 Oct 2015 16:57:48 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <C881A1D8-ADD9-4FE9-90D3-3C6DAA57C5EB@tislabs.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/T_o-Hsk0gwgqVeqoKKTRJt3Hm6g>
Subject: Re: [sidr] comments on draft-ymbk-sidr-transfer-01???
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 20:57:51 -0000

Sandy,

I provided detailed comments on this document on June 2.

Randy later said he didn't see them, so I resent (just to Randy) on July 7.

Steve






From nobody Thu Oct  8 14:45:05 2015
Return-Path: <gih902@gmail.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78C3E1ACF55 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 14:45:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.75
X-Spam-Level: 
X-Spam-Status: No, score=-1.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wid1B3XGUuV7 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 14:45:02 -0700 (PDT)
Received: from mail-qg0-x230.google.com (mail-qg0-x230.google.com [IPv6:2607:f8b0:400d:c04::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7B4C81ACF1D for <sidr@ietf.org>; Thu,  8 Oct 2015 14:45:02 -0700 (PDT)
Received: by qgez77 with SMTP id z77so54373381qge.1 for <sidr@ietf.org>; Thu, 08 Oct 2015 14:45:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=content-type:mime-version:subject:from:in-reply-to:date :content-transfer-encoding:message-id:references:to; bh=9zt6p4uLaszGQdAG5TXVzT2mhqE2w6BZ914+98Zq5A4=; b=tAXMehO5vSEO5pDM9o+h101T1S5Ly3r+GZV5uPNPdqkzYETJ88jKohjkYaj9+/QCd1 L2fGbDt2G+Gv35Zu7h3JKmme3BywQfJO1B8yhjCUDf+VRU6wZxDvmKCThoQBu5h1gc+2 +a+RQpbd8q2Wbfzd+9c2nfqijMLZf5oArkdWwcnPyIMeFRKJSrjtiUQptsuagA3hcCuy aJXjx+bY+9tcYwWInyg2dfyGrxixD6FZp+9uBAGSSx5d5CIAH8kqLbJbpDzOeyfFj0Rh 1uGsV41zRZuNgyfsOqjctJ++eVuByXORVpRI0JRt/b1VfRN2j5GGa75PGkhDPbVZ1y1i jq4g==
X-Received: by 10.140.93.68 with SMTP id c62mr11400186qge.54.1444340701654; Thu, 08 Oct 2015 14:45:01 -0700 (PDT)
Received: from [172.16.137.34] ([216.46.0.94]) by smtp.gmail.com with ESMTPSA id y12sm19567032qgd.20.2015.10.08.14.45.00 for <sidr@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 08 Oct 2015 14:45:01 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih902@gmail.com>
In-Reply-To: <C881A1D8-ADD9-4FE9-90D3-3C6DAA57C5EB@tislabs.com>
Date: Thu, 8 Oct 2015 17:45:00 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <D7C8F00F-3B91-43E7-AD0A-8C83FEB30A05@gmail.com>
References: <C881A1D8-ADD9-4FE9-90D3-3C6DAA57C5EB@tislabs.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/eqQymmXbcgWri9dqoKM4waSmxMo>
Subject: Re: [sidr] comments on draft-ymbk-sidr-transfer-01???
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 21:45:03 -0000

> On 8 Oct 2015, at 2:56 PM, Sandra Murphy <sandy@tislabs.com> wrote:
>=20
> The draft draft-ietf-sidr-rpki-validation-reconsidered speaks =
forcefully of the potential for damage if a certificate over claims, =
i.e., claims more resources than its parent.  The draft discusses how =
that could result from a failure of timing in a transfer of resources.

** or form any other form of a drop in precise synchronisation between =
the CA=92s number resource database and the state of a CA=92s issued =
certificates.

While I=92m sure perfection is an admirable objective, snafus do occur, =
and another part of the motivation of the reconsidered document was to =
reduce degree of catastrophic result from certain forms of certificate =
issuance failure from one where all subordinate certificates cannot be =
validated to one that impacts only of the validation status relative to =
the resource that was placed in this inconsistent state.

i.e. validation reconsidered is not 1:1 isomorphic to just transfers, as =
you may have been led to believe from the next sentence...


>=20
> In a presentation in the November 2014 IETF session on this topic, it =
was suggested that discussion of "a standard procedure for certificate =
management during resource transfer=94 and "current CA operational =
procedures for managing transfers=94 would help in the reconsideration =
of the validation algorithm.
>=20


regards,

   Geoff



From nobody Thu Oct  8 14:53:09 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 795651B2D19; Thu,  8 Oct 2015 14:53:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fcZjAF79AIjo; Thu,  8 Oct 2015 14:53:06 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 464341B2AB6; Thu,  8 Oct 2015 14:53:04 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151008215304.32333.52972.idtracker@ietfa.amsl.com>
Date: Thu, 08 Oct 2015 14:53:04 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Ph6mxuAkpkgHTGaMt6ZXEkigENg>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rfc6490-bis-05.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 21:53:07 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : Resource Public Key Infrastructure (RPKI) Trust Anchor Locator
        Authors         : Geoff Huston
                          Samuel Weiler
                          George Michaelson
                          Stephen Kent
	Filename        : draft-ietf-sidr-rfc6490-bis-05.txt
	Pages           : 9
	Date            : 2015-10-08

Abstract:
   This document defines a Trust Anchor Locator (TAL) for the Resource
   Public Key Infrastructure (RPKI).  This document obsoletes RFC6490 by
   adding support for multiple URIs in a TAL.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6490-bis/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rfc6490-bis-05

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rfc6490-bis-05


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Thu Oct  8 14:56:31 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 97A901B2D43 for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 14:56:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fc7W_76sWyZy for <sidr@ietfa.amsl.com>; Thu,  8 Oct 2015 14:56:27 -0700 (PDT)
Received: from ia-mailgw.apnic.net (ia-mailgw.apnic.net [IPv6:2001:dd8:a:851::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 06A861B2D41 for <sidr@ietf.org>; Thu,  8 Oct 2015 14:56:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date:cc: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=6yjRnI8tH+4C5cpNw7S5MC+6o5V+psl/PdtYESK5wOY=; b=mVVs7JQKEdst3Jtyiz5YjfToF5BrXWMLkXK0KBWh3VGiThDMzsjcBoXvm5shIqykp0AljJ2uKAAWJ EK8egxiOVCiDWL2G50KHULpo5zWr5YdbRHfml2MVBiL4x79zs5abSASe1AADvrpD2fzXy1FAC85nOO Om9ovDeHdgTGQ/3Y=
Received: from iamda3.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by ia-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS; Fri,  9 Oct 2015 07:56:37 +1000 (AEST)
Received: from [172.16.137.34] (203.119.101.249) by iamda3.org.apnic.net (203.119.111.31) with Microsoft SMTP Server (TLS) id 14.1.218.12; Fri, 9 Oct 2015 07:56:22 +1000
Content-Type: text/plain; charset="windows-1252"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <E91F4D62-1FB4-4AFE-B07D-34019EAB031F@tislabs.com>
Date: Thu, 8 Oct 2015 17:56:13 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <7A8285B5-6C9E-4E8D-8486-CA719414AA68@apnic.net>
References: <E91F4D62-1FB4-4AFE-B07D-34019EAB031F@tislabs.com>
To: Sandra Murphy <sandy@tislabs.com>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/q3Zm6DLgQCfPnRzQ_7L8jyaKTG8>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] draft-ietf-sidr-rfc6490-bis-04 - " Revised I-D Needed "
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 21:56:29 -0000

> On 5 Oct 2015, at 2:03 PM, Sandra Murphy <sandy@tislabs.com> wrote:
>=20
> The draft draft-ietf-sidr-rfc6490-bis-04 was approved by the IESG, =
provided the comments received during IETF Last Call were addressed.
>=20
> The IETF Last Call comments were noted to the sidr list in =
http://www.ietf.org/mail-archive/web/sidr/current/msg07208.html.
>=20
> As wg co-chair, I am satisfied that wg has consensus is to adopt =
=93Option #2=94 [ (allow but do not mandate line breaks)] as mentioned =
in the message that brought up the problem =
[http://www.ietf.org/mail-archive/web/sidr/current/msg07164.html].
>=20
> The draft authors are requested to submit a revised version of the =
draft including this response.   That would get the draft to =
publication.
>=20
> In the initial message, the following text was suggested.  The draft =
authors may use this as they wish.
>=20
> 2. Permit but don't require newlines.  For example, change Section 2.1
>  item #3 from:
>=20
>    3)  a subjectPublicKeyInfo [RFC5280] in DER format [X.509],
>        encoded in Base64 (see Section 4 of [RFC4648].
>=20
>  to:
>=20
>    3)  a subjectPublicKeyInfo [RFC5280] in DER format [X.509],
>        encoded in Base64 (see Section 4 of [RFC4648]).  To avoid
>        long lines, <CRLF> or <LF> line breaks MAY be inserted into
>        the Base64 encoded string.
>=20
> =97Sandy, speaking as co-chair


Sorry for the delay - it slipped off the desk and the dog ate it.

Here=92s the revised id with that vitally critical sentence added.


A new version of I-D, draft-ietf-sidr-rfc6490-bis-05.txt
has been successfully submitted by Geoff Huston and posted to the
IETF repository.

Name:		draft-ietf-sidr-rfc6490-bis
Revision:	05
Title:		Resource Public Key Infrastructure (RPKI) Trust Anchor =
Locator
Document date:	2015-10-08
Group:		sidr
Pages:		9
URL:            =
https://www.ietf.org/internet-drafts/draft-ietf-sidr-rfc6490-bis-05.txt
Status:         =
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6490-bis/
Htmlized:       =
https://tools.ietf.org/html/draft-ietf-sidr-rfc6490-bis-05
Diff:           =
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rfc6490-bis-05

Abstract:
  This document defines a Trust Anchor Locator (TAL) for the Resource
  Public Key Infrastructure (RPKI).  This document obsoletes RFC6490 by
  adding support for multiple URIs in a TAL.




Please note that it may take a couple of minutes from the time of =
submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat=


From nobody Fri Oct  9 06:09:01 2015
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71AC31B3CC2; Fri,  9 Oct 2015 06:08:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vfohpNNcSy8g; Fri,  9 Oct 2015 06:08:57 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id C8CF81B3CCA; Fri,  9 Oct 2015 06:08:51 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151009130851.19539.62756.idtracker@ietfa.amsl.com>
Date: Fri, 09 Oct 2015 06:08:51 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/XAh5Gbywci5rZzBH98GSmreU8ik>
Cc: sidr mailing list <sidr@ietf.org>, sidr chair <sidr-chairs@ietf.org>, RFC Editor <rfc-editor@rfc-editor.org>
Subject: [sidr] Protocol Action: 'Resource Public Key Infrastructure (RPKI) Trust Anchor Locator' to Proposed Standard (draft-ietf-sidr-rfc6490-bis-05.txt)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 13:08:58 -0000

The IESG has approved the following document:
- 'Resource Public Key Infrastructure (RPKI) Trust Anchor Locator'
  (draft-ietf-sidr-rfc6490-bis-05.txt) as Proposed Standard

This document is the product of the Secure Inter-Domain Routing Working
Group.

The IESG contact persons are Alvaro Retana, Alia Atlas and Deborah
Brungard.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6490-bis/





Technical Summary

   This document defines a Trust Anchor Locator (TAL) for the Resource
   Public Key Infrastructure (RPKI).  This document obsoletes RFC6490 by
   adding support for multiple URIs in a TAL.

Working Group Summary

   The multi-URI format was suggested in the draft 
   draft-ietf-sidr-multiple-publication-points.  The draft was 
   presented at four IETFs (IETF84-IETF87) and there were comments on the 
   mailing list.

   The working group felt that the feature of providing multiple
   publication points was a benefit for trust anchors, but that the
   appropriate way to represent that would be to modify RFC6490.

Document Quality

   An IETF presentation of the draft-ietf-sidr-multiple-publication-points-01
  (from which this extended format was taken) noted that it had
  been tested against all three known implementations.  Two
  implementers recently confirmed that this is the case.

Personnel

   Document Shepherd: Sandra Murphy (sandy@tislabs.com)
   Responsible Area Director: Alvaro Retana (aretana@cisco.com)


From nobody Fri Oct  9 10:06:52 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B0AC61B48B4; Fri,  9 Oct 2015 10:06:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l2JHP2Ez6jIt; Fri,  9 Oct 2015 10:06:50 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 87EF21B48B1; Fri,  9 Oct 2015 10:06:50 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151009170650.4800.42354.idtracker@ietfa.amsl.com>
Date: Fri, 09 Oct 2015 10:06:50 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/cAnKzdrbdjlwrDNA_N9unY9zbLk>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rpki-validation-reconsidered-02.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 17:06:51 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : RPKI Validation Reconsidered
        Authors         : Geoff Huston
                          George Michaelson
                          Carlos M. Martinez
                          Tim Bruijnzeels
                          Andrew Lee Newton
                          Alain Aina
	Filename        : draft-ietf-sidr-rpki-validation-reconsidered-02.txt
	Pages           : 12
	Date            : 2015-10-09

Abstract:
   This document reviews the certificate validation procedure specified
   in RFC6487 and highlights aspects of operational fragility in the
   management of certificates in the RPKI.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconsidered/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpki-validation-reconsidered-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Oct  9 10:11:18 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC0E91B48C1 for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:11:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cbJiUQo-7ZWW for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:11:16 -0700 (PDT)
Received: from ao-mailgw.apnic.net (ao-mailgw.apnic.net [IPv6:2001:dd8:8:701::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73C0D1B48AA for <sidr@ietf.org>; Fri,  9 Oct 2015 10:11:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=zozZks8u3oYzBVeVneIORT0Scptp6wsIvo/RLyXVi+k=; b=rqg4hwLaFvw6cZ+mHw06skqjPb3PUGfAuh9MfSzTi/1G37aQDu7n1RP6Yr/ghjEZCZ8DmBYrWxdFm 8Moi5QcFoYVbCJo+Svn/H4eNPo7EvUFq+MvxS5SXQ2hOIG1SqYx3stSuXNRTrQBElB8jlBlgtddtbZ Rt69z1EOmqa4L5Kk=
Received: from iamda3.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by ao-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS for <sidr@ietf.org>; Sat, 10 Oct 2015 03:11:10 +1000 (AEST)
Received: from [172.16.137.34] (203.119.101.249) by iamda3.org.apnic.net (203.119.111.31) with Microsoft SMTP Server (TLS) id 14.1.218.12; Sat, 10 Oct 2015 03:11:23 +1000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <20151009170650.4800.42354.idtracker@ietfa.amsl.com>
Date: Fri, 9 Oct 2015 13:11:04 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <F71B8751-E079-4C5B-B7F4-6B3AD81B48D8@apnic.net>
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/f6AbgiIdaLxlN809xPd1RIzT5Ns>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-validation-reconsidered-02.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 17:11:18 -0000

A date refresher, but with a minor excision in the intro sections to =
remove
the false impression that the only problem here is one related to=20
address transfers between RIRs. There is a more general issue of=20
the robustness of  certificate issuance and revocation tracking a space
that includes the dynamic state change of resources that this draft
addresses.

Geoff


> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
>=20
>=20
> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> This draft is a work item of the Secure Inter-Domain Routing Working =
Group of the IETF.
>=20
>        Title           : RPKI Validation Reconsidered
>        Authors         : Geoff Huston
>                          George Michaelson
>                          Carlos M. Martinez
>                          Tim Bruijnzeels
>                          Andrew Lee Newton
>                          Alain Aina
> 	Filename        : =
draft-ietf-sidr-rpki-validation-reconsidered-02.txt
> 	Pages           : 12
> 	Date            : 2015-10-09
>=20
> Abstract:
>   This document reviews the certificate validation procedure specified
>   in RFC6487 and highlights aspects of operational fragility in the
>   management of certificates in the RPKI.
>=20
>=20
> The IETF datatracker status page for this draft is:
> =
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconside=
red/
>=20
> There's also a htmlized version available at:
> =
https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-0=
2
>=20
> A diff from the previous version is available at:
> =
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-recons=
idered-02
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Fri Oct  9 10:20:31 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 03A0C1B48DF; Fri,  9 Oct 2015 10:20:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0ifApni2aeJn; Fri,  9 Oct 2015 10:20:27 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B687B1B48E5; Fri,  9 Oct 2015 10:20:24 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151009172024.13405.95194.idtracker@ietfa.amsl.com>
Date: Fri, 09 Oct 2015 10:20:24 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/qwvZTc53aubLblFXUl3NEYxJfJk>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rpsl-sig-08.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 17:20:30 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : Securing RPSL Objects with RPKI Signatures
        Authors         : Robert Kisteleki
                          Brian Haberman
	Filename        : draft-ietf-sidr-rpsl-sig-08.txt
	Pages           : 14
	Date            : 2015-10-09

Abstract:
   This document describes a method to allow parties to electronically
   sign RPSL-like objects and validate such electronic signatures.  This
   allows relying parties to detect accidental or malicious
   modifications on such objects.  It also allows parties who run
   Internet Routing Registries or similar databases, but do not yet have
   RPSS-like authentication of the maintainers of certain objects, to
   verify that the additions or modifications of such database objects
   are done by the legitimate holder(s) of the Internet resources
   mentioned in those objects.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpsl-sig/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rpsl-sig-08

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpsl-sig-08


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Oct  9 10:24:08 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89FC51B48F9 for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:24:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MlToldhbknUc for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:24:05 -0700 (PDT)
Received: from nx-mailgw.apnic.net (nx-mailgw.apnic.net [IPv6:2001:dd8:9:801::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7EB131B48F0 for <sidr@ietf.org>; Fri,  9 Oct 2015 10:24:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date:cc: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=HvDIYdzBKkV4hCogEFtFWHoQVYHpnkQN4S9NIp7E6G4=; b=WGhkY+D8YF1kVBjgATxu4n6EPi7cGufT79LK9u6qpwE7PQbJMHzvRKfCYWvxH0KqgMdp3XwOBsf4Y TTJRgFAnVjZCHnKyyb2UIclqqimr7GlOunCgNEGp9F8RKFMoiBIIz/KcHLxKUd9DmluRH6obX7YUWe CHEopVU3MQVi3cWg=
Received: from NXMDA2.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by nx-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS; Sat, 10 Oct 2015 03:24:10 +1000 (AEST)
Received: from [172.16.137.34] (203.119.101.249) by NXMDA2.org.apnic.net (203.119.107.21) with Microsoft SMTP Server (TLS) id 14.1.218.12; Sat, 10 Oct 2015 03:26:32 +1000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <20151009170650.4800.42354.idtracker@ietfa.amsl.com>
Date: Fri, 9 Oct 2015 13:23:52 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net>
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Sxkht1Idr1Iz59ZoQ0y8w2bDQwE>
Cc: Christopher Morrow <christopher.morrow@gmail.com>, George Michaelson <ggm@apnic.net>, Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 17:24:06 -0000

Hi,

We were about to ask the WG chairs for a WG Last Call on this document, =
but then noticed that this is an informational document and its =
attempting to update a standards track RFC

We suspect that the best case is to instead look at a precise standards =
track document that describes the update to the validation procedure =
described RFC6487 and would be a clear candidate for Standards Track =
itself.

So draft-huston-sidr-validity-00.txt is that draft.

WG Chairs:- We would like to request WG adoption of =
draft-huston-sidr-validity-00.txt, on the understanding that =
draft-ietf-sidr-rpki-validation-reconsidered has done its work and =
should be allowed to expire gracefully in a corner at this point!


regards,

    Geoff & George




> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
>=20
>=20
> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> This draft is a work item of the Secure Inter-Domain Routing Working =
Group of the IETF.
>=20
>       Title           : RPKI Validation Reconsidered
>       Authors         : Geoff Huston
>                         George Michaelson
>                         Carlos M. Martinez
>                         Tim Bruijnzeels
>                         Andrew Lee Newton
>                         Alain Aina
> 	Filename        : =
draft-ietf-sidr-rpki-validation-reconsidered-02.txt
> 	Pages           : 12
> 	Date            : 2015-10-09
>=20
> Abstract:
>  This document reviews the certificate validation procedure specified
>  in RFC6487 and highlights aspects of operational fragility in the
>  management of certificates in the RPKI.
>=20
>=20
> The IETF datatracker status page for this draft is:
> =
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconside=
red/
>=20
> There's also a htmlized version available at:
> =
https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-0=
2
>=20
> A diff from the previous version is available at:
> =
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-recons=
idered-02
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr

_______________________________________________
sidr mailing list
sidr@ietf.org
https://www.ietf.org/mailman/listinfo/sidr


From nobody Fri Oct  9 10:25:38 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0AE701B48F0 for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:25:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2P_lVMAattNP for <sidr@ietfa.amsl.com>; Fri,  9 Oct 2015 10:25:35 -0700 (PDT)
Received: from ia-mailgw.apnic.net (ia-mailgw.apnic.net [IPv6:2001:dd8:a:851::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC58A1B48F3 for <sidr@ietf.org>; Fri,  9 Oct 2015 10:25:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date:cc: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=SdLCVLmwCpFLkg2K1OwYib2U4aTcWHbCry45uow9faY=; b=NTBuaaepC9xKntgggprq47kBCKUF7e7fKwGWdyq2WMOZdHnbdbu3sC7cOu4S4twPP2p0vVidLDMYw tkr++EH5QuvKPg0GyryDuZj/uCZSNtGPHMAUjpVtBr20w7SRetMlRgBv7aRQGvOZMLB/nT4HGmHbVj lM4sSYmWfU+v0I4g=
Received: from NXMDA2.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by ia-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS; Sat, 10 Oct 2015 03:25:50 +1000 (AEST)
Received: from [172.16.137.34] (203.119.101.249) by NXMDA2.org.apnic.net (203.119.107.21) with Microsoft SMTP Server (TLS) id 14.1.218.12; Sat, 10 Oct 2015 03:28:04 +1000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net>
Date: Fri, 9 Oct 2015 13:25:25 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <B04829F7-0065-4E8A-B8D1-677B23B092B1@apnic.net>
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com> <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/b6KpGJadZPoNpZbwH0Dj8UZkgtw>
Cc: Christopher Morrow <christopher.morrow@gmail.com>, George Michaelson <ggm@apnic.net>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 17:25:37 -0000

sorry - forgot to add the url for this draft - here tis:


A new version of I-D, draft-huston-sidr-validity-00.txt
has been successfully submitted by Geoff Huston and posted to the
IETF repository.

Name:		draft-huston-sidr-validity
Revision:	00
Title:		Update to RPKI Validation
Document date:	2015-10-09
Group:		Individual Submission
Pages:		6
URL:            =
https://www.ietf.org/internet-drafts/draft-huston-sidr-validity-00.txt
Status:         =
https://datatracker.ietf.org/doc/draft-huston-sidr-validity/
Htmlized:       =
https://tools.ietf.org/html/draft-huston-sidr-validity-00


Abstract:
  This document updates the RPKI certificate validation procedure as
  specified in Section 7.2 of RFC6487.




Please note that it may take a couple of minutes from the time of =
submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat



> On 9 Oct 2015, at 1:23 PM, Geoff Huston <gih@apnic.net> wrote:
>=20
> Hi,
>=20
> We were about to ask the WG chairs for a WG Last Call on this =
document, but then noticed that this is an informational document and =
its attempting to update a standards track RFC
>=20
> We suspect that the best case is to instead look at a precise =
standards track document that describes the update to the validation =
procedure described RFC6487 and would be a clear candidate for Standards =
Track itself.
>=20
> So draft-huston-sidr-validity-00.txt is that draft.
>=20
> WG Chairs:- We would like to request WG adoption of =
draft-huston-sidr-validity-00.txt, on the understanding that =
draft-ietf-sidr-rpki-validation-reconsidered has done its work and =
should be allowed to expire gracefully in a corner at this point!
>=20
>=20
> regards,
>=20
>    Geoff & George
>=20
>=20
>=20
>=20
>> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
>>=20
>>=20
>> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
>> This draft is a work item of the Secure Inter-Domain Routing Working =
Group of the IETF.
>>=20
>>      Title           : RPKI Validation Reconsidered
>>      Authors         : Geoff Huston
>>                        George Michaelson
>>                        Carlos M. Martinez
>>                        Tim Bruijnzeels
>>                        Andrew Lee Newton
>>                        Alain Aina
>> 	Filename        : =
draft-ietf-sidr-rpki-validation-reconsidered-02.txt
>> 	Pages           : 12
>> 	Date            : 2015-10-09
>>=20
>> Abstract:
>> This document reviews the certificate validation procedure specified
>> in RFC6487 and highlights aspects of operational fragility in the
>> management of certificates in the RPKI.
>>=20
>>=20
>> The IETF datatracker status page for this draft is:
>> =
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconside=
red/
>>=20
>> There's also a htmlized version available at:
>> =
https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-0=
2
>>=20
>> A diff from the previous version is available at:
>> =
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-recons=
idered-02
>>=20
>>=20
>> Please note that it may take a couple of minutes from the time of =
submission
>> until the htmlized version and diff are available at tools.ietf.org.
>>=20
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/
>>=20
>> _______________________________________________
>> sidr mailing list
>> sidr@ietf.org
>> https://www.ietf.org/mailman/listinfo/sidr
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Fri Oct  9 12:37:01 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 785EB1A1A6E; Fri,  9 Oct 2015 12:36:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.064
X-Spam-Level: ***
X-Spam-Status: No, score=3.064 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, FH_RELAY_NODNS=1.451, HELO_EQ_MODEMCABLE=0.768, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FwlWX8IiSjlb; Fri,  9 Oct 2015 12:36:58 -0700 (PDT)
Received: from cdpipgw02.twcable.com (unknown [165.237.59.23]) by ietfa.amsl.com (Postfix) with ESMTP id E686F1A1A6D; Fri,  9 Oct 2015 12:36:57 -0700 (PDT)
X-SENDER-IP: 10.64.163.144
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,659,1437451200"; d="scan'208";a="806274551"
Received: from unknown (HELO exchpapp03.corp.twcable.com) ([10.64.163.144]) by cdpipgw02.twcable.com with ESMTP/TLS/AES256-SHA; 09 Oct 2015 15:32:22 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp03.corp.twcable.com (10.64.163.144) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Fri, 9 Oct 2015 15:36:55 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Fri, 9 Oct 2015 15:36:55 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: Sandra Murphy <sandy@tislabs.com>, Sean Turner <sean@sn3rd.com>
Thread-Topic: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
Thread-Index: AQHRAsnanioyZ3ot0U2ywhvnC3DZ+g==
Date: Fri, 9 Oct 2015 19:36:54 +0000
Message-ID: <D23D8E80.6C571%wesley.george@twcable.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <BAB8D720-5B2E-4197-857F-6DF24E31DCF1@sn3rd.com> <22F64DA2-03A5-4B52-A897-B591A4EC01FB@tislabs.com> <CA6807CB-F46E-4745-8E02-96D5CE5BC1D5@tislabs.com>
In-Reply-To: <CA6807CB-F46E-4745-8E02-96D5CE5BC1D5@tislabs.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.5.150821
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.239]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21868.004
x-tm-as-result: No--44.228100-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <CC1C6CE85DAAC34D9C12A73B71076BBA@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/cBzoyMIk696dGsSiWHPGzgnIFoI>
Cc: "sidr-chairs@ietf.org" <sidr-chairs@ietf.org>, sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2015 19:36:59 -0000

IE9uIDEwLzgvMTUsIDk6NTQgQU0sICJzaWRyIG9uIGJlaGFsZiBvZiBTYW5kcmEgTXVycGh5Ig0K
PHNpZHItYm91bmNlc0BpZXRmLm9yZyBvbiBiZWhhbGYgb2Ygc2FuZHlAdGlzbGFicy5jb20+IHdy
b3RlOg0KDQoNCg0KPiAgIFRoZSBzeXN0ZW0gY2hhbmdlZCBpdCB0byBEZWFkIGZyb20gIkFEIGlz
IFdhdGNoaW5nIiB3aGVuIHRoZSBkcmFmdA0KPmV4cGlyZWQuDQo+DQo+ICAgSW4gYW55IGNhc2Us
IGFsbCAiRGVhZCIgbWVhbnMgaXMgdGhhdCB0aGUgSUVTRyBpcyBub3QgdHJhY2tpbmcgdGhlDQo+
ZG9jdW1lbnQsIG5vdCB0aGF0IHdlJ3JlIGluIGZhY3Qga2lsbGluZyBpdC4NCg0KT29wcy4gTm93
IHRoYXQgSSd2ZSAoZmluYWxseSkgZ290dGVuIHRocm91Z2ggdGhlIG11bHRpcGxlIHNpZ25pZmlj
YW50DQpyZXZpc2lvbnMgbmVjZXNzYXJ5IG9uIHRoZSBwYXJlbnQgZG9jIGluIElEUiwgYW5kIGl0
IHNpdHMgaW4gdGhlIFJGQw0KZWRpdG9yJ3MgcXVldWUsIEkgaGF2ZSBzb21lIGN5Y2xlcyB0byBm
aW5pc2ggdGhpcyBvbmUgdXAuIEknbGwgd29yayB0byBnZXQNCmFuIHVwZGF0ZSBiZWZvcmUgdGhl
IHBvc3RpbmcgY3V0b2ZmIGZvciBZb2tvaGFtYSwgdGhvdWdoIEknbSBub3Qgc3VyZSB3ZQ0KbmVl
ZCB0byBkaXNjdXNzIGl0IGR1cmluZyB0aGUgbWVldGluZyB0byBnZXQgaXQgbW92aW5nIGZvcndh
cmQgYWdhaW4uDQpJJ2xsIGFsc28gdHJ5IHRvIGNhcnZlIHNvbWUgdGltZSBuZXh0IGJlZm9yZSB0
aGlzIGRvY3VtZW50J3MgV0dMQyBlbmRzIHRvDQpyZXZpZXcgaXQgd2l0aCB0aGUgYXMtbWlncmF0
aW9uIGRyYWZ0IGluIG1pbmQuDQoNClRoYW5rcywNCg0KV2VzDQoNCg0KDQpfX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fXw0KDQpUaGlzIEUtbWFpbCBhbmQgYW55IG9mIGl0cyBhdHRhY2ht
ZW50cyBtYXkgY29udGFpbiBUaW1lIFdhcm5lciBDYWJsZSBwcm9wcmlldGFyeSBpbmZvcm1hdGlv
biwgd2hpY2ggaXMgcHJpdmlsZWdlZCwgY29uZmlkZW50aWFsLCBvciBzdWJqZWN0IHRvIGNvcHly
aWdodCBiZWxvbmdpbmcgdG8gVGltZSBXYXJuZXIgQ2FibGUuIFRoaXMgRS1tYWlsIGlzIGludGVu
ZGVkIHNvbGVseSBmb3IgdGhlIHVzZSBvZiB0aGUgaW5kaXZpZHVhbCBvciBlbnRpdHkgdG8gd2hp
Y2ggaXQgaXMgYWRkcmVzc2VkLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50
IG9mIHRoaXMgRS1tYWlsLCB5b3UgYXJlIGhlcmVieSBub3RpZmllZCB0aGF0IGFueSBkaXNzZW1p
bmF0aW9uLCBkaXN0cmlidXRpb24sIGNvcHlpbmcsIG9yIGFjdGlvbiB0YWtlbiBpbiByZWxhdGlv
biB0byB0aGUgY29udGVudHMgb2YgYW5kIGF0dGFjaG1lbnRzIHRvIHRoaXMgRS1tYWlsIGlzIHN0
cmljdGx5IHByb2hpYml0ZWQgYW5kIG1heSBiZSB1bmxhd2Z1bC4gSWYgeW91IGhhdmUgcmVjZWl2
ZWQgdGhpcyBFLW1haWwgaW4gZXJyb3IsIHBsZWFzZSBub3RpZnkgdGhlIHNlbmRlciBpbW1lZGlh
dGVseSBhbmQgcGVybWFuZW50bHkgZGVsZXRlIHRoZSBvcmlnaW5hbCBhbmQgYW55IGNvcHkgb2Yg
dGhpcyBFLW1haWwgYW5kIGFueSBwcmludG91dC4NCg==


From nobody Tue Oct 13 06:27:43 2015
Return-Path: <arturo.servin@gmail.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2126C1B3149 for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 06:27:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8iboEF4rIBLT for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 06:27:39 -0700 (PDT)
Received: from mail-wi0-x234.google.com (mail-wi0-x234.google.com [IPv6:2a00:1450:400c:c05::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4DEF31B2A1C for <sidr@ietf.org>; Tue, 13 Oct 2015 06:27:39 -0700 (PDT)
Received: by wicge5 with SMTP id ge5so58217791wic.0 for <sidr@ietf.org>; Tue, 13 Oct 2015 06:27:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-type; bh=9XLKPOmYeceLGJyymU6Q10RF8h+KyEhUHvCIrARI09g=; b=tUDFxT8A4mlfFn3LNy2cGarQMQvRCFNp8vwQI+uUjWlwtpXZNEVBNcGxkH9sMMrQc/ 7AzAIkxN/cWJZLaFXq0grw9LpPG6Ln63TRSX0EuyvckgWWBUEQd+xP28+1whyC3lvBuU 4m7BIoExXK5x8gKONNlXQlDvR9ZPinkwAEmes/inney+vpq803+EQDvuy3pjFhH/dglv T+bznlk8xuBysNI5+INBeGVjNkP3AbE1oY6YPuDSfpX6uzoWbNnoYVpDCieEqWn4oV1y 4QvgyuPdmfBnPjrbP9cpgjjh4IyYKPfS8aJKXNOZXYQyT39zOphI3oWhqmXtvsnzA+pB H8aQ==
X-Received: by 10.194.205.229 with SMTP id lj5mr16677450wjc.57.1444742857912;  Tue, 13 Oct 2015 06:27:37 -0700 (PDT)
MIME-Version: 1.0
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com> <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net> <B04829F7-0065-4E8A-B8D1-677B23B092B1@apnic.net>
In-Reply-To: <B04829F7-0065-4E8A-B8D1-677B23B092B1@apnic.net>
From: Arturo Servin <arturo.servin@gmail.com>
Date: Tue, 13 Oct 2015 13:27:27 +0000
Message-ID: <CALo9H1Yc9OF4eWchoOBspLsfZ4DZcUHtwVuRUCjjKutUFQasGw@mail.gmail.com>
To: Geoff Huston <gih@apnic.net>, sidr wg list <sidr@ietf.org>
Content-Type: multipart/alternative; boundary=047d7ba984b8d6789f0521fc68e5
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Bx3R5jtyM2F9i0soe9H4DFenkPQ>
Cc: Christopher Morrow <christopher.morrow@gmail.com>, George Michaelson <ggm@apnic.net>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Oct 2015 13:27:42 -0000

--047d7ba984b8d6789f0521fc68e5
Content-Type: text/plain; charset=UTF-8

Hi

Something that I liked from draft-ietf-sidr-rpki-validation-reconsidered is
that it explained very well why we need to change the validation process.
Although it is not mandatory and I do not have a strong position about it,
I think it would be good to add some context to this document of why the
change.

/as


On Fri, 9 Oct 2015 at 18:25 Geoff Huston <gih@apnic.net> wrote:

> sorry - forgot to add the url for this draft - here tis:
>
>
> A new version of I-D, draft-huston-sidr-validity-00.txt
> has been successfully submitted by Geoff Huston and posted to the
> IETF repository.
>
> Name:           draft-huston-sidr-validity
> Revision:       00
> Title:          Update to RPKI Validation
> Document date:  2015-10-09
> Group:          Individual Submission
> Pages:          6
> URL:
> https://www.ietf.org/internet-drafts/draft-huston-sidr-validity-00.txt
> Status:
> https://datatracker.ietf.org/doc/draft-huston-sidr-validity/
> Htmlized:       https://tools.ietf.org/html/draft-huston-sidr-validity-00
>
>
> Abstract:
>   This document updates the RPKI certificate validation procedure as
>   specified in Section 7.2 of RFC6487.
>
>
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> The IETF Secretariat
>
>
>
> > On 9 Oct 2015, at 1:23 PM, Geoff Huston <gih@apnic.net> wrote:
> >
> > Hi,
> >
> > We were about to ask the WG chairs for a WG Last Call on this document,
> but then noticed that this is an informational document and its attempting
> to update a standards track RFC
> >
> > We suspect that the best case is to instead look at a precise standards
> track document that describes the update to the validation procedure
> described RFC6487 and would be a clear candidate for Standards Track itself.
> >
> > So draft-huston-sidr-validity-00.txt is that draft.
> >
> > WG Chairs:- We would like to request WG adoption of
> draft-huston-sidr-validity-00.txt, on the understanding that
> draft-ietf-sidr-rpki-validation-reconsidered has done its work and should
> be allowed to expire gracefully in a corner at this point!
> >
> >
> > regards,
> >
> >    Geoff & George
> >
> >
> >
> >
> >> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
> >>
> >>
> >> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> >> This draft is a work item of the Secure Inter-Domain Routing Working
> Group of the IETF.
> >>
> >>      Title           : RPKI Validation Reconsidered
> >>      Authors         : Geoff Huston
> >>                        George Michaelson
> >>                        Carlos M. Martinez
> >>                        Tim Bruijnzeels
> >>                        Andrew Lee Newton
> >>                        Alain Aina
> >>      Filename        :
> draft-ietf-sidr-rpki-validation-reconsidered-02.txt
> >>      Pages           : 12
> >>      Date            : 2015-10-09
> >>
> >> Abstract:
> >> This document reviews the certificate validation procedure specified
> >> in RFC6487 and highlights aspects of operational fragility in the
> >> management of certificates in the RPKI.
> >>
> >>
> >> The IETF datatracker status page for this draft is:
> >>
> https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconsidered/
> >>
> >> There's also a htmlized version available at:
> >>
> https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-02
> >>
> >> A diff from the previous version is available at:
> >>
> https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpki-validation-reconsidered-02
> >>
> >>
> >> Please note that it may take a couple of minutes from the time of
> submission
> >> until the htmlized version and diff are available at tools.ietf.org.
> >>
> >> Internet-Drafts are also available by anonymous FTP at:
> >> ftp://ftp.ietf.org/internet-drafts/
> >>
> >> _______________________________________________
> >> sidr mailing list
> >> sidr@ietf.org
> >> https://www.ietf.org/mailman/listinfo/sidr
> >
> > _______________________________________________
> > sidr mailing list
> > sidr@ietf.org
> > https://www.ietf.org/mailman/listinfo/sidr
> >
> > _______________________________________________
> > sidr mailing list
> > sidr@ietf.org
> > https://www.ietf.org/mailman/listinfo/sidr
>
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr
>

--047d7ba984b8d6789f0521fc68e5
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi<div><br></div><div>Something that I liked from=C2=A0dra=
ft-ietf-sidr-rpki-validation-reconsidered is that it explained very well wh=
y we need to change the validation process. Although it is not mandatory an=
d I do not have a strong position about it, I think it would be good to add=
 some context to this document of why the change.</div><div><br></div><div>=
/as</div><div><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"lt=
r">On Fri, 9 Oct 2015 at 18:25 Geoff Huston &lt;<a href=3D"mailto:gih@apnic=
.net">gih@apnic.net</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">=
sorry - forgot to add the url for this draft - here tis:<br>
<br>
<br>
A new version of I-D, draft-huston-sidr-validity-00.txt<br>
has been successfully submitted by Geoff Huston and posted to the<br>
IETF repository.<br>
<br>
Name:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0draft-huston-sidr-validity<br=
>
Revision:=C2=A0 =C2=A0 =C2=A0 =C2=A000<br>
Title:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 Update to RPKI Validation<br>
Document date:=C2=A0 2015-10-09<br>
Group:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 Individual Submission<br>
Pages:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 6<br>
URL:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"https://www.ietf.o=
rg/internet-drafts/draft-huston-sidr-validity-00.txt" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/internet-drafts/draft-huston-sidr-vali=
dity-00.txt</a><br>
Status:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"https://datatracker.iet=
f.org/doc/draft-huston-sidr-validity/" rel=3D"noreferrer" target=3D"_blank"=
>https://datatracker.ietf.org/doc/draft-huston-sidr-validity/</a><br>
Htmlized:=C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"https://tools.ietf.org/html/=
draft-huston-sidr-validity-00" rel=3D"noreferrer" target=3D"_blank">https:/=
/tools.ietf.org/html/draft-huston-sidr-validity-00</a><br>
<br>
<br>
Abstract:<br>
=C2=A0 This document updates the RPKI certificate validation procedure as<b=
r>
=C2=A0 specified in Section 7.2 of RFC6487.<br>
<br>
<br>
<br>
<br>
Please note that it may take a couple of minutes from the time of submissio=
n<br>
until the htmlized version and diff are available at <a href=3D"http://tool=
s.ietf.org" rel=3D"noreferrer" target=3D"_blank">tools.ietf.org</a>.<br>
<br>
The IETF Secretariat<br>
<br>
<br>
<br>
&gt; On 9 Oct 2015, at 1:23 PM, Geoff Huston &lt;<a href=3D"mailto:gih@apni=
c.net" target=3D"_blank">gih@apnic.net</a>&gt; wrote:<br>
&gt;<br>
&gt; Hi,<br>
&gt;<br>
&gt; We were about to ask the WG chairs for a WG Last Call on this document=
, but then noticed that this is an informational document and its attemptin=
g to update a standards track RFC<br>
&gt;<br>
&gt; We suspect that the best case is to instead look at a precise standard=
s track document that describes the update to the validation procedure desc=
ribed RFC6487 and would be a clear candidate for Standards Track itself.<br=
>
&gt;<br>
&gt; So draft-huston-sidr-validity-00.txt is that draft.<br>
&gt;<br>
&gt; WG Chairs:- We would like to request WG adoption of draft-huston-sidr-=
validity-00.txt, on the understanding that draft-ietf-sidr-rpki-validation-=
reconsidered has done its work and should be allowed to expire gracefully i=
n a corner at this point!<br>
&gt;<br>
&gt;<br>
&gt; regards,<br>
&gt;<br>
&gt;=C2=A0 =C2=A0 Geoff &amp; George<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;&gt; On 9 Oct 2015, at 1:06 PM, <a href=3D"mailto:internet-drafts@ietf.=
org" target=3D"_blank">internet-drafts@ietf.org</a> wrote:<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; A New Internet-Draft is available from the on-line Internet-Drafts=
 directories.<br>
&gt;&gt; This draft is a work item of the Secure Inter-Domain Routing Worki=
ng Group of the IETF.<br>
&gt;&gt;<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 Title=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
: RPKI Validation Reconsidered<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 Authors=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: Geo=
ff Huston<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 George Michaelson<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Carlos M. Martinez<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Tim Bruijnzeels<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Andrew Lee Newton<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Alain Aina<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 Filename=C2=A0 =C2=A0 =C2=A0 =C2=A0 : draft-ie=
tf-sidr-rpki-validation-reconsidered-02.txt<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 Pages=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
: 12<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 Date=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
: 2015-10-09<br>
&gt;&gt;<br>
&gt;&gt; Abstract:<br>
&gt;&gt; This document reviews the certificate validation procedure specifi=
ed<br>
&gt;&gt; in RFC6487 and highlights aspects of operational fragility in the<=
br>
&gt;&gt; management of certificates in the RPKI.<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; The IETF datatracker status page for this draft is:<br>
&gt;&gt; <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-v=
alidation-reconsidered/" rel=3D"noreferrer" target=3D"_blank">https://datat=
racker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconsidered/</a><br>
&gt;&gt;<br>
&gt;&gt; There&#39;s also a htmlized version available at:<br>
&gt;&gt; <a href=3D"https://tools.ietf.org/html/draft-ietf-sidr-rpki-valida=
tion-reconsidered-02" rel=3D"noreferrer" target=3D"_blank">https://tools.ie=
tf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-02</a><br>
&gt;&gt;<br>
&gt;&gt; A diff from the previous version is available at:<br>
&gt;&gt; <a href=3D"https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpk=
i-validation-reconsidered-02" rel=3D"noreferrer" target=3D"_blank">https://=
www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-reconsidered-02=
</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; Please note that it may take a couple of minutes from the time of =
submission<br>
&gt;&gt; until the htmlized version and diff are available at <a href=3D"ht=
tp://tools.ietf.org" rel=3D"noreferrer" target=3D"_blank">tools.ietf.org</a=
>.<br>
&gt;&gt;<br>
&gt;&gt; Internet-Drafts are also available by anonymous FTP at:<br>
&gt;&gt; <a href=3D"ftp://ftp.ietf.org/internet-drafts/" rel=3D"noreferrer"=
 target=3D"_blank">ftp://ftp.ietf.org/internet-drafts/</a><br>
&gt;&gt;<br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; sidr mailing list<br>
&gt;&gt; <a href=3D"mailto:sidr@ietf.org" target=3D"_blank">sidr@ietf.org</=
a><br>
&gt;&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"nore=
ferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br=
>
&gt;<br>
&gt; _______________________________________________<br>
&gt; sidr mailing list<br>
&gt; <a href=3D"mailto:sidr@ietf.org" target=3D"_blank">sidr@ietf.org</a><b=
r>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"noreferr=
er" target=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; sidr mailing list<br>
&gt; <a href=3D"mailto:sidr@ietf.org" target=3D"_blank">sidr@ietf.org</a><b=
r>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"noreferr=
er" target=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br>
<br>
_______________________________________________<br>
sidr mailing list<br>
<a href=3D"mailto:sidr@ietf.org" target=3D"_blank">sidr@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br>
</blockquote></div>

--047d7ba984b8d6789f0521fc68e5--


From nobody Tue Oct 13 06:39:30 2015
Return-Path: <weiler@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A146F1B3D30 for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 06:39:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CKZWwZ023nVj for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 06:39:28 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE2131B3D2D for <sidr@ietf.org>; Tue, 13 Oct 2015 06:39:28 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 1092C28B0046 for <sidr@ietf.org>; Tue, 13 Oct 2015 09:39:28 -0400 (EDT)
Received: from nova.tislabs.com (nova.tislabs.com [10.66.1.77]) by nova.tislabs.com (Postfix) with ESMTP id E291F1F8035 for <sidr@ietf.org>; Tue, 13 Oct 2015 09:39:27 -0400 (EDT)
Date: Tue, 13 Oct 2015 09:39:27 -0400 (EDT)
From: Samuel Weiler <weiler@tislabs.com>
To: sidr@ietf.org
Message-ID: <alpine.LRH.2.03.1510130931100.24000@tislabs.com>
User-Agent: Alpine 2.03 (LRH 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format=flowed; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/L3Ehu0YSLOQbBOx9J3c1T2MXliY>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Oct 2015 13:39:29 -0000

The doc cites a bunch of i-d's.  Under previous practice, that would have 
left it languishing in the RFC Editor queue waiting for the others.  If 
that were the practice now, I would suggest we hold it and release all of 
the docs as a group, which would permit later changes to this doc if 
needed.  I think current practice does allow citing i-d's (though version 
numbers need to be specified), but I'm wondering if we wouldn't be better 
off waiting.  This is the first BGPsec doc many will read - I would prefer 
to have it be correct and complete even if we make changes in the other 
docs along the way.

Other than that, no issues with the doc - it's in good shape.

Minor nits sent separately to the editors.

-- Sam Weiler


From nobody Tue Oct 13 08:15:46 2015
Return-Path: <sean@sn3rd.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F16AA1B46DC for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 08:15:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HrQ2OC5QSd9J for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 08:15:43 -0700 (PDT)
Received: from mail-yk0-x236.google.com (mail-yk0-x236.google.com [IPv6:2607:f8b0:4002:c07::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F9A91B46DA for <sidr@ietf.org>; Tue, 13 Oct 2015 08:15:43 -0700 (PDT)
Received: by ykdg206 with SMTP id g206so19641597ykd.1 for <sidr@ietf.org>; Tue, 13 Oct 2015 08:15:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=gVqSqgnT8HRbW5hUrCIi2jahY2ieCOK70jSflQnqjWM=; b=bArac67yjHPStJVqzaMDx0u5mfOhKxJgToOsVSdDPzzjFgP2lMJJAZyd+MRy7QyGMv DDF3wVKOef/F25AdO/2FM1orThx74VDyKgbc4UIyLpFlqhle1vexU17g4umvh3AE1N/+ c3DQNqK4VXUVpRtQqrZb7d5DnzoCGXVaVksRI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=gVqSqgnT8HRbW5hUrCIi2jahY2ieCOK70jSflQnqjWM=; b=DSEjmZ+EnjxbHigq9kTkSq9env0+IesNbmKJlOApyX49xjFxQ5YY/mH5N856Dm7zKt KfFgDdSoJT27spUmMAUZgJH8Hoi+IAmOK9bi5DMOSsu/vZY4lOQ/dJLVDKNHyeS0TrG1 KqJGwynhOp+MF80GnSLVyi5i2AB3Wpo9tsY01MIoUjJ5B5XTHttCPeNYAelndK3TzTj9 +mgh8Iz8VnhLs8GXetbk/gmGEyQ4nLuVNFRLy5FWVV6yNhWTrSyHpSoBFfH2Ow+3BH1b qeELOOIxJWJn7ujUGlw24hn/3YT+tBaHDgWMeLeaoVJw/NM/uitIq7uCMEgFq3NJ0Flv NMXw==
X-Gm-Message-State: ALoCoQnd5UkQ13Evbowa2bgIQgT2XCM7gzPjMoA8sqQ3KZ0wBA/X4XgAPku/DBRt1/36ZGv2ycps
X-Received: by 10.13.226.196 with SMTP id l187mr27431386ywe.231.1444749342659;  Tue, 13 Oct 2015 08:15:42 -0700 (PDT)
Received: from [172.16.0.112] (pool-173-73-126-234.washdc.east.verizon.net. [173.73.126.234]) by smtp.gmail.com with ESMTPSA id q2sm2353925ywd.11.2015.10.13.08.15.41 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 13 Oct 2015 08:15:42 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <alpine.LRH.2.03.1510130931100.24000@tislabs.com>
Date: Tue, 13 Oct 2015 11:15:40 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <80E8F2DB-7297-444E-A56D-BCED3512AB52@sn3rd.com>
References: <alpine.LRH.2.03.1510130931100.24000@tislabs.com>
To: Sam Weiller <weiler@tislabs.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/1LyHFpcKS3f4LkqXqgnDmJJq_cQ>
Cc: sidr@ietf.org
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Oct 2015 15:15:45 -0000

Ah so I guess this one is informational so it could proceed without the =
waiting for all the refs, but I do think we can ask the RFC editor to =
hold it for at least the normative refs.  When progressing a block of =
drafts, there=92s always a bunch of tradeoffs to deal with: 1) Will the =
IESG be upset by having to read a couple of hundred pages, 2) What=92s =
the right order of the drafts to hit the IESG agenda, 3) Will we need to =
change something in the overview draft, etc.  I=92ve come to think that =
when the WG thinks a draft is done we should push it upstream and let =
them deal with it in the order that it comes.  We can let the IESG place =
discusses that hold the draft before it gets to the RFC editor based on =
whatever criteria they feel is appropriate, or the RFC editor can hold =
it because of their processes - basically we should get things off our =
plate ASAP so that we can focus on other things.  Obviously YMMV.

spt

On Oct 13, 2015, at 09:39, Samuel Weiler <weiler@tislabs.com> wrote:

> The doc cites a bunch of i-d's.  Under previous practice, that would =
have left it languishing in the RFC Editor queue waiting for the others. =
 If that were the practice now, I would suggest we hold it and release =
all of the docs as a group, which would permit later changes to this doc =
if needed.  I think current practice does allow citing i-d's (though =
version numbers need to be specified), but I'm wondering if we wouldn't =
be better off waiting.  This is the first BGPsec doc many will read - I =
would prefer to have it be correct and complete even if we make changes =
in the other docs along the way.
>=20
> Other than that, no issues with the doc - it's in good shape.
>=20
> Minor nits sent separately to the editors.
>=20
> -- Sam Weiler
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Tue Oct 13 11:06:54 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF51C1A0387 for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 11:06:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IXxEJP58UF5F for <sidr@ietfa.amsl.com>; Tue, 13 Oct 2015 11:06:46 -0700 (PDT)
Received: from ia-mailgw.apnic.net (ia-mailgw.apnic.net [IPv6:2001:dd8:a:851::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E6201A0379 for <sidr@ietf.org>; Tue, 13 Oct 2015 11:06:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date:cc: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=f5wuVn2ZOKPZlYFPxyFR9tE3RaipL5Wx4uYoESpJgRM=; b=6t3fENQWFlzlZnQgQdqAcFxSv08f21bG+f2MVFqH2mtFcSQxJLSAtYisKWN7di1CovqiOYRW2gxl5 ROH/fVcQiH5fnjY2YSE8LuHM4T3WbxInFnX/4DP6TRoN4i22tEulIUawerlTdwqJlMfxsWaYXb3M5H FMxxPEocvdv13RRc=
Received: from NXMDA2.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by ia-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS; Wed, 14 Oct 2015 04:07:23 +1000 (AEST)
Received: from dhcp148.potaroo.net (203.119.101.249) by NXMDA2.org.apnic.net (203.119.107.21) with Microsoft SMTP Server (TLS) id 14.1.218.12; Wed, 14 Oct 2015 04:09:37 +1000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <CALo9H1Yc9OF4eWchoOBspLsfZ4DZcUHtwVuRUCjjKutUFQasGw@mail.gmail.com>
Date: Wed, 14 Oct 2015 05:06:41 +1100
Content-Transfer-Encoding: quoted-printable
Message-ID: <6156E4B5-6306-4030-81E0-3AA1D8ECD7E1@apnic.net>
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com> <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net> <B04829F7-0065-4E8A-B8D1-677B23B092B1@apnic.net> <CALo9H1Yc9OF4eWchoOBspLsfZ4DZcUHtwVuRUCjjKutUFQasGw@mail.gmail.com>
To: Arturo Servin <arturo.servin@gmail.com>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/DJJbOIg34nms1XVAdkLVYRwzfFc>
Cc: Christopher Morrow <christopher.morrow@gmail.com>, Sandra Murphy <sandy@tislabs.com>, George Michaelson <ggm@apnic.net>, sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Oct 2015 18:06:54 -0000

I think that a standards track document that updates a specification
should be precisely and exactly that. Note that the document it updates
contains no rationale for its many design decisions.

This does not stop an informational document being published that =
contains
the discussion of the rationale for the change, but I think it better to =
keep
the desired change to the specification as succinct and as focussed as
possible

thanks,

  Geoff


> On 14 Oct 2015, at 12:27 AM, Arturo Servin <arturo.servin@gmail.com> =
wrote:
>=20
> Hi
>=20
> Something that I liked from =
draft-ietf-sidr-rpki-validation-reconsidered is that it explained very =
well why we need to change the validation process. Although it is not =
mandatory and I do not have a strong position about it, I think it would =
be good to add some context to this document of why the change.
>=20
> /as
>=20
>=20
> On Fri, 9 Oct 2015 at 18:25 Geoff Huston <gih@apnic.net> wrote:
> sorry - forgot to add the url for this draft - here tis:
>=20
>=20
> A new version of I-D, draft-huston-sidr-validity-00.txt
> has been successfully submitted by Geoff Huston and posted to the
> IETF repository.
>=20
> Name:           draft-huston-sidr-validity
> Revision:       00
> Title:          Update to RPKI Validation
> Document date:  2015-10-09
> Group:          Individual Submission
> Pages:          6
> URL:            =
https://www.ietf.org/internet-drafts/draft-huston-sidr-validity-00.txt
> Status:         =
https://datatracker.ietf.org/doc/draft-huston-sidr-validity/
> Htmlized:       =
https://tools.ietf.org/html/draft-huston-sidr-validity-00
>=20
>=20
> Abstract:
>   This document updates the RPKI certificate validation procedure as
>   specified in Section 7.2 of RFC6487.
>=20
>=20
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> The IETF Secretariat
>=20
>=20
>=20
> > On 9 Oct 2015, at 1:23 PM, Geoff Huston <gih@apnic.net> wrote:
> >
> > Hi,
> >
> > We were about to ask the WG chairs for a WG Last Call on this =
document, but then noticed that this is an informational document and =
its attempting to update a standards track RFC
> >
> > We suspect that the best case is to instead look at a precise =
standards track document that describes the update to the validation =
procedure described RFC6487 and would be a clear candidate for Standards =
Track itself.
> >
> > So draft-huston-sidr-validity-00.txt is that draft.
> >
> > WG Chairs:- We would like to request WG adoption of =
draft-huston-sidr-validity-00.txt, on the understanding that =
draft-ietf-sidr-rpki-validation-reconsidered has done its work and =
should be allowed to expire gracefully in a corner at this point!
> >
> >
> > regards,
> >
> >    Geoff & George
> >
> >
> >
> >
> >> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
> >>
> >>
> >> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> >> This draft is a work item of the Secure Inter-Domain Routing =
Working Group of the IETF.
> >>
> >>      Title           : RPKI Validation Reconsidered
> >>      Authors         : Geoff Huston
> >>                        George Michaelson
> >>                        Carlos M. Martinez
> >>                        Tim Bruijnzeels
> >>                        Andrew Lee Newton
> >>                        Alain Aina
> >>      Filename        : =
draft-ietf-sidr-rpki-validation-reconsidered-02.txt
> >>      Pages           : 12
> >>      Date            : 2015-10-09
> >>
> >> Abstract:
> >> This document reviews the certificate validation procedure =
specified
> >> in RFC6487 and highlights aspects of operational fragility in the
> >> management of certificates in the RPKI.
> >>
> >>
> >> The IETF datatracker status page for this draft is:
> >> =
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconside=
red/
> >>
> >> There's also a htmlized version available at:
> >> =
https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-0=
2
> >>
> >> A diff from the previous version is available at:
> >> =
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-recons=
idered-02
> >>
> >>
> >> Please note that it may take a couple of minutes from the time of =
submission
> >> until the htmlized version and diff are available at =
tools.ietf.org.
> >>
> >> Internet-Drafts are also available by anonymous FTP at:
> >> ftp://ftp.ietf.org/internet-drafts/
> >>
> >> _______________________________________________
> >> sidr mailing list
> >> sidr@ietf.org
> >> https://www.ietf.org/mailman/listinfo/sidr
> >
> > _______________________________________________
> > sidr mailing list
> > sidr@ietf.org
> > https://www.ietf.org/mailman/listinfo/sidr
> >
> > _______________________________________________
> > sidr mailing list
> > sidr@ietf.org
> > https://www.ietf.org/mailman/listinfo/sidr
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Wed Oct 14 05:21:17 2015
Return-Path: <rogaglia@cisco.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B18381A1B1D for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 05:21:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level: 
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id takI77eglI2d for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 05:21:14 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3ECB21A1B1C for <sidr@ietf.org>; Wed, 14 Oct 2015 05:20:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5924; q=dns/txt; s=iport; t=1444825252; x=1446034852; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=4Rc+ZQ4ioN0pbX7Y2uFVRih97D6AR+jOzwDNF7BJdsw=; b=TGn8gPc5ozgHAzPBcKZUSvw8rEFajd411oQIbS/HHS51FX/uvMZDRtIA MYw+HfnFx9HiyFRaEdpPZnduj8DUYhZMhmMu/cS5nqb6WCHCH4kTkCASD 0uQ3f29eQLkgN8E92kne9XEJjAj0mnakJ9oHE/NQ0cJz831ygu5VwaFlc k=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BhAgCVRx5W/4QNJK1egyZUbga9fQENgVoXDIJwggp/AoE8OBQBAQEBAQEBgQqEJwEBBAEBAWsLEAIBCA4KLiEGCyUCBAENBRuHfgMSDb1QDYR5AQEBAQEBAQEBAQEBAQEBAQEBAQEYhnaDeIEGglCCCjMHhC4FjQ6JBwGFGIYOgXSBWEiDco0wf4dIAR8BAUKEAnEBhSclHIEGAQEB
X-IronPort-AV: E=Sophos;i="5.17,681,1437436800"; d="scan'208";a="198006381"
Received: from alln-core-10.cisco.com ([173.36.13.132]) by alln-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 14 Oct 2015 12:20:51 +0000
Received: from XCH-RCD-011.cisco.com (xch-rcd-011.cisco.com [173.37.102.21]) by alln-core-10.cisco.com (8.14.5/8.14.5) with ESMTP id t9ECKoW0026422 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 14 Oct 2015 12:20:51 GMT
Received: from xch-aln-011.cisco.com (173.36.7.21) by XCH-RCD-011.cisco.com (173.37.102.21) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Wed, 14 Oct 2015 07:20:37 -0500
Received: from xch-aln-011.cisco.com ([173.36.7.21]) by XCH-ALN-011.cisco.com ([173.36.7.21]) with mapi id 15.00.1104.000; Wed, 14 Oct 2015 07:20:37 -0500
From: "Roque Gagliano (rogaglia)" <rogaglia@cisco.com>
To: Geoff Huston <gih@apnic.net>, Arturo Servin <arturo.servin@gmail.com>
Thread-Topic: [sidr] posted: draft-huston-sidr-validity-00.txt
Thread-Index: AQHRBnq7rZv1SEO+vUKM/9EElZN9JQ==
Date: Wed, 14 Oct 2015 12:20:37 +0000
Message-ID: <D24414DD.34006%rogaglia@cisco.com>
References: <20151009170650.4800.42354.idtracker@ietfa.amsl.com> <4FC98452-5859-4A7B-ABA2-9281CB27FC15@apnic.net> <B04829F7-0065-4E8A-B8D1-677B23B092B1@apnic.net> <CALo9H1Yc9OF4eWchoOBspLsfZ4DZcUHtwVuRUCjjKutUFQasGw@mail.gmail.com> <6156E4B5-6306-4030-81E0-3AA1D8ECD7E1@apnic.net>
In-Reply-To: <6156E4B5-6306-4030-81E0-3AA1D8ECD7E1@apnic.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.6.150930
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.228.32.165]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <34736C1470542246B549E103333C066A@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/zRP3nTxCC5FgbrTLryk51dQOyKI>
Cc: Christopher Morrow <christopher.morrow@gmail.com>, sidr wg list <sidr@ietf.org>, George Michaelson <ggm@apnic.net>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 12:21:16 -0000

Hi Geoff,

In many cases we publish an Appendix on update documents detailing the
changes from previous version and given the rational that Arturo mentioned.

Roque

=8B=20
Roque Gagliano
Tail-f Solutions Architect Southern Europe
+41 76 449 8867






On 13/10/15 20:06, "sidr on behalf of Geoff Huston" <sidr-bounces@ietf.org
on behalf of gih@apnic.net> wrote:

>I think that a standards track document that updates a specification
>should be precisely and exactly that. Note that the document it updates
>contains no rationale for its many design decisions.
>
>This does not stop an informational document being published that contains
>the discussion of the rationale for the change, but I think it better to
>keep
>the desired change to the specification as succinct and as focussed as
>possible
>
>thanks,
>
>  Geoff
>
>
>> On 14 Oct 2015, at 12:27 AM, Arturo Servin <arturo.servin@gmail.com>
>>wrote:
>>=20
>> Hi
>>=20
>> Something that I liked from
>>draft-ietf-sidr-rpki-validation-reconsidered is that it explained very
>>well why we need to change the validation process. Although it is not
>>mandatory and I do not have a strong position about it, I think it would
>>be good to add some context to this document of why the change.
>>=20
>> /as
>>=20
>>=20
>> On Fri, 9 Oct 2015 at 18:25 Geoff Huston <gih@apnic.net> wrote:
>> sorry - forgot to add the url for this draft - here tis:
>>=20
>>=20
>> A new version of I-D, draft-huston-sidr-validity-00.txt
>> has been successfully submitted by Geoff Huston and posted to the
>> IETF repository.
>>=20
>> Name:           draft-huston-sidr-validity
>> Revision:       00
>> Title:          Update to RPKI Validation
>> Document date:  2015-10-09
>> Group:          Individual Submission
>> Pages:          6
>> URL:           =20
>>https://www.ietf.org/internet-drafts/draft-huston-sidr-validity-00.txt
>> Status:        =20
>>https://datatracker.ietf.org/doc/draft-huston-sidr-validity/
>> Htmlized:      =20
>>https://tools.ietf.org/html/draft-huston-sidr-validity-00
>>=20
>>=20
>> Abstract:
>>   This document updates the RPKI certificate validation procedure as
>>   specified in Section 7.2 of RFC6487.
>>=20
>>=20
>>=20
>>=20
>> Please note that it may take a couple of minutes from the time of
>>submission
>> until the htmlized version and diff are available at tools.ietf.org.
>>=20
>> The IETF Secretariat
>>=20
>>=20
>>=20
>> > On 9 Oct 2015, at 1:23 PM, Geoff Huston <gih@apnic.net> wrote:
>> >
>> > Hi,
>> >
>> > We were about to ask the WG chairs for a WG Last Call on this
>>document, but then noticed that this is an informational document and
>>its attempting to update a standards track RFC
>> >
>> > We suspect that the best case is to instead look at a precise
>>standards track document that describes the update to the validation
>>procedure described RFC6487 and would be a clear candidate for Standards
>>Track itself.
>> >
>> > So draft-huston-sidr-validity-00.txt is that draft.
>> >
>> > WG Chairs:- We would like to request WG adoption of
>>draft-huston-sidr-validity-00.txt, on the understanding that
>>draft-ietf-sidr-rpki-validation-reconsidered has done its work and
>>should be allowed to expire gracefully in a corner at this point!
>> >
>> >
>> > regards,
>> >
>> >    Geoff & George
>> >
>> >
>> >
>> >
>> >> On 9 Oct 2015, at 1:06 PM, internet-drafts@ietf.org wrote:
>> >>
>> >>
>> >> A New Internet-Draft is available from the on-line Internet-Drafts
>>directories.
>> >> This draft is a work item of the Secure Inter-Domain Routing Working
>>Group of the IETF.
>> >>
>> >>      Title           : RPKI Validation Reconsidered
>> >>      Authors         : Geoff Huston
>> >>                        George Michaelson
>> >>                        Carlos M. Martinez
>> >>                        Tim Bruijnzeels
>> >>                        Andrew Lee Newton
>> >>                        Alain Aina
>> >>      Filename        :
>>draft-ietf-sidr-rpki-validation-reconsidered-02.txt
>> >>      Pages           : 12
>> >>      Date            : 2015-10-09
>> >>
>> >> Abstract:
>> >> This document reviews the certificate validation procedure specified
>> >> in RFC6487 and highlights aspects of operational fragility in the
>> >> management of certificates in the RPKI.
>> >>
>> >>
>> >> The IETF datatracker status page for this draft is:
>> >>=20
>>https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-validation-reconsid
>>ered/
>> >>
>> >> There's also a htmlized version available at:
>> >>=20
>>https://tools.ietf.org/html/draft-ietf-sidr-rpki-validation-reconsidered-
>>02
>> >>
>> >> A diff from the previous version is available at:
>> >>=20
>>https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-rpki-validation-recon=
si
>>dered-02
>> >>
>> >>
>> >> Please note that it may take a couple of minutes from the time of
>>submission
>> >> until the htmlized version and diff are available at tools.ietf.org.
>> >>
>> >> Internet-Drafts are also available by anonymous FTP at:
>> >> ftp://ftp.ietf.org/internet-drafts/
>> >>
>> >> _______________________________________________
>> >> sidr mailing list
>> >> sidr@ietf.org
>> >> https://www.ietf.org/mailman/listinfo/sidr
>> >
>> > _______________________________________________
>> > sidr mailing list
>> > sidr@ietf.org
>> > https://www.ietf.org/mailman/listinfo/sidr
>> >
>> > _______________________________________________
>> > sidr mailing list
>> > sidr@ietf.org
>> > https://www.ietf.org/mailman/listinfo/sidr
>>=20
>> _______________________________________________
>> sidr mailing list
>> sidr@ietf.org
>> https://www.ietf.org/mailman/listinfo/sidr
>
>_______________________________________________
>sidr mailing list
>sidr@ietf.org
>https://www.ietf.org/mailman/listinfo/sidr


From nobody Wed Oct 14 06:00:08 2015
Return-Path: <kent@bbn.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 52C371A1EF1 for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 06:00:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ypl71z2ypTYA for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 06:00:04 -0700 (PDT)
Received: from smtp.bbn.com (smtp.bbn.com [128.33.1.81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 762BC1A21B0 for <sidr@ietf.org>; Wed, 14 Oct 2015 06:00:04 -0700 (PDT)
Received: from ssh.bbn.com ([192.1.122.15]:42310 helo=COMSEC.fios-router.home) by smtp.bbn.com with esmtp (Exim 4.77 (FreeBSD)) (envelope-from <kent@bbn.com>) id 1ZmLf0-000MTJ-T3 for sidr@ietf.org; Wed, 14 Oct 2015 09:00:03 -0400
To: sidr <sidr@ietf.org>
From: Stephen Kent <kent@bbn.com>
Message-ID: <561E51D2.2030909@bbn.com>
Date: Wed, 14 Oct 2015 09:00:02 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/ZyvhHVIGxvlA6akvt93CT2Vz55c>
Subject: [sidr] new version of adverse actions I-D
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 13:00:07 -0000

This version has two major changes:

     - it includes text that describes the impact of each of the adverse 
actions,
       in the context of each RPKI repository object type. This text was 
added in
       response to a request fro Andrei.

     - the subsections have been re-ordered to be uniform for each 
object type,
       to make it easier to see that every action is described for each 
object type.
       In the course of doing this we discovered that four descriptions were
       missing, which shows how helpful the re-ordering is ;-).

Remember, the intent of this document is to enumerate the classes of 
problems that
can arise in the RPKI due to an error by (or a successful attack 
against) a CA or
repository manager. Concerns about full scale deployment of the RPKI 
have been
raised based on informal discussion of these sorts of issues, but we 
felt that a
more detailed, comprehensive analysis was needed. When the WG considers 
mechanisms
that might address such problems, we ought to compare them against this 
enumeration
(in its final form, based on WG feedback), to evaluate the extent to 
which the
mechanisms address the full range of problems.

https://datatracker.ietf.org/doc/draft-kent-sidr-adverse-actions/

WG feedback is solicited.

Thanks,

Steve


From nobody Wed Oct 14 08:02:26 2015
Return-Path: <weiler@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F42C1A923B for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 08:02:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LPCNHM4vtuKt for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 08:02:24 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 818A11A916C for <sidr@ietf.org>; Wed, 14 Oct 2015 08:02:24 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id D8B8728B0046 for <sidr@ietf.org>; Wed, 14 Oct 2015 11:02:23 -0400 (EDT)
Received: from nova.tislabs.com (nova.tislabs.com [10.66.1.77]) by nova.tislabs.com (Postfix) with ESMTP id B352E1F8035 for <sidr@ietf.org>; Wed, 14 Oct 2015 11:02:23 -0400 (EDT)
Date: Wed, 14 Oct 2015 11:02:23 -0400 (EDT)
From: Samuel Weiler <weiler@tislabs.com>
To: sidr@ietf.org
Message-ID: <alpine.LRH.2.03.1510131517100.32318@tislabs.com>
User-Agent: Alpine 2.03 (LRH 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format=flowed; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/YM_G7WTmopzWbMQUZI38JNg0kFQ>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 15:02:25 -0000

> We were about to ask the WG chairs for a WG Last Call on this document, 
> but then noticed that this is an informational document and its 
> attempting to update a standards track RFC

Changing the "intended status" of a doc seems easier than spinning a new 
one.  In any case, I would prefer to see the change and the context for it 
kept together.

Also, both/either document would benefit from a more meaningful abstract 
and intro.  At the very least, briefly explain _what_ is being changed. 
(The abstract and intro of the current WG doc hint at "why", but still 
don't say "what".  The new doc does neither.)

-- Sam


From nobody Wed Oct 14 13:01:30 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 768181A19FA for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 13:01:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lc6xyrAPVYz9 for <sidr@ietfa.amsl.com>; Wed, 14 Oct 2015 13:01:26 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 644111A21C2 for <sidr@ietf.org>; Wed, 14 Oct 2015 13:01:24 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 8C67128B0043 for <sidr@ietf.org>; Wed, 14 Oct 2015 16:01:23 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 6F51A1F8035; Wed, 14 Oct 2015 16:01:23 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_735FA91C-8712-4A7A-B8B9-E216C93F01E1"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Wed, 14 Oct 2015 16:00:10 -0400
Message-Id: <B013A8FB-6AD3-4F69-9CC8-8FBB166835C9@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/hIp9SR64SjVbHd_Wrc52_ZZJPOM>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] SKI collisions conversation closure
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 20:01:28 -0000

--Apple-Mail=_735FA91C-8712-4A7A-B8B9-E216C93F01E1
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

It appears the working group consensus is that a note should be made in =
the security consideration section that hash collisions can occur and =
that a relying party should notify the operators if any such collisions =
are discovered.

Could the authors please provide a new draft with such a security =
considerations section.

The two drafts draft-ietf-sidr-bgpsec-algs and =
draft-ietf-sidr-bgpsec-pki-profiles have been around for a long while.  =
The authors and chairs believe the drafts are ready for a working group =
last call, once a revised draft for draft-ietf-sidr-bgpsec-pki-profiles =
has been submitted.  So be aware and stay tuned.

=97Sandy, speaking as one of the wg co-chairs


--Apple-Mail=_735FA91C-8712-4A7A-B8B9-E216C93F01E1
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWHrRgAAoJEHplpQeet0IZoGYQAMhpBsWnfNg/P2yczooGFgRd
mo0h1l7HSkuds6y9o8Ko7My7roauyT4TgnhVkP41014rUnkTalEWUjiUe7fhEYC+
YRQeAsqJprUVUCEpPPOYaKT6ZpMCwzAc6nl3mjbqaXMvgJVVy3/FeqsOr3rq86sc
+UHglEoBbAsTCWfec6cj5oEZrWFxBN9fUGkmqzWXKrgTwcZurmFzR3c07UUcCO/j
GNMrqseTqEPExZwt1dgmsNKdb+MNmudCIXLk4dOwTXgazquHwa1NdYOU6aOu1Hmj
/LRl9xDv+Cie69FpC/AUz/HHK7+jSvB6vE5bW1mjOq+2AZdtHL675ZjK0qGEZJCY
pGUOGXlbfV+vk1YGAuij3YoLKd/pwMVBFOSbAGLvDbPWFcrA/o005OtFBloTIWdP
AthdYxk4iH6Yzx38ZZ+q/RyuWiIxwPLcAqhY0Br+AcpVA3f3vuTpQJ8dkKvmpvd8
lK303qqEJ/7A+dIEZjEotgYjOvnGefHz621JIOukCPn0M6jS2yoL7WjLUuGxlxX2
OfoexNroEbH4Or92bfmKO195C25r54HHAICWcUbWj4Cfc2RqG1N6pJwTH8A7hC6G
eVz4J417yfM2NeHTZ4ATBYuV6816LWr1PZ2H1vMcrLN+ajiO8h2XI0mGFaiGHEZs
fvX7yuLYJUc8Ocx84CFv
=v7a+
-----END PGP SIGNATURE-----

--Apple-Mail=_735FA91C-8712-4A7A-B8B9-E216C93F01E1--


From nobody Wed Oct 14 14:25:41 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 502EE1A8969; Wed, 14 Oct 2015 14:25:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.664
X-Spam-Level: *
X-Spam-Status: No, score=1.664 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FH_RELAY_NODNS=1.451, HELO_EQ_MODEMCABLE=0.768, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IMw4GFaHQs_W; Wed, 14 Oct 2015 14:25:37 -0700 (PDT)
Received: from cdcipgw01.twcable.com (unknown [165.237.91.110]) by ietfa.amsl.com (Postfix) with ESMTP id 7FA501A8961; Wed, 14 Oct 2015 14:25:36 -0700 (PDT)
X-SENDER-IP: 10.64.163.149
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,682,1437451200"; d="scan'208";a="418476397"
Received: from unknown (HELO exchpapp08.corp.twcable.com) ([10.64.163.149]) by cdcipgw01.twcable.com with ESMTP/TLS/AES256-SHA; 14 Oct 2015 17:18:32 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp08.corp.twcable.com (10.64.163.149) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Wed, 14 Oct 2015 17:25:34 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Wed, 14 Oct 2015 17:25:34 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: Chris Morrow <morrowc@ops-netman.net>, "sidr-chairs@ietf.org" <sidr-chairs@ietf.org>, "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
Thread-Index: AQHRBsbcSHTgZniRgUuZ9gXNgaBt3g==
Date: Wed, 14 Oct 2015 21:25:34 +0000
Message-ID: <D2442A8C.6CE45%wesley.george@twcable.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net>
In-Reply-To: <yj9osi5mae4p.wl%morrowc@ops-netman.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.7.151005
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.240]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21880.001
x-tm-as-result: No--46.741800-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <F503DE8AFDC0574390264BCF8E0BFB7D@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/q3b5eL1pEjQQBzj6xgiMyZMA1GM>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 21:25:39 -0000

R2F2ZSB0aGlzIGEgcmV2aWV3LCBhbmQgc3R1bWJsZWQgYWNyb3NzIGFuIGlzc3VlIHRoYXQgbWF5
IG5vdCBuZWNlc3NhcmlseQ0KYmUgZ2F0aW5nIHRvIHRoaXMgZHJhZnQsIGJ1dCBzaG91bGQgcHJv
YmFibHkgYmUgYWRkcmVzc2VkIGluIHNvbWUgb3RoZXINCmRyYWZ0cy4NCg0KUmVnYXJkaW5nIHRo
aXMgdGV4dCBpbiA0LjI6DQoiQWRkaXRpb25hbGx5LCBCR1BzZWMgcmVxdWlyZXMgdGhhdCBhbGwg
QkdQc2VjIHNwZWFrZXJzIHdpbGwgc3VwcG9ydA0KICAgNC1ieXRlIEFTIE51bWJlcnMgW1JGQzY3
OTNdLiBUaGlzIGlzIGJlY2F1c2UgdGhlIGNvLWV4aXN0ZW5jZQ0KICAgc3RyYXRlZ3kgZm9yIDQt
Ynl0ZSBBUyBudW1iZXJzIGFuZCBsZWdhY3kgMi1ieXRlIEFTIHNwZWFrZXJzIHRoYXQNCiAgIGdp
dmVzIHNwZWNpYWwgbWVhbmluZyB0byBBUyAyMzQ1NiBpcyBpbmNvbXBhdGlibGUgd2l0aCB0aGUg
c2VjdXJpdHkNCiAgIHRoZSBzZWN1cml0eSBwcm9wZXJ0aWVzIHRoYXQgQkdQc2VjIHNlZWtzIHRv
IHByb3ZpZGUuIg0KDQpOaXQ6ICJ0aGUgc2VjdXJpdHkiIGFwcGVhcnMgdG8gYmUgZHVwbGljYXRl
ZC4NCg0KU3Vic3RhbnRpdmU6IEkgaGFkIHRvIHRoaW5rIHRocm91Z2ggdGhpcyBmb3IgYSBiaXQg
dG8gbWFrZSBzdXJlIEkNCnVuZGVyc3Rvb2Qgd2h5IHRoaXMgaXMgdHJ1ZSBiZXlvbmQgdGhlIG9i
dmlvdXMgcHJvYmxlbSBvZiBBUzIzNDU2IG5vdA0KYmVpbmcgdW5pcXVlLiBJIHRoaW5rIHdlIG5l
ZWQgc29tZSBhZGRpdGlvbmFsIHdvcmRzIGV4cGxhaW5pbmcgd2h5LCB0aG91Z2gNCkkgYW0gbm90
IHN1cmUgaWYgaXQgYmVsb25ncyBoZXJlLCBpbiB0aGUgcHJvdG9jb2wgZHJhZnQsIG9yIGluIHNy
aXJhbSdzDQpkZXNpZ24tY2hvaWNlcyBkb2MgKDcuNiBpcyB2ZXJ5IHRoaW4gb24gZXhwbGFuYXRp
b24pLiBJIHRoaW5rIHRoYXQgdGhpcyBpcw0KYSBzcGVjaWZpYyBjb3JuZXIgY2FzZSBmb3IgdGhl
IG1vcmUgZ2VuZXJpYyBjYXNlIG9mIGluY3JlbWVudGFsDQpkZXBsb3ltZW50LCB3aGVyZSBhIGdp
dmVuIHBhdGggaGFzIHNvbWUgcm91dGVycy9BU05zIHRoYXQgc3VwcG9ydCBCR1BTZWMNCmFuZCBz
b21lIHRoYXQgZG8gbm90LCBhbmQgYXMgZmFyIGFzIEkgY2FuIHRlbGwsIGluY3JlbWVudGFsIGRl
cGxveW1lbnQNCmlzbid0IHJlYWxseSBkaXNjdXNzZWQgYXMgYSBjb25jZXB0IGJleW9uZCB0aGUg
W25vbl1uZWdvdGlhdGlvbiBvZiBzdXBwb3J0DQpiZXR3ZWVuIHBlZXJzLg0KDQpXaGVuIGEgQkdQ
U2VjLWNhcGFibGUgcm91dGVyIHNlbmRzIHVwZGF0ZXMgdG8gYSBub24tY2FwYWJsZSBwZWVyLCBp
dA0Kc3RyaXBzIHRoZSBCR1BTRUNfUGF0aCBhdHRyaWJ1dGUgZnJvbSBhbnkgQkdQU2VjLXByb3Rl
Y3RlZCByb3V0ZXMgaXQgaXMNCnByb3BhZ2F0aW5nIGFuZCBhbm5vdW5jZXMgYSByZWd1bGFyIEFT
X1BBVEgsIGFuZCB0aGVyZWZvcmUgYW55IHByb3RlY3Rpb24NCmJleW9uZCB0aGF0IHBvaW50IGlz
IGxvc3QuDQpTZWN0aW9uIDQuMiBvZiB0aGUgcHJvdG9jb2wgZG9jIHNheXMgdGhhdCBpZiBhIEJH
UFNlYy1jYXBhYmxlIHJvdXRlcg0KcmVjZWl2ZXMgdXBkYXRlcyBmcm9tIGEgbm9uLUJHUFNlYyBw
ZWVyLCBpdCB3aWxsIG5vdCBzaWduIHRob3NlIHVwZGF0ZXMNCndoZW4gcHJvcGFnYXRpbmcgdGhl
bSB0byBvdGhlciBCR1BTZWMtY2FwYWJsZSBwZWVycy4gQXMgYSByZXN1bHQsIHRoYXQNCnJvdXRl
J3MgcGF0aCB3aWxsIG5vdCBiZSBwcm90ZWN0ZWQgYXQgYWxsLiBIb3dldmVyLCBJIGNvdWxkbid0
IGZpbmQgdGhhdA0KcGFydGljdWxhciBzZXQgb2YgaW50ZXJhY3Rpb25zIGRpc2N1c3NlZCBpbiBh
bnkgb2YgdGhlIGRvY3VtZW50cyBpbiB0aGUNCmNvbnRleHQgb2YgaW5jcmVtZW50YWwgZGVwbG95
bWVudCwgYW5kIHdoYXQgaXQgY2FuIGFuZCBjYW5ub3QgZG8gdG8NCnByb3RlY3QgZGlmZmVyZW50
IHJvdXRlIGFubm91bmNlbWVudHMuDQoNCkluIG90aGVyIHdvcmRzLCBCR1BTZWMgc3VwcG9ydHMg
c2VjdXJpbmcgdGhlIHBhdGggd2hlbjoNCi0gQWxsIHJvdXRlcnMgZW5kIHRvIGVuZCBzdXBwb3J0
IEJHUFNlYywgd2hpY2ggcmVzdWx0cyBpbiB0aGUgZW50aXJlIHBhdGgNCmJlaW5nIHByb3RlY3Rl
ZC4NCi0gVGhlIG9yaWdpbmF0aW5nIHJvdXRlciBhbmQgb25lIG9yIG1vcmUgY29udGlndW91cyBy
b3V0ZXJzIChBU05zKSBpbiB0aGUNCmRvd25zdHJlYW0gcGF0aCBzdXBwb3J0IEJHUFNlYywgYnV0
IG9uZSBvciBtb3JlIHJvdXRlcnMgYmVmb3JlIHRoZSByb3V0ZSdzDQpmaW5hbCBkZXN0aW5hdGlv
biBkbyBub3Qgc3VwcG9ydCBpdC4gVGhpcyByZXN1bHRzIGluIHRoZSBCR1BTZWMgc2lnbmF0dXJl
cw0KYmVpbmcgc3RyaXBwZWQgYW5kIGZhbGxpbmcgYmFjayB0byBpbnNlY3VyZSBtb2RlIGJleW9u
ZCB0aGUgbGFzdA0KY29udGlndW91cyBCR1BTZWMtY2FwYWJsZSByb3V0ZXIsIGJ1dCBzdGlsbCBw
cm92aWRlcyBwYXJ0aWFsIHByb3RlY3Rpb24NCnRocm91Z2ggdGhlIHBvcnRpb24gb2YgdGhlIHBh
dGggdGhhdCBpcyBCR1BTZWMtY2FwYWJsZS4gVGhpcyBpcyB0cnVlIGV2ZW4NCndoZW4gYSBnYXAg
b2Ygb25lIG9yIG1vcmUgQkdQU2VjLWluY2FwYWJsZSByb3V0ZXJzIGV4aXN0cyBpbiB0aGUgbWlk
ZGxlLA0KZm9sbG93ZWQgYnkgYWRkaXRpb25hbCBCR1BTZWMtY2FwYWJsZSByb3V0ZXJzLCBhcyBv
bmx5IHRoZSBmaXJzdCBwYXJ0IHdpbGwNCmJlIHNlY3VyZWQuDQoNCkJHUFNlYyBkb2VzICpub3Qq
IHN1cHBvcnQgc2VjdXJpbmcgdGhlIHBhdGggZXZlbiBwYXJ0aWFsbHkgd2hlbjoNCi0gVGhlIG9y
aWdpbmF0aW5nIHJvdXRlciBhbmQgb25lIG9yIG1vcmUgcm91dGVycyBpbiB0aGUgZG93bnN0cmVh
bSBwYXRoIGRvDQpub3Qgc3VwcG9ydCBCR1BTZWMsIGJ1dCBzZW5kIHRoZSB1cGRhdGUgdG8gcm91
dGVyKHMpIHRoYXQgZG8gc3VwcG9ydA0KQkdQU2VjLg0KSS5lLiBUaGVyZSBpcyBubyBtb2RlbCBp
biBCR1BTZWMgZm9yIHVwZGF0ZXMgdGhhdCBoYXZlIFt1bnNpZ25lZCBBU19QQVRIDQpvZiBvbmUg
b3IgbW9yZSBBU05zXSArIFtTaWduZWQgQkdQU2VjX1BhdGhdIG9mIG9uZSBvciBtb3JlIGFkZGl0
aW9uYWwgQVNOcw0KdG8gYXQgbGVhc3Qgc2VjdXJlIHRoZSBwYXJ0IG9mIHRoZSBwYXRoIHdoZXJl
IEJHUFNlYyBpcyBzdXBwb3J0ZWQuDQpTbyB5b3UgY2FuIGdyb3cgQkdQU2VjJ3MgY2hhaW4gb2Yg
cHJvdGVjdGlvbiBmcm9tIG9yaWdpbiB0byAibWlkZGxlIiBhbmQNCmdhaW4gc29tZSBpbmNyZW1l
bnRhbCBiZW5lZml0IGFjcm9zcyB0aGUgcGFydCBvZiB0aGUgcGF0aCB0aGF0IHN1cHBvcnRzDQpC
R1BTZWMsIGJ1dCB5b3UgY2Fubm90IGdyb3cgQkdQU2VjJ3MgY2hhaW4gb2YgcHJvdGVjdGlvbiBm
cm9tICJtaWRkbGUiIHRvDQplbmQgYW5kIGdhaW4gdGhlIHNhbWUgaW5jcmVtZW50YWwgYmVuZWZp
dCwgZXZlbiBpbiB0aGUgY2FzZSB3aGVyZSBvbmx5IHRoZQ0Kb3JpZ2luYXRpbmcgcm91dGVyIGRv
ZXNuJ3Qgc3VwcG9ydCBCR1BTZWMgYnV0IHRoZSByZXN0IG9mIHRoZSBwYXRoIGRvZXMuIEkNCnRo
aW5rIEkgdW5kZXJzdGFuZCB0aGUgcmVhc29ucyB3aHkgd2UgY2hvc2Ugbm90IHRvIGFsbG93IHRo
aXMgY2FzZSwgYnV0IEkNCmRvbid0IGtub3cgdGhhdCB0aGlzIGlzIGRpc2N1c3NlZCBhbnl3aGVy
ZSBpbiB0aGVzZSB0ZXJtcy4gVGhlcmUgaXMgYQ0KZGlzY3Vzc2lvbiBpbiA2LjQgb2YgU3JpcmFt
J3MgZGVzaWduLWNob2ljZXMgZG9jLCBidXQgSSB0aGluayBpdCdzDQppbmNvbXBsZXRlIHNpbmNl
IGl0IG9ubHkgZGlzY3Vzc2VzIGl0IGluIHRlcm1zIG9mIGl0IGJlaW5nIHVuYWNjZXB0YWJsZSB0
bw0Kc2lnbiB1cGRhdGVzIHRoYXQgaXQgY2FuJ3QgdmVyaWZ5LiBJTU8gdGhlcmUncyBhIGRpZmZl
cmVuY2UgYmV0d2Vlbg0Kc2lnbmluZyBhbiB1bnNpZ25lZCB1cGRhdGUgYW5kIGNhcnJ5aW5nIHVu
c2lnbmVkIHVwZGF0ZXMgYWxvbmdzaWRlIHNpZ25lZA0Kb25lcyBzbyB0aGF0IGl0IGlzIGNsZWFy
IHdoaWNoIHBhcnQgb2YgdGhlIHBhdGggaXMgcmlnb3JvdXNseSBwcm90ZWN0ZWQgdnMNCm5vdC4g
UHV0IGRpZmZlcmVudGx5OiAiSSBoYXZlIG5vIGlkZWEgd2hldGhlciB0aGUgcGVvcGxlIGJlZm9y
ZSBSYW5keSB3ZXJlDQp0ZWxsaW5nIHRoZSB0cnV0aCwgYnV0IEkgY2FuIGFzc2VydCB0aGF0IFJh
bmR5LCBTYW5keSwgQ2hyaXMsIE1hdHQsIGFuZA0KUm9iIGFsbCB2ZXJpZmlhYmx5IHRvbGQgdGhl
IHRydXRoIGFib3V0IHRoZWlyIHBhcnQgb2YgdGhlIHBhdGggd2hlbiB0aGV5DQpzZW50IHRoZSBy
b3V0ZSB0byBtZS4iIEkgdGhpbmsgbWF5YmUgdGhhdCBoYXMgc29tZSB2YWx1ZSBpbiBhbiBpbmNy
ZW1lbnRhbA0KbW9kZWwsIGJ1dCBpZiBpdCBkb2Vzbid0IChvciBpcyBzdWZmaWNpZW50bHkgZGlm
ZmljdWx0IHRvIGltcGxlbWVudCBhcyB0bw0KbmVnYXRlIHRoZSBwb3RlbnRpYWwgYmVuZWZpdCks
IHdlIHNob3VsZCBleHBsYWluIHdoeS4NCg0KVGhhbmtzLA0KDQpXZXMNCg0KDQoNCk9uIDEwLzcv
MTUsIDExOjMyIEFNLCAic2lkciBvbiBiZWhhbGYgb2YgQ2hyaXMgTW9ycm93Ig0KPHNpZHItYm91
bmNlc0BpZXRmLm9yZyBvbiBiZWhhbGYgb2YgbW9ycm93Y0BvcHMtbmV0bWFuLm5ldD4gd3JvdGU6
DQoNCj4NCj5Ib3dkeSBXRyBmb2xrcywNCj5QbGVhc2UgY29uc2lkZXIgdGhpcyB5b3VyIHdhcm5p
bmcvbm90aWNlIHRoYXQgdGhlIFdHTEMgaGFzIGJlZW4gc3RhcnRlZA0KPmZvcjoNCj4NCj4gIGRy
YWZ0LWlldGYtc2lkci1iZ3BzZWMtb3ZlcnZpZXcNCj4NCj5BYnN0cmFjdDoNCj4gICJUaGlzIGRv
Y3VtZW50IHByb3ZpZGVzIGFuIG92ZXJ2aWV3IG9mIGEgc2VjdXJpdHkgZXh0ZW5zaW9uIHRvIHRo
ZQ0KPiAgIEJvcmRlciBHYXRld2F5IFByb3RvY29sIChCR1ApIHJlZmVycmVkIHRvIGFzIEJHUHNl
Yy4gIEJHUHNlYyBpbXByb3Zlcw0KPiAgIHNlY3VyaXR5IGZvciBCR1Agcm91dGluZy4iDQo+DQo+
UGxlYXNlIGdpdmUgdGhpcyBhIHJlYWQsIHNlbmQgY29tbWVudHMgaWYgdGhlcmUgYXJlIGFueSwg
YW5kIGxldCB1cw0KPmtub3cgaWYgdGhpcyBpcyBwcmVwYXJlZCBmb3IgcHVibGljYXRpb24gcmVx
dWVzdC4NCj4NCj5UaGFua3MhDQo+DQo+LWNocmlzDQo+Y28tY2hhaXINCj4NCj5fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KPnNpZHIgbWFpbGluZyBsaXN0
DQo+c2lkckBpZXRmLm9yZw0KPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8v
c2lkcg0KDQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQoNClRoaXMgRS1tYWls
IGFuZCBhbnkgb2YgaXRzIGF0dGFjaG1lbnRzIG1heSBjb250YWluIFRpbWUgV2FybmVyIENhYmxl
IHByb3ByaWV0YXJ5IGluZm9ybWF0aW9uLCB3aGljaCBpcyBwcml2aWxlZ2VkLCBjb25maWRlbnRp
YWwsIG9yIHN1YmplY3QgdG8gY29weXJpZ2h0IGJlbG9uZ2luZyB0byBUaW1lIFdhcm5lciBDYWJs
ZS4gVGhpcyBFLW1haWwgaXMgaW50ZW5kZWQgc29sZWx5IGZvciB0aGUgdXNlIG9mIHRoZSBpbmRp
dmlkdWFsIG9yIGVudGl0eSB0byB3aGljaCBpdCBpcyBhZGRyZXNzZWQuIElmIHlvdSBhcmUgbm90
IHRoZSBpbnRlbmRlZCByZWNpcGllbnQgb2YgdGhpcyBFLW1haWwsIHlvdSBhcmUgaGVyZWJ5IG5v
dGlmaWVkIHRoYXQgYW55IGRpc3NlbWluYXRpb24sIGRpc3RyaWJ1dGlvbiwgY29weWluZywgb3Ig
YWN0aW9uIHRha2VuIGluIHJlbGF0aW9uIHRvIHRoZSBjb250ZW50cyBvZiBhbmQgYXR0YWNobWVu
dHMgdG8gdGhpcyBFLW1haWwgaXMgc3RyaWN0bHkgcHJvaGliaXRlZCBhbmQgbWF5IGJlIHVubGF3
ZnVsLiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzIEUtbWFpbCBpbiBlcnJvciwgcGxlYXNlIG5v
dGlmeSB0aGUgc2VuZGVyIGltbWVkaWF0ZWx5IGFuZCBwZXJtYW5lbnRseSBkZWxldGUgdGhlIG9y
aWdpbmFsIGFuZCBhbnkgY29weSBvZiB0aGlzIEUtbWFpbCBhbmQgYW55IHByaW50b3V0Lg0K


From nobody Wed Oct 14 15:38:06 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0FAE1B2A65; Wed, 14 Oct 2015 15:38:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A_UdctyX5sVJ; Wed, 14 Oct 2015 15:38:04 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id E2D7B1B2A77; Wed, 14 Oct 2015 15:38:02 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151014223802.2351.24407.idtracker@ietfa.amsl.com>
Date: Wed, 14 Oct 2015 15:38:02 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/jWG6S7f_rij6QwaXnX-XkbnuBJ0>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-bgpsec-pki-profiles-12.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 22:38:06 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests
        Authors         : Mark Reynolds
                          Sean Turner
                          Steve Kent
	Filename        : draft-ietf-sidr-bgpsec-pki-profiles-12.txt
	Pages           : 13
	Date            : 2015-10-14

Abstract:
   This document defines a standard profile for X.509 certificates for
   the purposes of supporting validation of Autonomous System (AS) paths
   in the Border Gateway Protocol (BGP), as part of an extension to that
   protocol known as BGPsec.  BGP is a critical component for the proper
   operation of the Internet as a whole.  The BGPsec protocol is under
   development as a component to address the requirement to provide
   security for the BGP protocol.  The goal of BGPsec is to design a
   protocol for full AS path validation based on the use of strong
   cryptographic primitives.  The end-entity (EE) certificates specified
   by this profile are issued under Resource Public Key Infrastructure
   (RPKI) Certification Authority (CA) certificates, containing the AS
   Identifier Delegation extension, to routers within the Autonomous
   System (AS) or ASes.  The certificate asserts that the router(s)
   holding the private key are authorized to send out secure route
   advertisements on behalf of the specified AS(es).  This document also
   profiles the Certificate Revocation List (CRL), profiles the format
   of certification requests, and specifies Relying Party certificate
   path validation procedures.  The document extends the RPKI;
   therefore, this documents updates the RPKI Resource Certificates
   Profile (RFC 6487).


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-bgpsec-pki-profiles/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-bgpsec-pki-profiles-12

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-bgpsec-pki-profiles-12


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed Oct 14 16:21:08 2015
Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C4411A1A33; Wed, 14 Oct 2015 16:21:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4tgXeg_GwWEv; Wed, 14 Oct 2015 16:21:02 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0794.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::794]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0BA251A1A15; Wed, 14 Oct 2015 16:21:01 -0700 (PDT)
Received: from CY1PR09MB0793.namprd09.prod.outlook.com (10.163.43.143) by CY1PR09MB0793.namprd09.prod.outlook.com (10.163.43.143) with Microsoft SMTP Server (TLS) id 15.1.300.14; Wed, 14 Oct 2015 23:20:43 +0000
Received: from CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) by CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) with mapi id 15.01.0300.010; Wed, 14 Oct 2015 23:20:43 +0000
From: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>
To: "George, Wes" <wesley.george@twcable.com>, Chris Morrow <morrowc@ops-netman.net>, "sidr-chairs@ietf.org" <sidr-chairs@ietf.org>, "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
Thread-Index: AQHRBsbkap7SgdO4QkCreBatmHEYy55rixDg
Date: Wed, 14 Oct 2015 23:20:42 +0000
Message-ID: <CY1PR09MB079361CBE768BE1B62DBCAEA843F0@CY1PR09MB0793.namprd09.prod.outlook.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <D2442A8C.6CE45%wesley.george@twcable.com>
In-Reply-To: <D2442A8C.6CE45%wesley.george@twcable.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=kotikalapudi.sriram@nist.gov; 
x-originating-ip: [129.6.140.100]
x-microsoft-exchange-diagnostics: 1; CY1PR09MB0793; 5:FwFb2EJEG3aax1C4OmROA4vvrXUH+yULCPyRUjJDpk46gWrXvPF5AWb/xLmzzDarxRNUJiyalC8fti/uMzebsntw9bJd7D7tf/NKdCb+mxIMhKgb4ohpRQlajdtBH2c9NkDX548Zfawtl1YWV2t5LQ==; 24:zS4n0y3UMyEtkwORcFwpJ8AqNOFXVOG75SoQigQ1C3iwf/jNWjACIHmSlt04BpjNzvg8WZwLHtLqhfFWu/TVU8Q5hSTb14VceUMettNJSCg=; 20:U0dz6g4Ry+PWg/rgrU6cWe7f4iF4WkOzVRncZgsdiImEx/+RT0k7y1DHgcx/st8KM2y83dUudlgMbZhmUBe5rA==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:CY1PR09MB0793;
x-microsoft-antispam-prvs: <CY1PR09MB0793DD1382F1FF7608CAA767843F0@CY1PR09MB0793.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(520078)(5005006)(8121501046)(3002001); SRVR:CY1PR09MB0793; BCL:0; PCL:0; RULEID:; SRVR:CY1PR09MB0793; 
x-forefront-prvs: 0729050452
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(199003)(5423002)(189002)(51444003)(122556002)(76576001)(11100500001)(81156007)(5004730100002)(5002640100001)(101416001)(189998001)(86362001)(5001960100002)(2501003)(107886002)(230783001)(76176999)(54356999)(5007970100001)(50986999)(40100003)(2900100001)(102836002)(2950100001)(5001770100001)(77096005)(92566002)(5008740100001)(97736004)(10400500002)(64706001)(87936001)(66066001)(46102003)(106116001)(105586002)(74316001)(99286002)(2201001)(106356001)(33656002)(5003600100002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR09MB0793; H:CY1PR09MB0793.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Oct 2015 23:20:42.9055 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR09MB0793
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/cRXmbV0j5B603Y-NsoJrwOdMvwk>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 23:21:06 -0000

>I think that this is a specific corner case for the more generic case of i=
ncremental=20
>deployment, where a given path has some routers/ASNs that support BGPSec=20
>and some that do not, and as far as I can tell, incremental deployment isn=
't really=20
>discussed as a concept beyond the [non]negotiation of support between peer=
s.

We did talk about the concept of BGPsec islands in [draft-sriram-bgpsec-des=
ign-choices].

"6.3.2.  Discussion

   During partial deployment, there will be BGPSEC islands as a result
   of this approach to incremental deployment.  Updates that originate
   within a BGPSEC island will generally propagate with signed AS paths
   to the edges of that island."

A natural consequence of the [non]negotiation of support between peers,
is the formation of BGPsec islands.=20
That is indeed how incremental deployment would look like.
We should expand on the discussion there to add that as BGPsec adoption gro=
ws,
the islands will expand outward (subsuming non-BGPsec portions of the Inter=
net)
and/or pairs of islands may join together to form larger BGPsec islands.  =
=20

>There is a discussion in 6.4 of Sriram's design-choices doc, but I think i=
t's incomplete=20
>since it only discusses it in terms of it being unacceptable to sign updat=
es that it can't verify.

"unacceptable to sign updates that it can't verify" -- I don't read that in=
 Section 6.4.=20

"6.4.1.  Decision

   It was decided that partial path signing in BGPSEC will not be
   allowed.  A BGPSEC update must be fully signed, i.e., each AS in the
   AS-PATH must sign the update.  So in a signed update there must be a
   signature corresponding each AS in the AS path."

>Put differently: "I have no idea whether the people before Randy were=20
>telling the truth, but I can assert that Randy, Sandy, Chris, Matt, and Ro=
b=20
>all verifiably told the truth about their part of the path when they=20
>sent the route to me." I think maybe that has some value in an incremental=
 model,=20
>but if it doesn't (or is sufficiently difficult to implement as to=20
>negate the potential benefit), we should explain why.

The AS that you named Randy could be a bad actor,
and may have changed the AS path segment before it=20
(dropped some ASes, reduced AS prepends, etc.).
Imagine Rob receives another update for the same NLRI that is completely un=
signed,
and it has a path via Wes, Chris, and Jeff.
Let us say both updates pass origin validation.=20
Should Rob trust the partially-singed update via Randy, Sandy, Chris, and  =
Matt,
or should he trust the completely unsigned latter update?
If Rob gives priority to partially-signed path over completely unsigned pat=
h,
there is potential for trouble (as in the example above).
Then what is the use of partially signed updates?=20
That the was kind of reasoning why the design decision was made not to allo=
w
partially signed paths. This reasoning is outlined in Section 6.4.2 of the=
=20
design choices doc, but certainly the explanation can be further improved.

Thank you.

Sriram


From nobody Thu Oct 15 02:30:12 2015
Return-Path: <arturo.servin@gmail.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EBD01A92B4 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 02:30:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vFah5CcglAsf for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 02:30:08 -0700 (PDT)
Received: from mail-wi0-x22f.google.com (mail-wi0-x22f.google.com [IPv6:2a00:1450:400c:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 88A471A92B5 for <sidr@ietf.org>; Thu, 15 Oct 2015 02:30:08 -0700 (PDT)
Received: by wijp11 with SMTP id p11so20026257wij.0 for <sidr@ietf.org>; Thu, 15 Oct 2015 02:30:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :content-type; bh=SY30p8z2aOVeIwMwz4Uc7qI2kAb7nK2r8mNIZrtWKA4=; b=gMHxpKkLZlUdyqqZ+7JWgjc9hFPbKK3IyFOHYC9KlPTPIUNaQwsdiC/hWMso5P9RWq F9smScVsHxc9XvkFMkhqCmmM46w6V+mXCQceS5lgGFCi1fM2lqrkoEXIsrCUYAcpe2MI tBUldh1aBBJzh/zY3KYqUzKtFyQbSAEYFXNsgcvFecr7YCI0XDgdiFa6hDEiiSyNMv8b fzX2TqKjwyF3Y5ZbV296NS2RV0heg9pmiBwAbVh6nc3B+q1pJBp4bd0jXBRXmHTJAA68 YLU1PueL+op5nwoH0pYEBie3+zMI1rFqOkjfBHVplQV0FNoJoRpr+l3LLuZEQhYXkZEQ n6dQ==
X-Received: by 10.194.205.229 with SMTP id lj5mr9321761wjc.57.1444901407160; Thu, 15 Oct 2015 02:30:07 -0700 (PDT)
MIME-Version: 1.0
References: <alpine.LRH.2.03.1510131517100.32318@tislabs.com>
In-Reply-To: <alpine.LRH.2.03.1510131517100.32318@tislabs.com>
From: Arturo Servin <arturo.servin@gmail.com>
Date: Thu, 15 Oct 2015 09:29:57 +0000
Message-ID: <CALo9H1Z2BLWHaie-L8Hn_BJTX8SwtJLUfB_NPiy=6bkYja5g7g@mail.gmail.com>
To: Samuel Weiler <weiler@tislabs.com>, sidr@ietf.org
Content-Type: multipart/alternative; boundary=047d7ba984b81bff1c0522215303
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/BTEr3OUxK_UZAkFEUnJa_w0t6A8>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 09:30:10 -0000

--047d7ba984b81bff1c0522215303
Content-Type: text/plain; charset=UTF-8

As I mentioned, I do not have a strong position but I think that is
important to have the record of why we are changing this.

It could be something very simply in the intro of the current document, an
appendix or it could be a separate one.

-as

On Wed, 14 Oct 2015 at 16:02 Samuel Weiler <weiler@tislabs.com> wrote:

> > We were about to ask the WG chairs for a WG Last Call on this document,
> > but then noticed that this is an informational document and its
> > attempting to update a standards track RFC
>
> Changing the "intended status" of a doc seems easier than spinning a new
> one.  In any case, I would prefer to see the change and the context for it
> kept together.
>
> Also, both/either document would benefit from a more meaningful abstract
> and intro.  At the very least, briefly explain _what_ is being changed.
> (The abstract and intro of the current WG doc hint at "why", but still
> don't say "what".  The new doc does neither.)
>
> -- Sam
>
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr
>

--047d7ba984b81bff1c0522215303
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div>As I mentioned, I do not have a strong position b=
ut I think that is important to have the record of why we are changing this=
.=C2=A0</div><div><br></div><div>It could be something very simply in the i=
ntro of the current document, an appendix or it could be a separate one.=C2=
=A0</div><div><br></div><div><span style=3D"line-height:1.5">-as</span><br>=
</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Wed, 14 Oct =
2015 at 16:02 Samuel Weiler &lt;<a href=3D"mailto:weiler@tislabs.com">weile=
r@tislabs.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" sty=
le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">&gt; W=
e were about to ask the WG chairs for a WG Last Call on this document,<br>
&gt; but then noticed that this is an informational document and its<br>
&gt; attempting to update a standards track RFC<br>
<br>
Changing the &quot;intended status&quot; of a doc seems easier than spinnin=
g a new<br>
one.=C2=A0 In any case, I would prefer to see the change and the context fo=
r it<br>
kept together.<br>
<br>
Also, both/either document would benefit from a more meaningful abstract<br=
>
and intro.=C2=A0 At the very least, briefly explain _what_ is being changed=
.<br>
(The abstract and intro of the current WG doc hint at &quot;why&quot;, but =
still<br>
don&#39;t say &quot;what&quot;.=C2=A0 The new doc does neither.)<br>
<br>
-- Sam<br>
<br>
_______________________________________________<br>
sidr mailing list<br>
<a href=3D"mailto:sidr@ietf.org" target=3D"_blank">sidr@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sidr" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/listinfo/sidr</a><br>
</blockquote></div>

--047d7ba984b81bff1c0522215303--


From nobody Thu Oct 15 04:03:13 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 774231B2AB6 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 04:03:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HUGFUUhYzXE4 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 04:03:10 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 50D991B2AB5 for <sidr@ietf.org>; Thu, 15 Oct 2015 04:03:10 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id A6B3F28B0046; Thu, 15 Oct 2015 07:03:09 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 6F3DC1F8035; Thu, 15 Oct 2015 07:03:09 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_D0DCB0C8-06C8-4503-A636-EA25ECD9ACC3"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <D2442A8C.6CE45%wesley.george@twcable.com>
Date: Thu, 15 Oct 2015 07:02:22 -0400
Message-Id: <CABE5B0C-6C9E-4EE7-A6F4-364745BBB1E9@tislabs.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <D2442A8C.6CE45%wesley.george@twcable.com>
To: Wesley George <wesley.george@twcable.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/vh5AZEInHe5g3tS4C5wTlJpsTNY>
Cc: "sidr@ietf.org" <sidr@ietf.org>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 11:03:11 -0000

--Apple-Mail=_D0DCB0C8-06C8-4503-A636-EA25ECD9ACC3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


On Oct 14, 2015, at 5:25 PM, George, Wes <wesley.george@twcable.com> =
wrote:

> Gave this a review, and stumbled across an issue that may not =
necessarily
> be gating to this draft, but should probably be addressed in some =
other
> drafts.

=85


>=20
> Substantive: I had to think through this for a bit to make sure I
> understood why this is true beyond the obvious problem of AS23456 not
> being unique. I think we need some additional words explaining why, =
though
> I am not sure if it belongs here, in the protocol draft, or in =
sriram's
> design-choices doc (7.6 is very thin on explanation). I think that =
this is
> a specific corner case for the more generic case of incremental
> deployment, where a given path has some routers/ASNs that support =
BGPSec
> and some that do not, and as far as I can tell, incremental deployment
> isn't really discussed as a concept beyond the [non]negotiation of =
support
> between peers.
>=20
>=20

Do you think the bgpsec-ops draft is the right place for that =
discussion?

Sriram=92s draft is an individual submission, not a wg draft.  Sriram =
can put text there if he wants.  But it=92s not subject to wg consensus.

=97Sandy


--Apple-Mail=_D0DCB0C8-06C8-4503-A636-EA25ECD9ACC3
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWH4e/AAoJEHplpQeet0IZ9sQQAJ+zFnw9k909WshwGewDkVvr
x6aB9Eb3FAlrQ1NWB5ECY38SZPsxM4475FXTZwOZKiD+JgQmnXShjh+nIstQ2VYo
blFVADXWOr1P9dvhnSdFSX2NDujEjK5QxmqIKCsqO/6O3c77lFuzW9OKndD427QV
G57OYiD8sqOMeHCHdJA+30WZf64vbBnn3R1WAePhv6iAvanZFvF/zQiqyyV6YkHt
PffABpGKQClY5SEjo7KqRMNelp6P5QcIbr7VMI6VDKJdSNxLs5P9UO2x78DDWgXW
qGinZgvdVG4RwQ4idhl2gRCMdwfLbhmxJ768E21h8GscdvK5uxgQpdoreMCh/qe3
CZxKjeElJ3C8omUpVSiOu48zy9//EkLv459eW5PklEbN3/sq7iPJ2/0dVv3SljuK
ReJGzv+ziCvMRHPF0c/meJzKFNyh5Z1JGIix18R52uGBAun4ifQ3Bm9sz1McagCf
Sm+tIqgaZ8YCcp6DlAZ9XNZHuAL3wbJydCVGr7t3yxKSEm0G9IM+SxS09sFwnbaw
r/TRRQioHH7cmhZtByjcmNJchOkkEXLZErsDfaMEdrl2XZ+RTEnGjoqV6qAd01T7
RZa+FnPmHrhwTiB/2cHt/cX3iKhQHflcusZCmv24hJP0GclgP5Yi616+o95AKC9d
cQmDVU642PwMwNWgBy7a
=Z/nw
-----END PGP SIGNATURE-----

--Apple-Mail=_D0DCB0C8-06C8-4503-A636-EA25ECD9ACC3--


From nobody Thu Oct 15 07:14:06 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6AEB11B3259; Thu, 15 Oct 2015 07:14:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.664
X-Spam-Level: *
X-Spam-Status: No, score=1.664 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FH_RELAY_NODNS=1.451, HELO_EQ_MODEMCABLE=0.768, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S80J3PRgfZfS; Thu, 15 Oct 2015 07:13:59 -0700 (PDT)
Received: from cdpipgw02.twcable.com (unknown [165.237.59.23]) by ietfa.amsl.com (Postfix) with ESMTP id 3DE1D1A1EF7; Thu, 15 Oct 2015 07:13:58 -0700 (PDT)
X-SENDER-IP: 10.64.163.149
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,686,1437451200"; d="scan'208";a="811896611"
Received: from unknown (HELO exchpapp08.corp.twcable.com) ([10.64.163.149]) by cdpipgw02.twcable.com with ESMTP/TLS/AES256-SHA; 15 Oct 2015 10:08:37 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp08.corp.twcable.com (10.64.163.149) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Thu, 15 Oct 2015 10:13:37 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Thu, 15 Oct 2015 10:13:37 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>, Chris Morrow <morrowc@ops-netman.net>, "sidr-chairs@ietf.org" <sidr-chairs@ietf.org>, "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
Thread-Index: AQHRB1Ourv/u8/GWe0ijQahajfn1Mg==
Date: Thu, 15 Oct 2015 14:13:36 +0000
Message-ID: <D2451B60.6CFFF%wesley.george@twcable.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <D2442A8C.6CE45%wesley.george@twcable.com> <CY1PR09MB079361CBE768BE1B62DBCAEA843F0@CY1PR09MB0793.namprd09.prod.outlook.com>
In-Reply-To: <CY1PR09MB079361CBE768BE1B62DBCAEA843F0@CY1PR09MB0793.namprd09.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.7.151005
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.240]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21880.004
x-tm-as-result: No--42.788100-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <C0983F84C4C90248AB58E23382CF5D68@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/eITTGjmhskbrsOmFxZ4lVT7dpfI>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 14:14:04 -0000

DQpPbiAxMC8xNC8xNSwgNzoyMCBQTSwgIlNyaXJhbSwgS290aWthbGFwdWRpIg0KPGtvdGlrYWxh
cHVkaS5zcmlyYW1AbmlzdC5nb3Y+IHdyb3RlOg0KDQo+PlRoZXJlIGlzIGEgZGlzY3Vzc2lvbiBp
biA2LjQgb2YgU3JpcmFtJ3MgZGVzaWduLWNob2ljZXMgZG9jLCBidXQgSSB0aGluaw0KPj5pdCdz
IGluY29tcGxldGUNCj4+c2luY2UgaXQgb25seSBkaXNjdXNzZXMgaXQgaW4gdGVybXMgb2YgaXQg
YmVpbmcgdW5hY2NlcHRhYmxlIHRvIHNpZ24NCj4+dXBkYXRlcyB0aGF0IGl0IGNhbid0IHZlcmlm
eS4NCj4NCj4idW5hY2NlcHRhYmxlIHRvIHNpZ24gdXBkYXRlcyB0aGF0IGl0IGNhbid0IHZlcmlm
eSIgLS0gSSBkb24ndCByZWFkIHRoYXQNCj5pbiBTZWN0aW9uIDYuNC4NCg0KV0ddIEkgaW50ZXJw
cmV0ZWQgaXQgdGhhdCB3YXkgYmFzZWQgb24gNi40LjIuIE1vcmUgYWJvdXQgdGhhdCBiZWxvdy4N
Cj4NCj4+UHV0IGRpZmZlcmVudGx5OiAiSSBoYXZlIG5vIGlkZWEgd2hldGhlciB0aGUgcGVvcGxl
IGJlZm9yZSBSYW5keSB3ZXJlDQo+PnRlbGxpbmcgdGhlIHRydXRoLCBidXQgSSBjYW4gYXNzZXJ0
IHRoYXQgUmFuZHksIFNhbmR5LCBDaHJpcywgTWF0dCwgYW5kDQo+PlJvYg0KPj5hbGwgdmVyaWZp
YWJseSB0b2xkIHRoZSB0cnV0aCBhYm91dCB0aGVpciBwYXJ0IG9mIHRoZSBwYXRoIHdoZW4gdGhl
eQ0KPj5zZW50IHRoZSByb3V0ZSB0byBtZS4iIEkgdGhpbmsgbWF5YmUgdGhhdCBoYXMgc29tZSB2
YWx1ZSBpbiBhbg0KPj5pbmNyZW1lbnRhbCBtb2RlbCwNCj4+YnV0IGlmIGl0IGRvZXNuJ3QgKG9y
IGlzIHN1ZmZpY2llbnRseSBkaWZmaWN1bHQgdG8gaW1wbGVtZW50IGFzIHRvDQo+Pm5lZ2F0ZSB0
aGUgcG90ZW50aWFsIGJlbmVmaXQpLCB3ZSBzaG91bGQgZXhwbGFpbiB3aHkuDQo+DQo+VGhlIEFT
IHRoYXQgeW91IG5hbWVkIFJhbmR5IGNvdWxkIGJlIGEgYmFkIGFjdG9yLA0KPmFuZCBtYXkgaGF2
ZSBjaGFuZ2VkIHRoZSBBUyBwYXRoIHNlZ21lbnQgYmVmb3JlIGl0DQo+KGRyb3BwZWQgc29tZSBB
U2VzLCByZWR1Y2VkIEFTIHByZXBlbmRzLCBldGMuKS4NCj5JbWFnaW5lIFJvYiByZWNlaXZlcyBh
bm90aGVyIHVwZGF0ZSBmb3IgdGhlIHNhbWUgTkxSSSB0aGF0IGlzIGNvbXBsZXRlbHkNCj51bnNp
Z25lZCwNCj5hbmQgaXQgaGFzIGEgcGF0aCB2aWEgV2VzLCBDaHJpcywgYW5kIEplZmYuDQo+TGV0
IHVzIHNheSBib3RoIHVwZGF0ZXMgcGFzcyBvcmlnaW4gdmFsaWRhdGlvbi4NCj5TaG91bGQgUm9i
IHRydXN0IHRoZSBwYXJ0aWFsbHktc2luZ2VkIHVwZGF0ZSB2aWEgUmFuZHksIFNhbmR5LCBDaHJp
cywgYW5kDQo+IE1hdHQsDQo+b3Igc2hvdWxkIGhlIHRydXN0IHRoZSBjb21wbGV0ZWx5IHVuc2ln
bmVkIGxhdHRlciB1cGRhdGU/DQo+SWYgUm9iIGdpdmVzIHByaW9yaXR5IHRvIHBhcnRpYWxseS1z
aWduZWQgcGF0aCBvdmVyIGNvbXBsZXRlbHkgdW5zaWduZWQNCj5wYXRoLA0KPnRoZXJlIGlzIHBv
dGVudGlhbCBmb3IgdHJvdWJsZSAoYXMgaW4gdGhlIGV4YW1wbGUgYWJvdmUpLg0KPlRoZW4gd2hh
dCBpcyB0aGUgdXNlIG9mIHBhcnRpYWxseSBzaWduZWQgdXBkYXRlcz8NCg0KV0ddIEkgdW5kZXJz
dGFuZCB0aGF0LiBJIHRoaW5rIHlvdSdyZSBtaXNzaW5nIHRoZSBkaXN0aW5jdGlvbiBJJ20gbWFr
aW5nDQpiZXR3ZWVuIHRoZSBzaWduZWQgYW5kIHVuc2lnbmVkIHBhcnRzIG9mIHRoZSB1cGRhdGUu
IEluIHRoaXMgcGFydGlhbC1zaWduDQptb2RlLCB0aGUgd2F5IEkgZXhwZWN0IGl0IHdvdWxkIHdv
cmsgdG8gYmUgYXQgYWxsIHVzZWZ1bCBpcyB0aGF0IGFueQ0KcG9saWN5IGJhc2VkIG9uIHRoZSB0
cnVzdCBvZiBzaWduZWQgdXBkYXRlcyB3b3VsZCBvbmx5IGFwcGx5IHRvIHRoZQ0KcG9ydGlvbiB0
aGF0IGlzIHNpZ25lZCwgbm90IHRoZSBlbnRpcmUgcGF0aC4gSSBjYW4ndCBzZWUgYSBibGFua2V0
IHRydXN0DQpvZiBhIHBhcnRpYWxseSBzaWduZWQgcm91dGUgYXMgYSBiaW5hcnkgdGhpbmcgc3Vj
aCB0aGF0IHlvdSBjb3VsZA0KYXV0b21hdGljYWxseSBwcmVmZXIgcGFydGlhbCBzaWduIG92ZXIg
dW5zaWduZWQsIGFuZCBzbyB5b3VyIGF0dGFjayB2ZWN0b3INCmlzIG92ZXJseSBzaW1wbGlzdGlj
LiBUaGUgcGFydGlhbCBzaWduaW5nIG9ubHkgbWF0dGVycyBpZiB5b3UgY2FyZSBhYm91dA0KdGhl
IGFjdHVhbCBkYXRhIHRoYXQgaXMgYmVpbmcgcHJvdGVjdGVkIGluc2lkZSB0aGUgc2lnbmVkIHBh
cnQuIEkgbWlnaHQNCm5vdCBjYXJlIHRoYXQgSSBjYW4ndCBleHBsaWNpdGx5IHZlcmlmeSB0aGF0
IHRoZSBBUyBwYXRoIHN0YXJ0ZWQgYXQgeW91cg0KaG91c2UsIHRoZW4gd2VudCB0aHJvdWdoIEpv
ZSdzIEJhaXQgU2hvcCBhbmQgV0lTUCBiZWZvcmUgY29ubmVjdGluZyB0bw0KUmFuZHkuIEJ1dCBJ
IG1pZ2h0IGNhcmUgdGhhdCBJIGNhbiBleHBsaWNpdGx5IHZlcmlmeSB0aGF0IGl0IHdlbnQgZnJv
bQ0KUmFuZHkgdG8gU2FuZHkgdG8gQ2hyaXMgdG8gTWF0dCB3aXRob3V0IGFueSB1bnBsYW5uZWQg
ZXhjdXJzaW9ucyB0aHJvdWdoDQpBbGljZSBvciBCb2IuDQpBcyBJIHNhaWQsIHRoZSBsb2dpYyBz
dGFydHMgZ2V0dGluZyBkaWZmaWN1bHQgZnJvbSBhIHJvdXRlIHBvbGljeQ0KcGVyc3BlY3RpdmUs
IGJ1dCBJIHdhcyB0cnlpbmcgdG8gcG9pbnQgb3V0IHRoYXQgdGhlIGV4aXN0aW5nIHRleHQgc2Vl
bXMgdG8NCnNheSB0aGF0IGEgcGFydGlhbGx5IHNpZ25lZCB1cGRhdGUgKG9uZSB0aGF0IG9yaWdp
bmF0ZXMgdW5zaWduZWQgYW5kIGlzDQpsYXRlciBzaWduZWQgZnJvbSBtaWQtcGF0aCB0byBlbmQp
IGlzIHNvbWVob3cgaW1wbHlpbmcgYSBsZXZlbCBvZiB0cnVzdCBvbg0KdGhlIHVuc2lnbmVkIHBv
cnRpb24gdGhhdCBkb2Vzbid0IGV4aXN0LiBJIHRoaW5rIHRoZSByZWFsaXR5IGlzIHRoYXQNCnBh
cnRpYWxseSBzaWduZWQgdXBkYXRlcyB3b3VsZCByZXF1aXJlIHNvbWUgYWRkaXRpb25hbCBjaGFu
Z2VzIGluIHRoZQ0KcHJvdG9jb2wgdG8gbWFrZSB0aGF0IHVzZWZ1bCwgYW5kIGEgc2lnbmlmaWNh
bnQgYW1vdW50IG9mIGFkZGl0aW9uYWwgbG9naWMNCnRvIG1ha2UgaXQgd29yayBpbiBwb2xpY3kt
bGFuZCwgd2hpY2ggbWF5IG5vdCBiZSB3b3J0aCB0aGUgZWZmb3J0LCBidXQNCnNheWluZyB0aGF0
IHdlIGRvbid0IHdhbnQgdG8gcHJvdGVjdCB0aGUgQkdQU2VjLWNhcGFibGUgcGFydCBvZiB0aGUg
cGF0aA0KYmVjYXVzZSB3ZSBjYW4ndCBwcm90ZWN0IHRoZSBwcmVjZWRpbmcgcGFydCBvZiB0aGUg
cGF0aCB0aGF0IGlzbid0IEJHUFNlYw0KY2FwYWJsZSBzZWVtcyBjaXJjdWxhciBsb2dpYyB0byBt
ZS4NCg0KV2VzDQoNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCg0KVGhpcyBF
LW1haWwgYW5kIGFueSBvZiBpdHMgYXR0YWNobWVudHMgbWF5IGNvbnRhaW4gVGltZSBXYXJuZXIg
Q2FibGUgcHJvcHJpZXRhcnkgaW5mb3JtYXRpb24sIHdoaWNoIGlzIHByaXZpbGVnZWQsIGNvbmZp
ZGVudGlhbCwgb3Igc3ViamVjdCB0byBjb3B5cmlnaHQgYmVsb25naW5nIHRvIFRpbWUgV2FybmVy
IENhYmxlLiBUaGlzIEUtbWFpbCBpcyBpbnRlbmRlZCBzb2xlbHkgZm9yIHRoZSB1c2Ugb2YgdGhl
IGluZGl2aWR1YWwgb3IgZW50aXR5IHRvIHdoaWNoIGl0IGlzIGFkZHJlc3NlZC4gSWYgeW91IGFy
ZSBub3QgdGhlIGludGVuZGVkIHJlY2lwaWVudCBvZiB0aGlzIEUtbWFpbCwgeW91IGFyZSBoZXJl
Ynkgbm90aWZpZWQgdGhhdCBhbnkgZGlzc2VtaW5hdGlvbiwgZGlzdHJpYnV0aW9uLCBjb3B5aW5n
LCBvciBhY3Rpb24gdGFrZW4gaW4gcmVsYXRpb24gdG8gdGhlIGNvbnRlbnRzIG9mIGFuZCBhdHRh
Y2htZW50cyB0byB0aGlzIEUtbWFpbCBpcyBzdHJpY3RseSBwcm9oaWJpdGVkIGFuZCBtYXkgYmUg
dW5sYXdmdWwuIElmIHlvdSBoYXZlIHJlY2VpdmVkIHRoaXMgRS1tYWlsIGluIGVycm9yLCBwbGVh
c2Ugbm90aWZ5IHRoZSBzZW5kZXIgaW1tZWRpYXRlbHkgYW5kIHBlcm1hbmVudGx5IGRlbGV0ZSB0
aGUgb3JpZ2luYWwgYW5kIGFueSBjb3B5IG9mIHRoaXMgRS1tYWlsIGFuZCBhbnkgcHJpbnRvdXQu
DQo=


From nobody Thu Oct 15 07:21:59 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C76261B3298 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 07:21:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.664
X-Spam-Level: *
X-Spam-Status: No, score=1.664 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FH_RELAY_NODNS=1.451, HELO_EQ_MODEMCABLE=0.768, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ysBlASD18wzK for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 07:21:57 -0700 (PDT)
Received: from cdcipgw01.twcable.com (unknown [165.237.91.110]) by ietfa.amsl.com (Postfix) with ESMTP id 822CA1B3297 for <sidr@ietf.org>; Thu, 15 Oct 2015 07:21:57 -0700 (PDT)
X-SENDER-IP: 10.64.163.142
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,686,1437451200"; d="scan'208";a="419166636"
Received: from unknown (HELO exchpapp01.corp.twcable.com) ([10.64.163.142]) by cdcipgw01.twcable.com with ESMTP/TLS/AES256-SHA; 15 Oct 2015 10:14:49 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp01.corp.twcable.com (10.64.163.142) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Thu, 15 Oct 2015 10:21:55 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Thu, 15 Oct 2015 10:21:55 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: Sandra Murphy <sandy@tislabs.com>
Thread-Topic: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
Thread-Index: AQHRB1TXHQORHOSh50KNGTpiPeZLWQ==
Date: Thu, 15 Oct 2015 14:21:54 +0000
Message-ID: <D2451CE2.6D00E%wesley.george@twcable.com>
References: <yj9osi5mae4p.wl%morrowc@ops-netman.net> <D2442A8C.6CE45%wesley.george@twcable.com> <CABE5B0C-6C9E-4EE7-A6F4-364745BBB1E9@tislabs.com>
In-Reply-To: <CABE5B0C-6C9E-4EE7-A6F4-364745BBB1E9@tislabs.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.7.151005
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.240]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21880.004
x-tm-as-result: No--38.555200-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <A5E498AEFC93E141BD6A29229230FB31@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/HKGLmGYO2rk1bQV4w_wQ1jwkxZw>
Cc: "sidr@ietf.org" <sidr@ietf.org>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 14:21:59 -0000

DQpPbiAxMC8xNS8xNSwgNzowMiBBTSwgIlNhbmRyYSBNdXJwaHkiIDxzYW5keUB0aXNsYWJzLmNv
bT4gd3JvdGU6DQoNCj5EbyB5b3UgdGhpbmsgdGhlIGJncHNlYy1vcHMgZHJhZnQgaXMgdGhlIHJp
Z2h0IHBsYWNlIGZvciB0aGF0IGRpc2N1c3Npb24/DQo+DQo+U3JpcmFt4oCZcyBkcmFmdCBpcyBh
biBpbmRpdmlkdWFsIHN1Ym1pc3Npb24sIG5vdCBhIHdnIGRyYWZ0Lg0KDQpXR10gV2VsbCwgSSdt
IHRoZSB3cm9uZyBwZXJzb24gdG8gYW5zd2VyIHRoYXQgcXVlc3Rpb24gYmVjYXVzZSBJIGZlZWwg
bGlrZQ0KU0lEUiBpcyBlc3BlY2lhbGx5IGJhZCBhYm91dCBtYWtpbmcgdGhlIHJlYWRlciBjaGFz
ZSB0aGluZ3MgYWNyb3NzDQptdWx0aXBsZSBkcmFmdHMgaW4gc29tZSBtaXN0YWtlbiBhdHRlbXB0
IHRvIG1ha2UgdGhlIGluZGl2aWR1YWwgZG9jdW1lbnRzDQptb3JlIGNvbmNpc2UuIEkgaGFkIHRv
IGdvIGxvb2sgYXQgMyBvciA0IGRvY3VtZW50cyAodGhlIEJHUHNlYyBvdmVydmlldw0KaW50cm8g
cmVmZXJlbmNlcyA4KSBpbiBvcmRlciB0byBzZWUgaWYgdGhlcmUgd2FzIG1vcmUgaW5mbyBhdmFp
bGFibGUNCmRpc2N1c3NpbmcgdGhpcyBwb2ludCB0aGF0IHdhcyBjb25mdXNpbmcgbWUsIGFuZCBm
cm9tIFNyaXJhbSdzIHJlc3BvbnNlDQppdCdzIGNsZWFyIHRoYXQgSSBtaXNzZWQgYXQgbGVhc3Qg
b25lIHBvcnRpb24gb2YgdGhhdCBkaXNjdXNzaW9uIGluIG15DQpjdXJzb3J5IHNlYXJjaC4gSSBo
YXZlIHJlYWQgbWFueSBvZiB0aGUgZG9jdW1lbnRzIGluIHRoZSBwYXN0IGFuZCBzaG91bGQNCmhh
dmUgc29tZSBmYW1pbGlhcml0eSB3aXRoIHRoZW0gdGhhdCB0aGUgYXZlcmFnZSByZWFkZXIgbWF5
IG5vdCwgc28gSQ0KdGhpbmsgdGhpcyBpcyBpbmRpY2F0aXZlIG9mIGEgcHJvYmxlbSB3aXRoIG91
ciBkb2N1bWVudCBvcmdhbml6YXRpb24sIGFuZA0KaW4gaG93IHdlIGRlY2lkZSB3aGF0IGlzIHJl
bGV2YW50IGVub3VnaCB0byBiZSBpbiB0aGUgcHJpbWFyeSBkb2N1bWVudCB2cw0KYmVpbmcgcGln
ZW9uaG9sZWQgaW4gYSBzZXBhcmF0ZSBvbmUuDQoNClNyaXJhbSBpcyBhbHdheXMgcXVpdGUgcmVz
cG9uc2l2ZSB0byBmZWVkYmFjaywgc28gSSdtIHN1cmUgaGUnbGwgYWRkcmVzcw0Kc29tZSBvZiB0
aGUgZGlzY3Vzc2lvbiBpbiBoaXMgZHJhZnQuIEJ1dCBnaXZlbiB0aGF0IGF0IGxlYXN0IHRoaXMg
V0cNCmRyYWZ0LCBhbmQgcG9zc2libHkgb3RoZXJzIGFyZSByZWZlcmVuY2luZyBTcmlyYW0ncyBk
cmFmdCBpbiBsaWV1IG9mDQpleHBsYWluaW5nIHRoaW5ncyBsaWtlIHRoaXMgZGlyZWN0bHksIGlz
IHRoZXJlIGFueSByZWFzb24gd2h5IHdlIHNob3VsZG4ndA0KanVzdCBhZG9wdCBTcmlyYW0ncyBk
cmFmdD8gSXQgc2VlbXMgdG8gYmUgcmVwcmVzZW50aW5nIHByZXZpb3VzIGNvbnNlbnN1cw0Kd2l0
aGluIHRoZSBXRyBvbiBhIHNpZ25pZmljYW50IG51bWJlciBvZiBtYWpvciBwcm90b2NvbCBkZXNp
Z24gZWxlbWVudHMsDQpzbyB0aGUgZmFjdCB0aGF0IGl0IGlzbid0IGEgY29uc2Vuc3VzIGRvY3Vt
ZW50IHNlZW1zIG9kZC4NCg0KV2VzDQoNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X18NCg0KVGhpcyBFLW1haWwgYW5kIGFueSBvZiBpdHMgYXR0YWNobWVudHMgbWF5IGNvbnRhaW4g
VGltZSBXYXJuZXIgQ2FibGUgcHJvcHJpZXRhcnkgaW5mb3JtYXRpb24sIHdoaWNoIGlzIHByaXZp
bGVnZWQsIGNvbmZpZGVudGlhbCwgb3Igc3ViamVjdCB0byBjb3B5cmlnaHQgYmVsb25naW5nIHRv
IFRpbWUgV2FybmVyIENhYmxlLiBUaGlzIEUtbWFpbCBpcyBpbnRlbmRlZCBzb2xlbHkgZm9yIHRo
ZSB1c2Ugb2YgdGhlIGluZGl2aWR1YWwgb3IgZW50aXR5IHRvIHdoaWNoIGl0IGlzIGFkZHJlc3Nl
ZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lwaWVudCBvZiB0aGlzIEUtbWFpbCwg
eW91IGFyZSBoZXJlYnkgbm90aWZpZWQgdGhhdCBhbnkgZGlzc2VtaW5hdGlvbiwgZGlzdHJpYnV0
aW9uLCBjb3B5aW5nLCBvciBhY3Rpb24gdGFrZW4gaW4gcmVsYXRpb24gdG8gdGhlIGNvbnRlbnRz
IG9mIGFuZCBhdHRhY2htZW50cyB0byB0aGlzIEUtbWFpbCBpcyBzdHJpY3RseSBwcm9oaWJpdGVk
IGFuZCBtYXkgYmUgdW5sYXdmdWwuIElmIHlvdSBoYXZlIHJlY2VpdmVkIHRoaXMgRS1tYWlsIGlu
IGVycm9yLCBwbGVhc2Ugbm90aWZ5IHRoZSBzZW5kZXIgaW1tZWRpYXRlbHkgYW5kIHBlcm1hbmVu
dGx5IGRlbGV0ZSB0aGUgb3JpZ2luYWwgYW5kIGFueSBjb3B5IG9mIHRoaXMgRS1tYWlsIGFuZCBh
bnkgcHJpbnRvdXQuDQo=


From nobody Thu Oct 15 15:21:43 2015
Return-Path: <gih@apnic.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC6261A8034 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 15:21:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.801
X-Spam-Level: 
X-Spam-Status: No, score=-101.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lK03Qza8ehPJ for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 15:21:40 -0700 (PDT)
Received: from nx-mailgw.apnic.net (nx-mailgw.apnic.net [IPv6:2001:dd8:9:801::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D729F1A86F6 for <sidr@ietf.org>; Thu, 15 Oct 2015 15:21:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.net; s=c3po; h=received:received:content-type:mime-version:subject:from:in-reply-to:date: content-transfer-encoding:message-id:references:to:x-mailer:return-path; bh=d5DInGqCfOo7JCVVzV4luGf9y5kOde+fqpsqyTwL8II=; b=NhokioyJeOcQFealn91Cz3qpYA7Brt8H7lVPnRQiiGyOmPr44hIMqK3U/1Lz+6ngUWrkV8pf6rc8E P6PsS1guv1dsqrCZBMGpgvY6P+D/4jl9vRUhmBzI7hRbtJrTUuu5gQB2d3M2jo0oM7Q2/DFKwIjaP6 ZW3WEYj2+4+rcRoE=
Received: from NXMDA2.org.apnic.net (unknown [IPv6:2001:dd8:9:2::101:249]) by nx-mailgw.apnic.net (Halon Mail Gateway) with ESMTPS for <sidr@ietf.org>; Fri, 16 Oct 2015 08:22:19 +1000 (AEST)
Received: from dhcp150.potaroo.net (203.119.101.249) by NXMDA2.org.apnic.net (203.119.107.21) with Microsoft SMTP Server (TLS) id 14.1.218.12; Fri, 16 Oct 2015 08:23:40 +1000
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <alpine.LRH.2.03.1510131517100.32318@tislabs.com>
Date: Fri, 16 Oct 2015 09:21:36 +1100
Content-Transfer-Encoding: quoted-printable
Message-ID: <0719A207-9171-4023-9BE9-0D62A39AE957@apnic.net>
References: <alpine.LRH.2.03.1510131517100.32318@tislabs.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/CsvjcgcYz-7Wzg0iCAJ6mW0XReI>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 22:21:42 -0000

> On 15 Oct 2015, at 2:02 AM, Samuel Weiler <weiler@tislabs.com> wrote:
>=20
>> We were about to ask the WG chairs for a WG Last Call on this =
document, but then noticed that this is an informational document and =
its attempting to update a standards track RFC
>=20
> Changing the "intended status" of a doc seems easier than spinning a =
new one.  In any case, I would prefer to see the change and the context =
for it kept together.
>=20
> Also, both/either document would benefit from a more meaningful =
abstract and intro.  At the very least, briefly explain _what_ is being =
changed. (The abstract and intro of the current WG doc hint at "why", =
but still don't say "what".  The new doc does neither.)
>=20


=E2=80=9CThe new doc does neither=E2=80=9D=20

You are joking - right?

Lets see - the Abstract states:

  "This document updates the RPKI certificate validation procedure as =
specified in Section 7.2 of RFC6487."

And the introduction states:

  "This document updates the RPKI certificate validation procedure as =
specified in Section 7.2 of [RFC6487], by replacing the section 7.2 of =
[RFC6487] with the specification contained here.=E2=80=9D

I believe that this is a very clear, concise and accurate description of =
WHAT is being changed. i.e. go look up section 7.2 of RFC6487 and =
replace it with the procedure described in this document. What exactly =
gives you a problem with such a explanation of the proposed update to =
the RPKI validation procedure?

Geoff











From nobody Thu Oct 15 17:27:21 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FCF21A1B2B; Thu, 15 Oct 2015 17:27:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Va6NRWgA0aqh; Thu, 15 Oct 2015 17:27:17 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D99E1A8A91; Thu, 15 Oct 2015 17:27:17 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151016002717.26750.32728.idtracker@ietfa.amsl.com>
Date: Thu, 15 Oct 2015 17:27:17 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/YnzILe_56nkJFMXUIz5ttnbGwag>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rfc6485bis-04.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 00:27:19 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : The Profile for Algorithms and Key Sizes for use in the Resource Public Key Infrastructure
        Authors         : Geoff Huston
                          George Michaelson
	Filename        : draft-ietf-sidr-rfc6485bis-04.txt
	Pages           : 9
	Date            : 2015-10-15

Abstract:
   This document specifies the algorithms, algorithms' parameters,
   asymmetric key formats, asymmetric key size, and signature format for
   the Resource Public Key Infrastructure (RPKI) subscribers that
   generate digital signatures on certificates, Certificate Revocation
   Lists (CRLs), Cryptographic Message Syntax (CMS) signed objects and
   certification requests as well as for the relying parties (RPs) that
   verify these digital signatures.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6485bis/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rfc6485bis-04

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rfc6485bis-04


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Thu Oct 15 18:26:37 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF5921ACF08 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 18:26:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oeE0SeDIB2Iv for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 18:26:35 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 74F391ACF02 for <sidr@ietf.org>; Thu, 15 Oct 2015 18:26:35 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 955CE28B0043 for <sidr@ietf.org>; Thu, 15 Oct 2015 21:26:34 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 67C8F1F8035; Thu, 15 Oct 2015 21:26:34 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_547C3A52-C6F1-4B97-A18A-9E31A87ED096"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Thu, 15 Oct 2015 21:26:37 -0400
Message-Id: <B184011E-E167-4C68-A7D7-EB6A012CF152@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/nsF0Wj0Et9pEujbSqNlamDUFkWY>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] WGLC on draft-ietf-sidr-bgpsec-pki-profiles-12 (ENDS 29-Oct-2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 01:26:37 -0000

--Apple-Mail=_547C3A52-C6F1-4B97-A18A-9E31A87ED096
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The chairs and the authors believe that  =
draft-ietf-sidr-bgpsec-pki-profiles-12 is mature and has stabilized.

This message starts a WGLC for  draft-ietf-sidr-bgpsec-pki-profiles, =
which will end 29-October-2015.

Please review the draft and send comments to the list, and say whether =
you believe it is ready for publication.

http://tools.ietf.org/html/draft-ietf-sidr-bgpsec-pki-profiles


A Profile for BGPsec Router Certificates,
Certificate Revocation Lists, and Certification Requests

Abstract

   This document defines a standard profile for X.509 certificates for
   the purposes of supporting validation of Autonomous System (AS) paths
   in the Border Gateway Protocol (BGP), as part of an extension to that
   protocol known as BGPsec.  BGP is a critical component for the proper
   operation of the Internet as a whole.  The BGPsec protocol is under
   development as a component to address the requirement to provide
   security for the BGP protocol.  The goal of BGPsec is to design a
   protocol for full AS path validation based on the use of strong
   cryptographic primitives.  The end-entity (EE) certificates specified
   by this profile are issued under Resource Public Key Infrastructure
   (RPKI) Certification Authority (CA) certificates, containing the AS
   Identifier Delegation extension, to routers within the Autonomous
   System (AS) or ASes.  The certificate asserts that the router(s)
   holding the private key are authorized to send out secure route
   advertisements on behalf of the specified AS(es).  This document also
   profiles the Certificate Revocation List (CRL), profiles the format
   of certification requests, and specifies Relying Party certificate
   path validation procedures.  The document extends the RPKI;
   therefore, this documents updates the RPKI Resource Certificates
   Profile ( RFC 6487).

=97Sandy, speaking as one of the wg co-chairs



--Apple-Mail=_547C3A52-C6F1-4B97-A18A-9E31A87ED096
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWIFJNAAoJEHplpQeet0IZ+r4QAKErSw8GWaU4B6n1Yu3R7wAg
NVyXjD6v0xUI0aoDZ+wEkCWkqDGUB/pUNVH+3ElemErQqbuxbj4Oe1TYrlIRQp4u
89J1SHM6m/OHxw8TQdIKduDVAjCspSKGVIg/5vE0VMh06pReXrekO8zuHYjRmDlu
Dv9AkqWMwNZdrQptjRJhN2DsmG0lJNYplORHlK4FQKrRpUjErAllX5WYbWJLFuKl
GS5K9MoN4MfPK2QX8neyWnZnHnGwBYjj7RKOaMMQHLOGdwmbxVCZ4E/nD8v0TSA8
zYsxNR+bIGn830hkB6G2CChPLSL6ysv3blnXijAlwFPgLoQf/zHUGEw5xnMzSpXc
CqG+ETIkVVVt7zRuY7GGP8ChqBfD9pwBlB6KoB7oAH5yFP8sBuMYJTbQaVXfln3Q
XLTbpFUzhs6sYi440V56Gf6AdXYrvSw9LAXuchkkIxH9HXhfEdQDq/kkDnCcz2vL
k1ii0Dz0OU4/HeXnvabVZSM30B7IFwtAc9QGMyauSI7umNokSoWNJ3soICOUgKVU
ldD61u1/cUDluehPbI1X+LEP6RfLdGXrfZuEM7D9NouAxFEAb0UYT+H+6xSzSLEC
yTrVit8wCb1ILJaH+FkwBx4PMmaVyFNxxKlz4WrzLWBsTAkOpcjLKMZ9VpioBL/I
TacYnHD+Ng4WkLa54DVm
=+9dG
-----END PGP SIGNATURE-----

--Apple-Mail=_547C3A52-C6F1-4B97-A18A-9E31A87ED096--


From nobody Thu Oct 15 18:50:55 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DAE401B29C9 for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 18:50:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5FzIhguMUcQx for <sidr@ietfa.amsl.com>; Thu, 15 Oct 2015 18:50:53 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F3681B29C7 for <sidr@ietf.org>; Thu, 15 Oct 2015 18:50:53 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 002EE28B0043; Thu, 15 Oct 2015 21:50:52 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id D9BA31F8035; Thu, 15 Oct 2015 21:50:52 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_BAE09F41-E5AD-4737-ABBB-FB1B924D8A22"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <ABEC23B2-FF01-46F7-8AC5-F0D5F807FDE9@tislabs.com>
Date: Thu, 15 Oct 2015 21:50:51 -0400
Message-Id: <FFF5155A-BDE2-49AF-8CEF-C1F567025110@tislabs.com>
References: <20151006143526.10775.43421.idtracker@ietfa.amsl.com> <20151006143851.16C2F1C2CC4C@minas-ithil.hactrn.net> <ABEC23B2-FF01-46F7-8AC5-F0D5F807FDE9@tislabs.com>
To: Rob Austein <sra@hactrn.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/qQWjGSahg_l7_z6AGAzhbbeTuYQ>
Cc: sidr@ietf.org, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-rtr-rfc6810-bis-06.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 01:50:55 -0000

--Apple-Mail=_BAE09F41-E5AD-4737-ABBB-FB1B924D8A22
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252


On Oct 6, 2015, at 8:50 PM, Sandra Murphy <sandy@tislabs.com> wrote:

>=20
> On Oct 6, 2015, at 10:38 AM, Rob Austein <sra@hactrn.net> wrote:
>=20
>> Updated per instructions from WG chair:
>=20
> True.  Newest document shepherd writeup asks for this info.

Mentioning the shepherd writeup should have been a hint that a =
publication request is coming.

Rob=92s last update responding to last set of comments has been there =
for awhile.  Publication request will be going out by Monday.

=97Sandy, speaking as one of the wg co-chairs

--Apple-Mail=_BAE09F41-E5AD-4737-ABBB-FB1B924D8A22
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWIFgAAAoJEHplpQeet0IZPtIP/3CUvoS7w65D49tVrr2HgriT
MIn6/gKRD6Ai2mU1KdUlg9H29sqSmlH8jKgnw93vwz9rVLgomkk9+7ScaCFko7wF
FZRN+/YW8US4oq+8ygDZ9Yc9JfrWzQRH+xbzCmdcumaBruEaUE5xBKZcDIsel+9t
zBmiiAMyiEATZJcInvmDUFnEmH+SRUJwNVlnSqNnZb1JlLIbVDTEJZp/QTf5PHyU
2b8XDlE0odHeKwzfVds1Y/U+W+y72XTLzL5YZdjD6Vlp2bzAI5i5RJGh8C/gJhDA
/THhetA5V6DRT1IfR6pBPJRDrK2m1IF+nUPCXWepGLRjBF2hXY/T1vPDvBTzpSTv
NTNzSFZbr4WBkl+XY1uL/XcS8S7wcIQBmPbM+hyrpNquiqQDj3C1J5JfPwD8yXo5
ERwuK/2DIlx1q17/8gUcqeA9PEbXfkP8mTRlLpgBkDMj2pumTXEy2fGolTNPlGFm
5RBwJKv4VeCI6qyDkPm4CEbaUyGRO7FnpdEscmhtzXoOrfmnKtf6d6mQ0Mq6p47v
yvbEA8OjLA/E7T7SgGwq3fuHaNGJm3eWCw224R0/0GK1G9ge2ZP/sLq8Xl1Zk8oa
1Af5W1WiZk/GHtsWrY8GCXjmaALD1vc5wTHw7MaTEl7yQ97kRcGo1PFzhdruAq66
i4PwbytanNutL18F7ScB
=kny8
-----END PGP SIGNATURE-----

--Apple-Mail=_BAE09F41-E5AD-4737-ABBB-FB1B924D8A22--


From nobody Fri Oct 16 07:34:11 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8F021B2C5F for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 07:34:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dIjNVlxnx2UQ for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 07:34:08 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 600971B2C61 for <sidr@ietf.org>; Fri, 16 Oct 2015 07:34:08 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id AE31F28B0046; Fri, 16 Oct 2015 10:34:07 -0400 (EDT)
Received: from cloud.netsec (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 7ED361F8035; Fri, 16 Oct 2015 10:34:07 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_FFE0A90A-B28D-4AD9-9225-C676972DFC70"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <CAL9jLaaUFMh8CJj6QzzP8yzY+L+smi1QWh6q1Jy+rGs2HdA-iw@mail.gmail.com>
Date: Fri, 16 Oct 2015 10:34:00 -0400
Message-Id: <97072CE8-ED14-4AA6-AAB4-48CAADF674F6@tislabs.com>
References: <55828BEC.9010605@ops-netman.net> <5592F128.7030908@bbn.com> <CAL9jLaYa7ZvhFFNgi4sULmVv8GASVVnwmme78rPFREqDJ31ntA@mail.gmail.com> <55F1BA96.8070502@bbn.com> <CAL9jLaaUFMh8CJj6QzzP8yzY+L+smi1QWh6q1Jy+rGs2HdA-iw@mail.gmail.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Y955ecCnKO_EFtpPdfGA1W80e9c>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] WGLC: draft-ietf-sidr-rpsl-sig - End Jul 02 2015
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 14:34:10 -0000

--Apple-Mail=_FFE0A90A-B28D-4AD9-9225-C676972DFC70
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The authors submitted a revision =
https://tools.ietf.org/html/draft-ietf-sidr-rpsl-sig-08 last week.

It would be awesome to receive confirmation from the commenters that =
their comments have been adequately addressed.

If no confirmations are received, the chairs will make their own =
determination.

Please confirm by Friday 23 Oct.

=97Sandy, speaking as one of the co-chairs

On Sep 10, 2015, at 1:44 PM, Christopher Morrow =
<morrowc.lists@gmail.com> wrote:

> On Thu, Sep 10, 2015 at 1:15 PM, Stephen Kent <kent@bbn.com> wrote:
>> Chris,
>>=20
>> Since I was just a person offering suggested edits, I presume this =
message
>> is really directed to the doc authors, right?
>>=20
>=20
> yes indeed... to the authors and other folk who offered suggested
> edits (if they did hear back that'd be good to know)
>=20
> -chris
>=20
>> Steve
>>=20
>>=20
>>=20
>>> Howdy!
>>> there was a flurry of activity, some comments that seemed useful.... =
I
>>> didn't see an update to the doc though yet?
>>>=20
>>> It's cool if that's waiting in the wings behind other work, just
>>> checking on status though.
>>>=20
>>> On Tue, Jun 30, 2015 at 3:42 PM, Stephen Kent <kent@bbn.com> wrote:
>>>>=20
>>>> I made a few edits to correct spelling errors. I also have some =
questions
>>>> about
>>>> ambiguities in the text and some suggestions for adding text to =
warn
>>>> relying
>>>> parties
>>>> about the danger of assuming that all signed attributes in an RPSL =
object
>>>> are
>>>> trustworthy/valid.
>>>>=20
>>>> I have attached a PDF of the MS Word reviewed text.
>>>>=20
>>>> Steve
>>>>=20
>>>>=20
>>>>=20
>>>>=20
>>>> _______________________________________________
>>>> sidr mailing list
>>>> sidr@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/sidr
>>>>=20
>>=20
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


--Apple-Mail=_FFE0A90A-B28D-4AD9-9225-C676972DFC70
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWIQrfAAoJEHplpQeet0IZYNQQAJ3SYMC2IpBmkdr+Bg+LNiRt
ui06X96UA4VOpXw9OyMuPTLuua0ACULvbFieroOeXir2NZHyIB3+/AMkThp55Mg9
zX6Hsyx73FkVT1ulY3SGKNJgscaTgWvF7YzGaLqQ8AAMj545sQmDH6zBQI+eOnOm
7l3DU75w3nOsylCxGCQ/MfXeAMJCq7CcCO3CoAPpYpK3VP8TtJszNN0UmSm5daWV
f6vFkoCHg3ll2ubrYR8v+RyzRpIz1XWyu8FScy/ojM52El+UBLCA4tpGBGFNj3hz
xCPVEADy05fvRCzS/4zJWv6kzCAOpgSyD/GJYWVGQGYp9Rap8SeAwYIx0loY+Uw8
L7Hgtk9Ksy4T0hckUdKoct6kONZ9so/7fp1e58HoUUObyBxib8sh6GSiQ4+O5nVp
KfQeJqxWEGXYSUE+G2oC4y2Nq41hAOQsYvlRhsNVlTXSlibaV6flYHSyPubaUbZF
yg9uLuUCNfsoX/k8Jl927KkCamMTYbvk5pg8R//p+2qgeAajy10SJ8UAmtCDWMYf
WQ3ri8OHc7X12EgsbRYsHk7DTaCQ4FPRsOxqTHwyxm2emC4KliXn50/7+E2eDMn7
2DH89Hs/7KTKbdvUOUuuuXciNphaimhgCT5aQl/4OdBDvdf8rpP+R0ujZ9hSV9qE
WJyZ4TZsGRRde1Xuo0i8
=oi75
-----END PGP SIGNATURE-----

--Apple-Mail=_FFE0A90A-B28D-4AD9-9225-C676972DFC70--


From nobody Fri Oct 16 08:12:30 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A44341B2BBB for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 08:12:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.475
X-Spam-Level: 
X-Spam-Status: No, score=-0.475 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_MODEMCABLE=0.768, HOST_EQ_MODEMCABLE=1.368, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EI9CDBZog0ZW for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 08:12:27 -0700 (PDT)
Received: from cdpipgw01.twcable.com (cdpipgw01.twcable.com [165.237.59.22]) by ietfa.amsl.com (Postfix) with ESMTP id CB5641A90B5 for <sidr@ietf.org>; Fri, 16 Oct 2015 08:12:26 -0700 (PDT)
X-SENDER-IP: 10.64.163.150
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,689,1437451200"; d="scan'208";a="1001851274"
Received: from unknown (HELO exchpapp09.corp.twcable.com) ([10.64.163.150]) by cdpipgw01.twcable.com with ESMTP/TLS/AES256-SHA; 16 Oct 2015 11:07:05 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp09.corp.twcable.com (10.64.163.150) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Fri, 16 Oct 2015 11:12:23 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Fri, 16 Oct 2015 11:12:23 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: as-migration nit in bgpsec-protocol-13
Thread-Index: AQHRCCUOs+UKDCxztUqIc1SAUM68tA==
Date: Fri, 16 Oct 2015 15:12:22 +0000
Message-ID: <D24688C9.6D372%wesley.george@twcable.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.7.151005
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.239]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21882.004
x-tm-as-result: No--50.373000-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <989FEC4E0915564B8F4FFE39BE8C4992@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/5sogBnL4s5so3ilqOAkEjVIbzyA>
Subject: [sidr] as-migration nit in bgpsec-protocol-13
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 15:12:28 -0000

SSBqdXN0IG1hZGUgYW5vdGhlciBwYXNzIHRocm91Z2ggc2lkci1hcy1taWdyYXRpb24gYW5kIGJn
cHNlYy1wcm90b2NvbC0xMw0KYmFjayB0byBiYWNrIHRvIG1ha2Ugc3VyZSB0aGF0IHRoZXkgYXJl
IGluIHN5bmMsIGFuZCBJIG9ubHkgZm91bmQgb25lDQpzZW50ZW5jZSBpbiB0aGUgc2VjdXJpdHkg
Y29uc2lkZXJhdGlvbnMgKDcuNCkgdGhhdCBwcm9iYWJseSBuZWVkcyB0byBiZQ0KY2hhbmdlZDoN
Cg0KQ3VycmVudDoNCkhvd2V2ZXIsIGVudGl0aWVzIG90aGVyIHRoYW4gcm91dGUgc2VydmVycyBj
b3VsZA0KICAgY29uY2VpdmFibHkgdXNlIHRoaXMgbWVjaGFuaXNtIChzZXQgdGhlIHBDb3VudCB0
byB6ZXJvKSB0byBhdHRyYWN0DQogICB0cmFmZmljIChieSByZWR1Y2luZyB0aGUgZWZmZWN0aXZl
IGxlbmd0aCBvZiB0aGUgQVMtUEFUSCkNCiAgIGlsbGVnaXRpbWF0ZWx5LiAgVGhpcyByaXNrIGlz
IGxhcmdlbHkgbWl0aWdhdGVkIGlmIGV2ZXJ5IEJHUHNlYw0KICAgc3BlYWtlciBkcm9wcyBpbmNv
bWluZyB1cGRhdGUgbWVzc2FnZXMgdGhhdCBzZXQgcENvdW50IHRvIHplcm8gYnV0DQogICBjb21l
IGZyb20gYSBwZWVyIHRoYXQgaXMgbm90IGEgcm91dGUgc2VydmVyLg0KDQoNClByb3Bvc2VkOg0K
Li4uIGlmIGV2ZXJ5IEJHUHNlYw0Kc3BlYWtlciBkcm9wcyBpbmNvbWluZyB1cGRhdGUgbWVzc2Fn
ZXMgdGhhdCBzZXQgcENvdW50IHRvIHplcm8gdW5sZXNzDQpleHBsaWNpdGx5IGNvbmZpZ3VyZWQg
dG8gYWNjZXB0IHRoZW0gZnJvbSBhIHNwZWNpZmljIHBlZXIgd2hlcmUgcENvdW50PTANCm1lc3Nh
Z2VzIGFyZSBleHBlY3RlZCwgc3VjaCBhcyBhIHJvdXRlIHNlcnZlci4NCg0KVGhhbmtzLA0KDQpX
ZXMNCg0KDQpPbiA3LzYvMTUsIDc6MjEgUE0sICJzaWRyIG9uIGJlaGFsZiBvZiBpbnRlcm5ldC1k
cmFmdHNAaWV0Zi5vcmciDQo8c2lkci1ib3VuY2VzQGlldGYub3JnIG9uIGJlaGFsZiBvZiBpbnRl
cm5ldC1kcmFmdHNAaWV0Zi5vcmc+IHdyb3RlOg0KDQo+DQo+QSBOZXcgSW50ZXJuZXQtRHJhZnQg
aXMgYXZhaWxhYmxlIGZyb20gdGhlIG9uLWxpbmUgSW50ZXJuZXQtRHJhZnRzDQo+ZGlyZWN0b3Jp
ZXMuDQo+IFRoaXMgZHJhZnQgaXMgYSB3b3JrIGl0ZW0gb2YgdGhlIFNlY3VyZSBJbnRlci1Eb21h
aW4gUm91dGluZyBXb3JraW5nDQo+R3JvdXAgb2YgdGhlIElFVEYuDQo+DQo+ICAgICAgICBUaXRs
ZSAgICAgICAgICAgOiBCR1BzZWMgUHJvdG9jb2wgU3BlY2lmaWNhdGlvbg0KPiAgICAgICAgQXV0
aG9yICAgICAgICAgIDogTWF0dGhldyBMZXBpbnNraQ0KPkZpbGVuYW1lICAgICAgICA6IGRyYWZ0
LWlldGYtc2lkci1iZ3BzZWMtcHJvdG9jb2wtMTMudHh0DQo+UGFnZXMgICAgICAgICAgIDogMzkN
Cj5EYXRlICAgICAgICAgICAgOiAyMDE1LTA3LTA2DQo+DQo+QWJzdHJhY3Q6DQo+ICAgVGhpcyBk
b2N1bWVudCBkZXNjcmliZXMgQkdQc2VjLCBhbiBleHRlbnNpb24gdG8gdGhlIEJvcmRlciBHYXRl
d2F5DQo+ICAgUHJvdG9jb2wgKEJHUCkgdGhhdCBwcm92aWRlcyBzZWN1cml0eSBmb3IgdGhlIHBh
dGggb2YgYXV0b25vbW91cw0KPiAgIHN5c3RlbXMgdGhyb3VnaCB3aGljaCBhIEJHUCB1cGRhdGUg
bWVzc2FnZSBwYXNzZXMuICBCR1BzZWMgaXMNCj4gICBpbXBsZW1lbnRlZCB2aWEgYSBuZXcgb3B0
aW9uYWwgbm9uLXRyYW5zaXRpdmUgQkdQIHBhdGggYXR0cmlidXRlIHRoYXQNCj4gICBjYXJyaWVz
IGEgZGlnaXRhbCBzaWduYXR1cmUgcHJvZHVjZWQgYnkgZWFjaCBhdXRvbm9tb3VzIHN5c3RlbSB0
aGF0DQo+ICAgcHJvcGFnYXRlcyB0aGUgdXBkYXRlIG1lc3NhZ2UuDQo+DQo+DQo+DQo+VGhlIElF
VEYgZGF0YXRyYWNrZXIgc3RhdHVzIHBhZ2UgZm9yIHRoaXMgZHJhZnQgaXM6DQo+aHR0cHM6Ly9k
YXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtaWV0Zi1zaWRyLWJncHNlYy1wcm90b2NvbC8N
Cj4NCj5UaGVyZSdzIGFsc28gYSBodG1saXplZCB2ZXJzaW9uIGF2YWlsYWJsZSBhdDoNCj5odHRw
czovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtaWV0Zi1zaWRyLWJncHNlYy1wcm90b2NvbC0x
Mw0KPg0KPkEgZGlmZiBmcm9tIHRoZSBwcmV2aW91cyB2ZXJzaW9uIGlzIGF2YWlsYWJsZSBhdDoN
Cj5odHRwczovL3d3dy5pZXRmLm9yZy9yZmNkaWZmP3VybDI9ZHJhZnQtaWV0Zi1zaWRyLWJncHNl
Yy1wcm90b2NvbC0xMw0KPg0KPg0KPlBsZWFzZSBub3RlIHRoYXQgaXQgbWF5IHRha2UgYSBjb3Vw
bGUgb2YgbWludXRlcyBmcm9tIHRoZSB0aW1lIG9mDQo+c3VibWlzc2lvbg0KPnVudGlsIHRoZSBo
dG1saXplZCB2ZXJzaW9uIGFuZCBkaWZmIGFyZSBhdmFpbGFibGUgYXQgdG9vbHMuaWV0Zi5vcmcu
DQo+DQo+SW50ZXJuZXQtRHJhZnRzIGFyZSBhbHNvIGF2YWlsYWJsZSBieSBhbm9ueW1vdXMgRlRQ
IGF0Og0KPmZ0cDovL2Z0cC5pZXRmLm9yZy9pbnRlcm5ldC1kcmFmdHMvDQo+DQo+X19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCj5zaWRyIG1haWxpbmcgbGlz
dA0KPnNpZHJAaWV0Zi5vcmcNCj5odHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZv
L3NpZHINCg0KDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KDQpUaGlzIEUtbWFp
bCBhbmQgYW55IG9mIGl0cyBhdHRhY2htZW50cyBtYXkgY29udGFpbiBUaW1lIFdhcm5lciBDYWJs
ZSBwcm9wcmlldGFyeSBpbmZvcm1hdGlvbiwgd2hpY2ggaXMgcHJpdmlsZWdlZCwgY29uZmlkZW50
aWFsLCBvciBzdWJqZWN0IHRvIGNvcHlyaWdodCBiZWxvbmdpbmcgdG8gVGltZSBXYXJuZXIgQ2Fi
bGUuIFRoaXMgRS1tYWlsIGlzIGludGVuZGVkIHNvbGVseSBmb3IgdGhlIHVzZSBvZiB0aGUgaW5k
aXZpZHVhbCBvciBlbnRpdHkgdG8gd2hpY2ggaXQgaXMgYWRkcmVzc2VkLiBJZiB5b3UgYXJlIG5v
dCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50IG9mIHRoaXMgRS1tYWlsLCB5b3UgYXJlIGhlcmVieSBu
b3RpZmllZCB0aGF0IGFueSBkaXNzZW1pbmF0aW9uLCBkaXN0cmlidXRpb24sIGNvcHlpbmcsIG9y
IGFjdGlvbiB0YWtlbiBpbiByZWxhdGlvbiB0byB0aGUgY29udGVudHMgb2YgYW5kIGF0dGFjaG1l
bnRzIHRvIHRoaXMgRS1tYWlsIGlzIHN0cmljdGx5IHByb2hpYml0ZWQgYW5kIG1heSBiZSB1bmxh
d2Z1bC4gSWYgeW91IGhhdmUgcmVjZWl2ZWQgdGhpcyBFLW1haWwgaW4gZXJyb3IsIHBsZWFzZSBu
b3RpZnkgdGhlIHNlbmRlciBpbW1lZGlhdGVseSBhbmQgcGVybWFuZW50bHkgZGVsZXRlIHRoZSBv
cmlnaW5hbCBhbmQgYW55IGNvcHkgb2YgdGhpcyBFLW1haWwgYW5kIGFueSBwcmludG91dC4NCg==


From nobody Fri Oct 16 08:53:47 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A8C791B3266; Fri, 16 Oct 2015 08:53:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dgyosFVGLvC5; Fri, 16 Oct 2015 08:53:43 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F9891B3232; Fri, 16 Oct 2015 08:53:43 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151016155343.16008.68230.idtracker@ietfa.amsl.com>
Date: Fri, 16 Oct 2015 08:53:43 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/J83fqmIXfPaCY23YL5a7Ltxc9w0>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-as-migration-04.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 15:53:44 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : BGPSec Considerations for AS Migration
        Authors         : Wesley George
                          Sandy Murphy
	Filename        : draft-ietf-sidr-as-migration-04.txt
	Pages           : 15
	Date            : 2015-10-16

Abstract:
   This document discusses considerations and methods for supporting and
   securing a common method for AS-Migration within the BGPSec protocol.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-as-migration/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-as-migration-04

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-as-migration-04


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Oct 16 09:02:55 2015
Return-Path: <wesley.george@twcable.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A79D51B32AB for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 09:02:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.664
X-Spam-Level: *
X-Spam-Status: No, score=1.664 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FH_RELAY_NODNS=1.451, HELO_EQ_MODEMCABLE=0.768, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x2VkXuh3oQDr for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 09:02:47 -0700 (PDT)
Received: from cdpipgw02.twcable.com (unknown [165.237.59.23]) by ietfa.amsl.com (Postfix) with ESMTP id B4C921B32DD for <sidr@ietf.org>; Fri, 16 Oct 2015 09:02:27 -0700 (PDT)
X-SENDER-IP: 10.64.163.148
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="5.17,689,1437451200"; d="scan'208";a="812963168"
Received: from unknown (HELO exchpapp07.corp.twcable.com) ([10.64.163.148]) by cdpipgw02.twcable.com with ESMTP/TLS/AES256-SHA; 16 Oct 2015 11:56:39 -0400
Received: from EXCHPAPP06.corp.twcable.com (10.64.163.147) by exchpapp07.corp.twcable.com (10.64.163.148) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Fri, 16 Oct 2015 12:01:47 -0400
Received: from EXCHPAPP06.corp.twcable.com ([10.64.163.147]) by exchpapp06.corp.twcable.com ([10.64.163.147]) with mapi id 15.00.1104.000; Fri, 16 Oct 2015 12:01:47 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: "sidr@ietf.org" <sidr@ietf.org>
Thread-Topic: [sidr] I-D Action: draft-ietf-sidr-as-migration-04.txt
Thread-Index: AQHRCCv1K1GQjqkGBEiV9gd4zCX4mg==
Date: Fri, 16 Oct 2015 16:01:46 +0000
Message-ID: <D246970A.6D3B1%wesley.george@twcable.com>
References: <20151016155343.16008.68230.idtracker@ietfa.amsl.com>
In-Reply-To: <20151016155343.16008.68230.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.5.7.151005
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.64.163.240]
x-tm-as-product-ver: SMEX-11.0.0.1191-8.000.1202-21882.004
x-tm-as-result: No--48.986300-8.000000-31
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
Content-Type: text/plain; charset="utf-8"
Content-ID: <B1A632236432A349B572B9A264C5ADCC@twcable.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/LbOF-mE5UUgQmheTiwj69hpuWvM>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-as-migration-04.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 16:02:48 -0000

SSBiZWxpZXZlIHRoYXQgdGhpcyBkcmFmdCBpcyBjb21wbGV0ZSBhbmQgcmVhZHkgdG8gbW92ZSBm
b3J3YXJkLiBUaGlzDQp2ZXJzaW9uIGFkZHJlc3NlcyBBRC1yZXZpZXcgY29tbWVudHMgcmVjZWl2
ZWQgYXQgV0dMQywgc28gSSB0aGluayB3ZSdyZQ0KanVzdCB3YWl0aW5nIGZvciBpdCB0byBiZSBy
ZXN1Ym1pdHRlZCB0byBJRVNHIGZvciBJRVRGIExDLCBhcyB0aGUgY2hhbmdlcw0KbWFkZSB3ZXJl
IGxpa2VseSBub3Qgc3Vic3RhbnRpdmUgZW5vdWdoIHRvIHJlcXVpcmUgYSBuZXcgV0dMQy4gSSBk
byAqbm90Kg0KbmVlZCB0aW1lIHRvIGRpc2N1c3MgdGhpcyBkdXJpbmcgdGhlIG1lZXRpbmcgZWl0
aGVyLg0KDQpUaGFua3MsDQoNCldlcw0KDQoNCg0KDQpPbiAxMC8xNi8xNSwgMTE6NTMgQU0sICJz
aWRyIG9uIGJlaGFsZiBvZiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmciDQo8c2lkci1ib3VuY2Vz
QGlldGYub3JnIG9uIGJlaGFsZiBvZiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmc+IHdyb3RlOg0K
DQo+DQo+QSBOZXcgSW50ZXJuZXQtRHJhZnQgaXMgYXZhaWxhYmxlIGZyb20gdGhlIG9uLWxpbmUg
SW50ZXJuZXQtRHJhZnRzDQo+ZGlyZWN0b3JpZXMuDQo+IFRoaXMgZHJhZnQgaXMgYSB3b3JrIGl0
ZW0gb2YgdGhlIFNlY3VyZSBJbnRlci1Eb21haW4gUm91dGluZyBXb3JraW5nDQo+R3JvdXAgb2Yg
dGhlIElFVEYuDQo+DQo+ICAgICAgICBUaXRsZSAgICAgICAgICAgOiBCR1BTZWMgQ29uc2lkZXJh
dGlvbnMgZm9yIEFTIE1pZ3JhdGlvbg0KPiAgICAgICAgQXV0aG9ycyAgICAgICAgIDogV2VzbGV5
IEdlb3JnZQ0KPiAgICAgICAgICAgICAgICAgICAgICAgICAgU2FuZHkgTXVycGh5DQo+RmlsZW5h
bWUgICAgICAgIDogZHJhZnQtaWV0Zi1zaWRyLWFzLW1pZ3JhdGlvbi0wNC50eHQNCj5QYWdlcyAg
ICAgICAgICAgOiAxNQ0KPkRhdGUgICAgICAgICAgICA6IDIwMTUtMTAtMTYNCj4NCj5BYnN0cmFj
dDoNCj4gICBUaGlzIGRvY3VtZW50IGRpc2N1c3NlcyBjb25zaWRlcmF0aW9ucyBhbmQgbWV0aG9k
cyBmb3Igc3VwcG9ydGluZyBhbmQNCj4gICBzZWN1cmluZyBhIGNvbW1vbiBtZXRob2QgZm9yIEFT
LU1pZ3JhdGlvbiB3aXRoaW4gdGhlIEJHUFNlYyBwcm90b2NvbC4NCj4NCj4NCj5UaGUgSUVURiBk
YXRhdHJhY2tlciBzdGF0dXMgcGFnZSBmb3IgdGhpcyBkcmFmdCBpczoNCj5odHRwczovL2RhdGF0
cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1pZXRmLXNpZHItYXMtbWlncmF0aW9uLw0KPg0KPlRo
ZXJlJ3MgYWxzbyBhIGh0bWxpemVkIHZlcnNpb24gYXZhaWxhYmxlIGF0Og0KPmh0dHBzOi8vdG9v
bHMuaWV0Zi5vcmcvaHRtbC9kcmFmdC1pZXRmLXNpZHItYXMtbWlncmF0aW9uLTA0DQo+DQo+QSBk
aWZmIGZyb20gdGhlIHByZXZpb3VzIHZlcnNpb24gaXMgYXZhaWxhYmxlIGF0Og0KPmh0dHBzOi8v
d3d3LmlldGYub3JnL3JmY2RpZmY/dXJsMj1kcmFmdC1pZXRmLXNpZHItYXMtbWlncmF0aW9uLTA0
DQo+DQo+DQo+UGxlYXNlIG5vdGUgdGhhdCBpdCBtYXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVz
IGZyb20gdGhlIHRpbWUgb2YNCj5zdWJtaXNzaW9uDQo+dW50aWwgdGhlIGh0bWxpemVkIHZlcnNp
b24gYW5kIGRpZmYgYXJlIGF2YWlsYWJsZSBhdCB0b29scy5pZXRmLm9yZy4NCj4NCj5JbnRlcm5l
dC1EcmFmdHMgYXJlIGFsc28gYXZhaWxhYmxlIGJ5IGFub255bW91cyBGVFAgYXQ6DQo+ZnRwOi8v
ZnRwLmlldGYub3JnL2ludGVybmV0LWRyYWZ0cy8NCj4NCj5fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fXw0KPnNpZHIgbWFpbGluZyBsaXN0DQo+c2lkckBpZXRm
Lm9yZw0KPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vc2lkcg0KDQoNCl9f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQoNClRoaXMgRS1tYWlsIGFuZCBhbnkgb2Yg
aXRzIGF0dGFjaG1lbnRzIG1heSBjb250YWluIFRpbWUgV2FybmVyIENhYmxlIHByb3ByaWV0YXJ5
IGluZm9ybWF0aW9uLCB3aGljaCBpcyBwcml2aWxlZ2VkLCBjb25maWRlbnRpYWwsIG9yIHN1Ympl
Y3QgdG8gY29weXJpZ2h0IGJlbG9uZ2luZyB0byBUaW1lIFdhcm5lciBDYWJsZS4gVGhpcyBFLW1h
aWwgaXMgaW50ZW5kZWQgc29sZWx5IGZvciB0aGUgdXNlIG9mIHRoZSBpbmRpdmlkdWFsIG9yIGVu
dGl0eSB0byB3aGljaCBpdCBpcyBhZGRyZXNzZWQuIElmIHlvdSBhcmUgbm90IHRoZSBpbnRlbmRl
ZCByZWNpcGllbnQgb2YgdGhpcyBFLW1haWwsIHlvdSBhcmUgaGVyZWJ5IG5vdGlmaWVkIHRoYXQg
YW55IGRpc3NlbWluYXRpb24sIGRpc3RyaWJ1dGlvbiwgY29weWluZywgb3IgYWN0aW9uIHRha2Vu
IGluIHJlbGF0aW9uIHRvIHRoZSBjb250ZW50cyBvZiBhbmQgYXR0YWNobWVudHMgdG8gdGhpcyBF
LW1haWwgaXMgc3RyaWN0bHkgcHJvaGliaXRlZCBhbmQgbWF5IGJlIHVubGF3ZnVsLiBJZiB5b3Ug
aGF2ZSByZWNlaXZlZCB0aGlzIEUtbWFpbCBpbiBlcnJvciwgcGxlYXNlIG5vdGlmeSB0aGUgc2Vu
ZGVyIGltbWVkaWF0ZWx5IGFuZCBwZXJtYW5lbnRseSBkZWxldGUgdGhlIG9yaWdpbmFsIGFuZCBh
bnkgY29weSBvZiB0aGlzIEUtbWFpbCBhbmQgYW55IHByaW50b3V0Lg0K


From nobody Fri Oct 16 09:09:10 2015
Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CE3C61B2B05 for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 09:09:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hi3LPmJOjDfh for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 09:09:02 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0121.outbound.protection.outlook.com [207.46.100.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F6F01B32B7 for <sidr@ietf.org>; Fri, 16 Oct 2015 09:09:02 -0700 (PDT)
Received: from CY1PR09MB0793.namprd09.prod.outlook.com (10.163.43.143) by CY1PR09MB0795.namprd09.prod.outlook.com (10.163.43.145) with Microsoft SMTP Server (TLS) id 15.1.300.14; Fri, 16 Oct 2015 16:09:00 +0000
Received: from CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) by CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) with mapi id 15.01.0300.010; Fri, 16 Oct 2015 16:09:00 +0000
From: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>
To: Matthew Lepinski <mlepinski.ietf@gmail.com>
Thread-Topic: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt
Thread-Index: AQHRCCz4wwoZaaJjcUiLCIPytNy8pQ==
Date: Fri, 16 Oct 2015 16:09:00 +0000
Message-ID: <CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0@CY1PR09MB0793.namprd09.prod.outlook.com>
References: <SN1PR09MB079938B1A44171328C0B16CA846A0@SN1PR09MB0799.namprd09.prod.outlook.com> <D20B8CAC.45839%dougm@nist.gov> <CY1PR09MB079376AC097FDDB73531814184690@CY1PR09MB0793.namprd09.prod.outlook.com> <m2613ca3kf.wl%randy@psg.com> <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>, <CANTg3aCvdCKY+BfJ9G0dtJpQth=ckud=pmYyY4rKJh_V2A+7fQ@mail.gmail.com>
In-Reply-To: <CANTg3aCvdCKY+BfJ9G0dtJpQth=ckud=pmYyY4rKJh_V2A+7fQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=kotikalapudi.sriram@nist.gov; 
x-originating-ip: [129.6.219.252]
x-microsoft-exchange-diagnostics: 1; CY1PR09MB0795; 5:L2gfuNy9XT6L0XQKI1wcE9UEN3d1APar+aB0CEEFLEyPasH5AtSwpdZhlL/igKSliSNqTiyS7Vt6AoQZC1RPlbnmkJ/kGe4KMZLAUXQfXSwL3Yb6R6XzOVfyzx1wjryWC8O4b4YKGpnYRiX6wo6vmA==; 24:IZ5o7IiK85xJzTZu3BSK7b6616wfbO3YLtK1qR+1CUzVs0eEj34auRG5a+DhPc9o24QrtVbFEDAS3SNvkJQUdBfVhjGAOVpDhuusaCEPyo8=; 20:XsoKlueEuCe9Dr+ZA4MRfHuja898sCF/Lt6HueAMn7iFAkpH8DSp3SQNzSqdMt8rA/Q/DbWQsubadDgSYyNIBw==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:CY1PR09MB0795;
x-microsoft-antispam-prvs: <CY1PR09MB079526653DB5C42D2D512DD8843D0@CY1PR09MB0795.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(520078)(5005006)(8121501046)(3002001); SRVR:CY1PR09MB0795; BCL:0; PCL:0; RULEID:; SRVR:CY1PR09MB0795; 
x-forefront-prvs: 0731AA2DE6
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(199003)(189002)(19627405001)(122556002)(5008740100001)(5001960100002)(110136002)(101416001)(64706001)(74316001)(5007970100001)(92566002)(230783001)(11100500001)(5004730100002)(46102003)(76576001)(54356999)(106356001)(40100003)(19625215002)(2900100001)(5003600100002)(87936001)(77096005)(189998001)(99286002)(93886004)(76176999)(19580395003)(2950100001)(10400500002)(86362001)(66066001)(50986999)(33656002)(15975445007)(81156007)(19617315012)(106116001)(97736004)(5002640100001)(105586002)(102836002)(16236675004); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR09MB0795; H:CY1PR09MB0793.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0CY1PR09MB0793namp_"
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Oct 2015 16:09:00.5436 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR09MB0795
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/UmFHKtJP_Ztc70n5rpkuEFofBlw>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 16:09:09 -0000

--_000_CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0CY1PR09MB0793namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable


Hi Matt,


A few notes below (one editorial and one substantive).
There is a typo in this sentence (page 11):
In particular, the BGPsec
   attribute SHOULD NOT be removed even in the case where the BGPsec
   update message *has not* been that *has not* successfully validated.
Repeat of 'has not' above. May be the sentence was meant to read as follows=
?
In particular, the BGPsec
   attribute SHOULD NOT be removed even in the case where the BGPsec
   update message has not been validated (not attempted) or has not been su=
ccessfully validated.
Substantive comment ....
Looking at this on page 23,
"BGPsec update messages do not contain an AS_PATH attribute.
   Therefore, a BGPsec speaker MUST utilize the AS path information in
   the BGPsec_Path attribute in all cases where it would otherwise use
   the AS path information in the AS_PATH attribute.  The only exception
   to this rule is when AS path information must be updated in order to
   propagate a route to a peer (in which case the BGPsec speaker follows
   the instructions in Section 4<https://tools.ietf.org/html/draft-ietf-sid=
r-bgpsec-protocol-13#section-4>)."
What is being said in the second sentence above is not clear.
No exception applies if the peer is BGPsec capable and negotiated BGPsec.
So is the exception for the case when the peer is non-BGPsec?
May the fix is to replace this (current):
"The only exception
   to this rule is when AS path information must be updated in order to
   propagate a route to a peer (in which case the BGPsec speaker follows
   the instructions in Section 4<https://tools.ietf.org/html/draft-ietf-sid=
r-bgpsec-protocol-13#section-4>)."
with the following (proposed):
The only exception
   to this rule is when AS path information must be re-formatted to AS_PATH=
 in order to
   propagate a route to a non-BGPsec peer (in which case the BGPsec speaker=
 follows
   the instructions in Section 4.4).
Sriram



--_000_CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0CY1PR09MB0793namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi=
n-bottom:0;} --></style>
</head>
<body dir=3D"ltr">
<div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt;color:#000000;back=
ground-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p><br>
</p>
<p><span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Cal=
ibri; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-=
family: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">Hi Mat=
t,</span></p>
<p><span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Cal=
ibri; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-=
family: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;"><o:p><=
/o:p></span>&nbsp;</p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">A few not=
es&nbsp;below (one editorial and one substantive).
<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">There is =
a&nbsp;typo in this sentence (page 11):<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">In partic=
ular, the BGPsec<br>
&nbsp;&nbsp; attribute SHOULD NOT be removed even in the case where the BGP=
sec<br>
&nbsp;&nbsp; update message *has not* been that *has not* successfully vali=
dated.<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">Repeat of=
 'has not' above. May be the sentence was meant to read
 as follows?<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">In partic=
ular, the BGPsec<br>
&nbsp;&nbsp; attribute SHOULD NOT be removed even in the case where the BGP=
sec<br>
&nbsp;&nbsp; update message has not been validated (not attempted) or has n=
ot been successfully validated.<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">Substanti=
ve comment ....<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">Looking a=
t this on page 23,<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">&quot;BGP=
sec update messages do not contain an AS_PATH attribute.<br>
&nbsp;&nbsp; Therefore, a BGPsec speaker MUST utilize the AS path informati=
on in<br>
&nbsp;&nbsp; the BGPsec_Path attribute in all cases where it would otherwis=
e use<br>
&nbsp;&nbsp; the AS path information in the AS_PATH attribute.&nbsp; The on=
ly exception<br>
&nbsp;&nbsp; to this rule is when AS path information must be updated in or=
der to<br>
&nbsp;&nbsp; propagate a route to a peer (in which case the BGPsec speaker =
follows<br>
&nbsp;&nbsp; the instructions in <a id=3D"LPlnk334703" href=3D"https://tool=
s.ietf.org/html/draft-ietf-sidr-bgpsec-protocol-13#section-4">
<span style=3D"color: blue;">Section 4</span></a>).&quot;&nbsp; <o:p></o:p>=
</span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">What is b=
eing said in the second sentence above is not clear.
<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">No except=
ion applies if the peer is BGPsec capable and negotiated
 BGPsec.<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">So is the=
 exception for the case when the peer is non-BGPsec?<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">May the f=
ix is to replace this (current):<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">&quot;The=
 only exception<br>
&nbsp;&nbsp; to this rule is when AS path information must be updated in or=
der to<br>
&nbsp;&nbsp; propagate a route to a peer (in which case the BGPsec speaker =
follows<br>
&nbsp;&nbsp; the instructions in <a href=3D"https://tools.ietf.org/html/dra=
ft-ietf-sidr-bgpsec-protocol-13#section-4">
<span style=3D"color: blue;">Section 4</span></a>).&quot;<o:p></o:p></span>=
</p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">with the =
following (proposed):<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">The only =
exception<br>
&nbsp;&nbsp; to this rule is when AS path information must be&nbsp;re-forma=
tted to AS_PATH&nbsp;in order to<br>
&nbsp;&nbsp; propagate a route to a non-BGPsec peer (in which case the BGPs=
ec speaker follows<br>
&nbsp;&nbsp; the instructions in Section 4.4).&nbsp;<o:p></o:p></span></p>
<font face=3D"Times New Roman"></font>
<p class=3D"MsoNormal" style=3D"background: white; margin: 0in 0in 8pt; lin=
e-height: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;">
<span style=3D"color: black; font-size: 12pt; mso-ascii-font-family: Calibr=
i; mso-fareast-font-family: &quot;Times New Roman&quot;; mso-hansi-font-fam=
ily: Calibri; mso-bidi-font-family: &quot;Times New Roman&quot;;">Sriram<o:=
p></o:p></span></p>
<font face=3D"Times New Roman"></font><br>
<br>
</div>
</body>
</html>

--_000_CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0CY1PR09MB0793namp_--


From nobody Fri Oct 16 12:29:05 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B99CA1B31BF; Fri, 16 Oct 2015 12:29:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kryDpGPcZGR5; Fri, 16 Oct 2015 12:29:02 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7F8C31B3115; Fri, 16 Oct 2015 12:29:02 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151016192902.15303.54576.idtracker@ietfa.amsl.com>
Date: Fri, 16 Oct 2015 12:29:02 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/ecFkQfDQN-EPGZ4d5QEFsccTItM>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rpki-oob-setup-02.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 19:29:03 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : An Out-Of-Band Setup Protocol For RPKI Production Services
        Author          : Rob Austein
	Filename        : draft-ietf-sidr-rpki-oob-setup-02.txt
	Pages           : 19
	Date            : 2015-10-16

Abstract:
   This note describes a simple out-of-band protocol to ease setup of
   the RPKI provisioning and publication protocols between two parties.
   The protocol is encoded in a small number of XML messages, which can
   be passed back and forth by any mutually agreeable secure means.

   This setup protocol is not part of the provisioning or publication
   protocol, rather, it is intended to simplify configuration of these
   protocols by setting up relationships and exchanging BPKI keying
   material.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-oob-setup/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rpki-oob-setup-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpki-oob-setup-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Oct 16 12:31:36 2015
Return-Path: <sra@hactrn.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F21E1B3165 for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 12:31:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SDTmG4xw226P for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 12:31:34 -0700 (PDT)
Received: from adrilankha.hactrn.net (adrilankha.hactrn.net [IPv6:2001:418:1::19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D27C1B313D for <sidr@ietf.org>; Fri, 16 Oct 2015 12:31:34 -0700 (PDT)
Received: from minas-ithil.hactrn.net (c-24-34-34-101.hsd1.ma.comcast.net [24.34.34.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "nargothrond.hactrn.net", Issuer "Grunchweather Associates" (verified OK)) by adrilankha.hactrn.net (Postfix) with ESMTPS id 29A2D3982B for <sidr@ietf.org>; Fri, 16 Oct 2015 19:31:34 +0000 (UTC)
Received: from minas-ithil.hactrn.net (localhost [IPv6:::1]) by minas-ithil.hactrn.net (Postfix) with ESMTP id 7CFE11D0D1B0 for <sidr@ietf.org>; Fri, 16 Oct 2015 15:30:24 -0400 (EDT)
Date: Fri, 16 Oct 2015 15:30:24 -0400
From: Rob Austein <sra@hactrn.net>
To: sidr@ietf.org
In-Reply-To: <20151016192902.15303.54576.idtracker@ietfa.amsl.com>
References: <20151016192902.15303.54576.idtracker@ietfa.amsl.com>
User-Agent: Wanderlust/2.15.5 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset=US-ASCII
Message-Id: <20151016193024.7CFE11D0D1B0@minas-ithil.hactrn.net>
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/PmedrPbbFZfs3pZENZEYZcNKLmM>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-oob-setup-02.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 19:31:35 -0000

Refresh of an old draft with one minor substantive change: -02 adds
RRDP support.


From nobody Fri Oct 16 15:47:52 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A7C2C1B3463 for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 15:47:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k9dcXL7U6yeW for <sidr@ietfa.amsl.com>; Fri, 16 Oct 2015 15:47:45 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6178D1A6F64 for <sidr@ietf.org>; Fri, 16 Oct 2015 15:47:45 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 9F9BD28B0046 for <sidr@ietf.org>; Fri, 16 Oct 2015 18:47:44 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 86CD21F8035; Fri, 16 Oct 2015 18:47:44 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_7C98C3D2-33D4-48DB-B706-B6F893B0AE30"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Fri, 16 Oct 2015 18:47:45 -0400
Message-Id: <1C34B13A-A444-4EB5-A1A9-7933E67992FA@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/EZ4jqBpz_Yvmo4toutZU5_LRIQk>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] WGLC on draft-ietf-sidr-bgpsec-algs-11 (ENDS 30-Oct-2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 22:47:46 -0000

--Apple-Mail=_7C98C3D2-33D4-48DB-B706-B6F893B0AE30
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The chairs and the authors believe that draft-ietf-sidr-bgpsec-algs-11 =
is mature and has stabilized.

This message starts a WGLC for  draft-ietf-sidr-bgpsec-algs-11, which =
will end 30-October-2015.

Please review the draft and send comments to the list, and say whether =
you believe it is ready for publication.

http://tools.ietf.org/html/draft-ietf-sidr-bgpsec-algs

          BGPsec Algorithms, Key Formats, & Signature Formats

Abstract

   This document specifies the algorithms, algorithms' parameters,
   asymmetric key formats, asymmetric key size and signature format used
   in BGPsec (Border Gateway Protocol Security).  This document updates
   the Profile for Algorithms and Key Sizes for use in the Resource
   Public Key Infrastructure (draft-ietf-sidr-rfc6485bis).

=97Sandy, speaking as one of the wg co-chairs




--Apple-Mail=_7C98C3D2-33D4-48DB-B706-B6F893B0AE30
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWIX6ZAAoJEHplpQeet0IZJJsQAIFxIgz9DQw15gDUeXk7cTPh
uXNpc2sp3q3mcGRAHoi4x1whNxUsTeP9Ct5sjYaXjhVnHc3XE7s4o7L0KrZYr4f/
fbr0F1TNiI0foAt7xmnm1tYL1k5loKvs6lWA5MQaLM12Wg3cEQ5BpJy84m8hrqEP
tE3T8XtrvOb0EkIymhqOXNgtIMfY9sl6H66wxbvm+n+Ljbe7sEwE196kmZQSbJwp
fvyI1w9VfJiQuopU2iUT6NTRFlxYiyEIADRLige5XOIah3/sqciw0g84ffghAfs1
VKr6nlwp7v5D1YAZWct6DRD3SuqUqCDAy7/FHJg/HDANq12lEma8coKkoA+kwN68
IFLWMBzfm4VK6uZ7ViXyg0JdpZ2gyHaNGx7ZuBXB05iYAJn39rQbVh172PdY9gms
jyRVlHRmSt2wy2rCx3SmNlPDrt8LspnQ+bhyA2dnz9jZuCRPcI8+QHtXjCJc95V2
9He+5QMf4w6wh7byGi05FXLe2VLA3qgPciKFj0d1U+uGVAu73FB5yGEineYq3JV2
Mq8/BplyqtIXMZfeRHNKmZCC6lkfSXTFeOXhp6sEKL+BDQ2zqlpN0BQEKo1ekGd5
0v3N7fSefBmeFPNmDpz67EHNqpjf9QO16d4hHX0WZPZNiqF1fZYWUxIUWsmWw1D8
nXSd0mHAcpUu7kgHY7t4
=i3OL
-----END PGP SIGNATURE-----

--Apple-Mail=_7C98C3D2-33D4-48DB-B706-B6F893B0AE30--


From nobody Sat Oct 17 08:30:58 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 202B81A9117 for <sidr@ietfa.amsl.com>; Sat, 17 Oct 2015 08:30:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ACNij_tEj0NP for <sidr@ietfa.amsl.com>; Sat, 17 Oct 2015 08:30:55 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F54E1A9111 for <sidr@ietf.org>; Sat, 17 Oct 2015 08:30:55 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id D178928B0046; Sat, 17 Oct 2015 11:30:54 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 80C211F8035; Sat, 17 Oct 2015 11:30:54 -0400 (EDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_D03705CD-1289-4BD3-B6AE-E2BA5E80E1FF"; protocol="application/pgp-signature"; micalg=pgp-sha512
X-Pgp-Agent: GPGMail 2.5.1
From: Sandra Murphy <sandy@tislabs.com>
In-Reply-To: <CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0@CY1PR09MB0793.namprd09.prod.outlook.com>
Date: Sat, 17 Oct 2015 11:30:59 -0400
Message-Id: <A2062B52-F6E8-4C8D-B1B9-02C5DD57E548@tislabs.com>
References: <SN1PR09MB079938B1A44171328C0B16CA846A0@SN1PR09MB0799.namprd09.prod.outlook.com> <D20B8CAC.45839%dougm@nist.gov> <CY1PR09MB079376AC097FDDB73531814184690@CY1PR09MB0793.namprd09.prod.outlook.com> <m2613ca3kf.wl%randy@psg.com> <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>, <CANTg3aCvdCKY+BfJ9G0dtJpQth=ckud=pmYyY4rKJh_V2A+7fQ@mail.gmail.com> <CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0@CY1PR09MB0793.namprd09.prod.outlook.com>
To: Sriram Kotikalapudi <kotikalapudi.sriram@nist.gov>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/e59vHmSa87DTAbWQ5Ung9EGHiyw>
Cc: sidr wg list <sidr@ietf.org>, Sandra Murphy <sandy@tislabs.com>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 17 Oct 2015 15:30:57 -0000

--Apple-Mail=_D03705CD-1289-4BD3-B6AE-E2BA5E80E1FF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

speaking as a regular ol=92 member

On Oct 16, 2015, at 12:09 PM, Sriram, Kotikalapudi =
<kotikalapudi.sriram@nist.gov> wrote:

>=20
>=20
> Substantive comment ....
>=20
> Looking at this on page 23,
>=20
> "BGPsec update messages do not contain an AS_PATH attribute.
>    Therefore, a BGPsec speaker MUST utilize the AS path information in
>    the BGPsec_Path attribute in all cases where it would otherwise use
>    the AS path information in the AS_PATH attribute.  The only =
exception
>    to this rule is when AS path information must be updated in order =
to
>    propagate a route to a peer (in which case the BGPsec speaker =
follows
>    the instructions in Section 4)."
>=20
> What is being said in the second sentence above is not clear.
>=20
> No exception applies if the peer is BGPsec capable and negotiated =
BGPsec.
>=20
> So is the exception for the case when the peer is non-BGPsec?
>=20
> May the fix is to replace this (current):
>=20
> "The only exception
>    to this rule is when AS path information must be updated in order =
to
>    propagate a route to a peer (in which case the BGPsec speaker =
follows
>    the instructions in Section 4)."
>=20
> with the following (proposed):
>=20
> The only exception
>    to this rule is when AS path information must be re-formatted to =
AS_PATH in order to
>    propagate a route to a non-BGPsec peer (in which case the BGPsec =
speaker follows
>    the instructions in Section 4.4).
>=20


I read that sentence differently.

When BGP is propagating a route to a neighbor, it ordinarily appends its =
AS to the AS_PATH.

The =93in all cases=94 would imply the same would happen in BPGsec, =
whether the neighbor is bpgsec capable or not.

The exception is that, in the propagating case, BGPsec will instead =
follow section 4 - which covers bgpsec capable neighbors (embed AS in =
BGPsec_Path) and bgpsec incapable neighbors (reconstruct AS_PATH).

I think your statement is correct, but I don=92t think it is what is =
meant here.

=97Sandy, speaking as a regular ol=92 member


--Apple-Mail=_D03705CD-1289-4BD3-B6AE-E2BA5E80E1FF
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWImnAAAoJEHplpQeet0IZ7tgP/j7U7DEfcu7FKawUg+ujeyyq
4L/M2WlmDCkkMzbGE1aCHQZbxks9phBD7rX6Z8E/96h+3eip85uFi0jc42Dc8qxh
geak70Ri8oRpnd0nsbLY+s4DShViOJtbYH9EvqGn4pP0Dme/OGIyDtqdCu/bYWyE
h9z8ebKV0puClMJnjbzgBeB0VmEki37YdpN3Bakaq4mp8xEJJ7v/HpUXvyKWGTFR
Jf7vgfb18yv0Z77Q3iBJADKiEHYoXJNOmqy7+L00RTFUv8Cx9607h735k/I0iLt5
QtDMkLwb8YioX8KCnHb34ejRKtzOrgQcX8AQMZmudt7wtuBXVPnhCNOsKy9rtjNU
zPE24ygYEBVg0ckbPrVD0khepa4b/jBc19RUczqOfCf+aId21CKiKjxfiA6AXxVw
FLRmyAZXEOlDA4BzMKJjIg3W343F29ssQYyTi/7FFe4X6+NAIqzud3yIlsoRvuHu
afnc6ot7HpXg5pUZ9B6HYrsCP7wNbXLEExYSrjAjQgUmdo+rrd+5A8CwqZ0oQJhs
b1VkWBxJlCyHLzDhIVgiHNpVZKVQg4HdSyXmJuHzmrWUKfXiU15NHgZICnkMzBbi
bpJTo4FynEcKf7OMbgNcqCJu7HiR560CIGOK92huz2q2m9vNZlCppQTItVabspxe
R/E/kX557EmW5U1TLLOQ
=iooE
-----END PGP SIGNATURE-----

--Apple-Mail=_D03705CD-1289-4BD3-B6AE-E2BA5E80E1FF--


From nobody Sat Oct 17 20:09:56 2015
Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3783A1A87F0 for <sidr@ietfa.amsl.com>; Sat, 17 Oct 2015 20:09:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OpwZNnHldr8Z for <sidr@ietfa.amsl.com>; Sat, 17 Oct 2015 20:09:52 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0129.outbound.protection.outlook.com [207.46.100.129]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 07E841A87D9 for <sidr@ietf.org>; Sat, 17 Oct 2015 20:09:51 -0700 (PDT)
Received: from CY1PR09MB0793.namprd09.prod.outlook.com (10.163.43.143) by CY1PR09MB0796.namprd09.prod.outlook.com (10.163.43.146) with Microsoft SMTP Server (TLS) id 15.1.300.14; Sun, 18 Oct 2015 03:09:47 +0000
Received: from CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) by CY1PR09MB0793.namprd09.prod.outlook.com ([10.163.43.143]) with mapi id 15.01.0300.010; Sun, 18 Oct 2015 03:09:48 +0000
From: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>
To: Sandra Murphy <sandy@tislabs.com>
Thread-Topic: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt
Thread-Index: AQHRCCz4wwoZaaJjcUiLCIPytNy8pZ5v0UuAgADBklI=
Date: Sun, 18 Oct 2015 03:09:47 +0000
Message-ID: <CY1PR09MB0793422D9283EF98031B05E1843B0@CY1PR09MB0793.namprd09.prod.outlook.com>
References: <SN1PR09MB079938B1A44171328C0B16CA846A0@SN1PR09MB0799.namprd09.prod.outlook.com> <D20B8CAC.45839%dougm@nist.gov> <CY1PR09MB079376AC097FDDB73531814184690@CY1PR09MB0793.namprd09.prod.outlook.com> <m2613ca3kf.wl%randy@psg.com> <0F44566E-2054-4ECA-83AF-EE39585E841E@tislabs.com>, <CANTg3aCvdCKY+BfJ9G0dtJpQth=ckud=pmYyY4rKJh_V2A+7fQ@mail.gmail.com> <CY1PR09MB0793A1FDB2C6AE9FE72114EC843D0@CY1PR09MB0793.namprd09.prod.outlook.com>, <A2062B52-F6E8-4C8D-B1B9-02C5DD57E548@tislabs.com>
In-Reply-To: <A2062B52-F6E8-4C8D-B1B9-02C5DD57E548@tislabs.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=kotikalapudi.sriram@nist.gov; 
x-originating-ip: [129.6.218.148]
x-microsoft-exchange-diagnostics: 1; CY1PR09MB0796; 5:FGHac2p43/M7sviYd8YvrsUN+kEiToTYMUYg3VeZ7mioyK97nKvP6HYx2I+Pac3KcOGQg0W9U83+E9J3olPsdjo6krTRxQhag0PtsWkjh8LGP2SQHjS1fBiTQ3gLhN8neAbafh+Rv2nUSNW3SYHvHA==; 24:GopBw5WyaK/uTadlNsQg30YMYsrSrXhElU7eFqn75GHUkB6b1lqVKOtl7B4ElOBNituDlgVNXpqvStLTkUYh+TMKf7PWstJPm+h/1YaJuWg=; 20:mulBntgvlBj9Eeb8WjrmMsg4/FWhMGjN0ZuOJuhAqNSkpaX0lC7NLP4tVAzLwYugGmmt/T3NLAhBhcXWKtKDbg==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:CY1PR09MB0796;
x-microsoft-antispam-prvs: <CY1PR09MB0796CFF86E2F2A62C335F406843B0@CY1PR09MB0796.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(65766998875637);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(520078)(5005006)(8121501046)(3002001); SRVR:CY1PR09MB0796; BCL:0; PCL:0; RULEID:; SRVR:CY1PR09MB0796; 
x-forefront-prvs: 07334CBCCD
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(199003)(189002)(24454002)(377454003)(97736004)(76176999)(5008740100001)(102836002)(189998001)(5003600100002)(92566002)(86362001)(81156007)(106356001)(74316001)(19580395003)(5002640100001)(77096005)(5001960100002)(105586002)(10400500002)(230783001)(2900100001)(2950100001)(40100003)(110136002)(76576001)(5001920100001)(50986999)(106116001)(64706001)(66066001)(93886004)(87936001)(122556002)(99286002)(19580405001)(46102003)(101416001)(5007970100001)(33656002)(5004730100002)(54356999); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR09MB0796; H:CY1PR09MB0793.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Oct 2015 03:09:47.0329 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR09MB0796
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/4U9Ky6oZ2XkuNFmuAvNIlUHD7wA>
Cc: sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 18 Oct 2015 03:09:54 -0000

Ah, I see. I agree your interpretation is the correct one. So no change is =
necessary.=20
Thank you.

Sriram

________________________________________
From: Sandra Murphy <sandy@tislabs.com>
Sent: Saturday, October 17, 2015 11:30 AM
To: Sriram, Kotikalapudi
Cc: Sandra Murphy; Matthew Lepinski; sidr wg list
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-bgpsec-protocol-13.txt

speaking as a regular ol=92 member

On Oct 16, 2015, at 12:09 PM, Sriram, Kotikalapudi <kotikalapudi.sriram@nis=
t.gov> wrote:

>
>
> Substantive comment ....
>
> Looking at this on page 23,
>
> "BGPsec update messages do not contain an AS_PATH attribute.
>    Therefore, a BGPsec speaker MUST utilize the AS path information in
>    the BGPsec_Path attribute in all cases where it would otherwise use
>    the AS path information in the AS_PATH attribute.  The only exception
>    to this rule is when AS path information must be updated in order to
>    propagate a route to a peer (in which case the BGPsec speaker follows
>    the instructions in Section 4)."
>
> What is being said in the second sentence above is not clear.
>
> No exception applies if the peer is BGPsec capable and negotiated BGPsec.
>
> So is the exception for the case when the peer is non-BGPsec?
>
> May the fix is to replace this (current):
>
> "The only exception
>    to this rule is when AS path information must be updated in order to
>    propagate a route to a peer (in which case the BGPsec speaker follows
>    the instructions in Section 4)."
>
> with the following (proposed):
>
> The only exception
>    to this rule is when AS path information must be re-formatted to AS_PA=
TH in order to
>    propagate a route to a non-BGPsec peer (in which case the BGPsec speak=
er follows
>    the instructions in Section 4.4).
>


I read that sentence differently.

When BGP is propagating a route to a neighbor, it ordinarily appends its AS=
 to the AS_PATH.

The =93in all cases=94 would imply the same would happen in BPGsec, whether=
 the neighbor is bpgsec capable or not.

The exception is that, in the propagating case, BGPsec will instead follow =
section 4 - which covers bgpsec capable neighbors (embed AS in BGPsec_Path)=
 and bgpsec incapable neighbors (reconstruct AS_PATH).

I think your statement is correct, but I don=92t think it is what is meant =
here.

=97Sandy, speaking as a regular ol=92 member


From nobody Mon Oct 19 08:12:07 2015
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: sidr@ietf.org
Delivered-To: sidr@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B54651AC3D7; Mon, 19 Oct 2015 08:12:04 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Sender: <iesg-secretary@ietf.org>
Message-ID: <20151019151204.30268.25582.idtracker@ietfa.amsl.com>
Date: Mon, 19 Oct 2015 08:12:04 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/XZw2f_XhTgjmeIFJqyH4jFGIsp4>
Cc: sidr@ietf.org, sidr-chairs@ietf.org, draft-ietf-sidr-rfc6485bis@ietf.org, sandy@tislabs.com
Subject: [sidr] Last Call: <draft-ietf-sidr-rfc6485bis-04.txt> (The Profile for Algorithms and Key Sizes for use in the Resource Public Key Infrastructure) to Proposed Standard
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Reply-To: ietf@ietf.org
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 15:12:04 -0000

The IESG has received a request from the Secure Inter-Domain Routing WG
(sidr) to consider the following document:
- 'The Profile for Algorithms and Key Sizes for use in the Resource
   Public Key Infrastructure'
  <draft-ietf-sidr-rfc6485bis-04.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2015-11-02. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

Abstract


   This document specifies the algorithms, algorithms' parameters,
   asymmetric key formats, asymmetric key size, and signature format for
   the Resource Public Key Infrastructure (RPKI) subscribers that
   generate digital signatures on certificates, Certificate Revocation
   Lists (CRLs), Cryptographic Message Syntax (CMS) signed objects and
   certification requests as well as for the relying parties (RPs) that
   verify these digital signatures.


Downref:
Normative references are made to 3 Informational documents: RFC2986, RFC3447 and RFC6480.
RFC2986 and RFC3447 have been previously approved by the community (https://trac.tools.ietf.org/group/iesg/trac/wiki/DownrefRegistry).
RFC2986 and RFC6480 were also Downrefs in RFC6485, which this document obsoletes.


The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6485bis/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-sidr-rfc6485bis/ballot/


No IPR declarations have been submitted directly on this I-D.



From nobody Mon Oct 19 09:22:09 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietf.org
Delivered-To: sidr@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D77BA1A88D8; Mon, 19 Oct 2015 09:22:05 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151019162205.15865.68267.idtracker@ietfa.amsl.com>
Date: Mon, 19 Oct 2015 09:22:05 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/ORnuqIFgOlokhCnWulrlWWoVVr8>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-delta-protocol-01.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 16:22:06 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : RPKI Repository Delta Protocol
        Authors         : Tim Bruijnzeels
                          Oleg Muravskiy
                          Bryan Weber
                          Rob Austein
                          David Mandelberg
	Filename        : draft-ietf-sidr-delta-protocol-01.txt
	Pages           : 15
	Date            : 2015-10-19

Abstract:
   In the Resource Public Key Infrastructure (RPKI), certificate
   authorities publish certificates, including end entity certificates,
   and CRLs to repositories on repository servers.  Relying Parties (RP)
   retrieve the published information from the repository and MAY store
   it in a cache.  This document specifies a delta protocol which
   provides relying parties with a mechanism to query a repository for
   changes, thus enabling the RP to keep its state in sync with the
   repository.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-delta-protocol/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-delta-protocol-01

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-delta-protocol-01


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Mon Oct 19 13:36:47 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sidr@ietf.org
Delivered-To: sidr@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BDA11AC431; Mon, 19 Oct 2015 13:36:24 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.6.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20151019203624.26194.3376.idtracker@ietfa.amsl.com>
Date: Mon, 19 Oct 2015 13:36:24 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/oBx4mPPDPnc2sQ9R__20cZB-EJw>
Cc: sidr@ietf.org
Subject: [sidr] I-D Action: draft-ietf-sidr-rpki-oob-setup-03.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 20:36:24 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.

        Title           : An Out-Of-Band Setup Protocol For RPKI Production Services
        Author          : Rob Austein
	Filename        : draft-ietf-sidr-rpki-oob-setup-03.txt
	Pages           : 19
	Date            : 2015-10-19

Abstract:
   This note describes a simple out-of-band protocol to ease setup of
   the RPKI provisioning and publication protocols between two parties.
   The protocol is encoded in a small number of XML messages, which can
   be passed back and forth by any mutually agreeable secure means.

   This setup protocol is not part of the provisioning or publication
   protocol, rather, it is intended to simplify configuration of these
   protocols by setting up relationships and exchanging BPKI keying
   material.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sidr-rpki-oob-setup/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sidr-rpki-oob-setup-03

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sidr-rpki-oob-setup-03


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Mon Oct 19 13:39:18 2015
Return-Path: <sra@hactrn.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3AA931AC43B for <sidr@ietfa.amsl.com>; Mon, 19 Oct 2015 13:38:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E8CbKQFjN0kB for <sidr@ietfa.amsl.com>; Mon, 19 Oct 2015 13:38:54 -0700 (PDT)
Received: from adrilankha.hactrn.net (adrilankha.hactrn.net [IPv6:2001:418:1::19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2BC0D1ACCED for <sidr@ietf.org>; Mon, 19 Oct 2015 13:38:54 -0700 (PDT)
Received: from minas-ithil.hactrn.net (c-24-34-34-101.hsd1.ma.comcast.net [24.34.34.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "nargothrond.hactrn.net", Issuer "Grunchweather Associates" (verified OK)) by adrilankha.hactrn.net (Postfix) with ESMTPS id DCCD339828 for <sidr@ietf.org>; Mon, 19 Oct 2015 20:38:53 +0000 (UTC)
Received: from minas-ithil.hactrn.net (localhost [IPv6:::1]) by minas-ithil.hactrn.net (Postfix) with ESMTP id B59561D6121E for <sidr@ietf.org>; Mon, 19 Oct 2015 16:37:36 -0400 (EDT)
Date: Mon, 19 Oct 2015 16:37:36 -0400
From: Rob Austein <sra@hactrn.net>
To: sidr@ietf.org
In-Reply-To: <20151019203624.26194.3376.idtracker@ietfa.amsl.com>
References: <20151019203624.26194.3376.idtracker@ietfa.amsl.com>
User-Agent: Wanderlust/2.15.5 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset=US-ASCII
Message-Id: <20151019203736.B59561D6121E@minas-ithil.hactrn.net>
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/lQ0OMeSK9Gjc9MSF_YbvYcT7oFA>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-rpki-oob-setup-03.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 20:38:58 -0000

If you read last week's version, don't bother reading this one.

The only change was updating one of the references to point to the
current WG RRDP draft instead of the expired individual submission.


From nobody Mon Oct 19 17:49:22 2015
Return-Path: <sra@hactrn.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B7F01B2CA7 for <sidr@ietfa.amsl.com>; Mon, 19 Oct 2015 17:49:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3yMNDRm20dEo for <sidr@ietfa.amsl.com>; Mon, 19 Oct 2015 17:49:20 -0700 (PDT)
Received: from adrilankha.hactrn.net (adrilankha.hactrn.net [147.28.0.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28D8D1B2AF7 for <sidr@ietf.org>; Mon, 19 Oct 2015 17:49:20 -0700 (PDT)
Received: from minas-ithil.hactrn.net (c-24-34-34-101.hsd1.ma.comcast.net [24.34.34.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "nargothrond.hactrn.net", Issuer "Grunchweather Associates" (verified OK)) by adrilankha.hactrn.net (Postfix) with ESMTPS id DD23D39828 for <sidr@ietf.org>; Tue, 20 Oct 2015 00:49:19 +0000 (UTC)
Received: from minas-ithil.hactrn.net (localhost [IPv6:::1]) by minas-ithil.hactrn.net (Postfix) with ESMTP id 38E4D1D635D4 for <sidr@ietf.org>; Mon, 19 Oct 2015 20:48:02 -0400 (EDT)
Date: Mon, 19 Oct 2015 20:48:02 -0400
From: Rob Austein <sra@hactrn.net>
To: sidr@ietf.org
In-Reply-To: <20151019203736.B59561D6121E@minas-ithil.hactrn.net>
References: <20151019203624.26194.3376.idtracker@ietfa.amsl.com> <20151019203736.B59561D6121E@minas-ithil.hactrn.net>
User-Agent: Wanderlust/2.15.5 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset=US-ASCII
Message-Id: <20151020004802.38E4D1D635D4@minas-ithil.hactrn.net>
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/oUQn-TAu64Iqb4wDkKdS3NsZPhA>
Subject: [sidr] oob-translate.xsl (was Re: I-D Action: draft-ietf-sidr-rpki-oob-setup-03.txt)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 00:49:21 -0000

However, a bonus prize (which almost certainly doesn't belong in an
I-D anyway) for those who implemented portions of the original version
of this protocol: an XSL transform that translates between the
original version and the version specified in the I-D.  Currently at:

  http://subvert-rpki.hactrn.net/branches/tk705/potpourri/oob-translate.xsl

Still under development, doesn't cover all possible cases, but
probably covers the important ones.  Output passes RelaxNG validation.

People who've implemented the old version of this protocol please let
me know whether this works for the cases you care about.


From nobody Tue Oct 20 04:32:34 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DAA211B3326 for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 04:32:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id faJaUks-QZgl for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 04:32:31 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B2931B3323 for <sidr@ietf.org>; Tue, 20 Oct 2015 04:32:31 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 03E3328B003D for <sidr@ietf.org>; Tue, 20 Oct 2015 07:32:30 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id A786D1F8035; Tue, 20 Oct 2015 07:32:29 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_1DC5E8A1-BC64-43D4-973C-AFE37E6E3EF6"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Tue, 20 Oct 2015 07:32:54 -0400
Message-Id: <4F0F4923-0B80-4BA9-946A-BDC8C1486F65@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/UwZa6P-GX9fDrzV4T9-iW1rvWOc>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] WGLCs in progress (one ends tomorrow), and other wg activity
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 11:32:34 -0000

--Apple-Mail=_1DC5E8A1-BC64-43D4-973C-AFE37E6E3EF6
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

Several working group actions are in progress.  One of them ends =
tomorrow, one on Friday and two next week.

WGLC in progress:

Ends Tomorrow!

[sidr] WGLC: draft-ietf-sidr-bgpsec-overview ENDING: 10/21/2015)
http://www.ietf.org/mail-archive/web/sidr/current/msg07297.html

End next week:

[sidr] WGLC on draft-ietf-sidr-bgpsec-pki-profiles-12 (ENDS 29-Oct-2015)
http://www.ietf.org/mail-archive/web/sidr/current/msg07332.html

[sidr] WGLC on draft-ietf-sidr-bgpsec-algs-11 (ENDS 30-Oct-2015)
http://www.ietf.org/mail-archive/web/sidr/current/msg07341.html


A request in progress to confirm the latest version satisfies wglc =
comments.

The request for confirmation ends on Friday 23 Oct, don=92t let the =
subject line confuse you.

Re: [sidr] WGLC: draft-ietf-sidr-rpsl-sig - End Jul 02 2015
http://www.ietf.org/mail-archive/web/sidr/current/msg07334.html

=97Sandy

--Apple-Mail=_1DC5E8A1-BC64-43D4-973C-AFE37E6E3EF6
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWJiZtAAoJEHplpQeet0IZtncQAJooqRtqvG5Bx83mhIWjJbP8
uB2DttGqkQh68UdU5SZQpP+kP6AKk5CCMLVxd65unj6NuVhkfWas0NkVQPhSZbvf
RslsFcJ0KcILEs9F5cNGci9ijIRg5cx6rp8VUmY8b7jismuOumLi/xYCaIfuSxGg
ibHRUhZruePn77UToiH7io2NSXZVXSA2gQbgWt+wwPZytkvzJysICjXdRwHeGn7d
7fwMegdyDJXBV2nsf4M4qFsuN9Qh9iwOOXfvdYAAg0DfYsHt4eoUUzJnCnWEEn9i
iDFwmKhQfo/cqxX5m/yglObKq74fh3XVAr9OgpGJMYR5olFNWjbDjsjlD7yavomC
gMqAJkvQC/2wL49WmODpal5JEQM44J8eA82CLzZghee7tv0sLpN6dkic7cBlB8md
GSrC5XU4TzMPEKu8Ts3eL6zVuOicCQDkMCW405kqniR7BRF9Hk3kmJLF+bAgMGy/
NUx78gqwNwCgXnf+RB8ikcTpfx0c2/mu8PE84wHPmEwkceSwq+iotZb+5a7MrPrs
3zjHDW9MprSKO2YkwHalDhdRVddvFGEq4/vz2aI2e1ybBEsScDA0uipTcswHuZsi
s8yyd6JlxQ0pUZj7EW8BENreAj6qH1KpJ7+NYeFCEuuB+iELD4s9mToJK5w1rh49
0xeJ7BHq1jXy0GUkMgZi
=gLEw
-----END PGP SIGNATURE-----

--Apple-Mail=_1DC5E8A1-BC64-43D4-973C-AFE37E6E3EF6--


From nobody Tue Oct 20 08:08:19 2015
Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0BD871B35DA; Tue, 20 Oct 2015 08:08:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NECS21v4XCKK; Tue, 20 Oct 2015 08:08:13 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0737.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::737]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 927E01B3471; Tue, 20 Oct 2015 08:01:54 -0700 (PDT)
Received: from SN1PR09MB0799.namprd09.prod.outlook.com (10.162.101.145) by SN1PR09MB0800.namprd09.prod.outlook.com (10.162.101.146) with Microsoft SMTP Server (TLS) id 15.1.300.14; Tue, 20 Oct 2015 15:01:36 +0000
Received: from SN1PR09MB0799.namprd09.prod.outlook.com ([10.162.101.145]) by SN1PR09MB0799.namprd09.prod.outlook.com ([10.162.101.145]) with mapi id 15.01.0300.010; Tue, 20 Oct 2015 15:01:36 +0000
From: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>
To: "idr@ietf.org" <idr@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-idr-route-leak-detection-mitigation-01.txt
Thread-Index: AQHRCroALjIarZRc5UG7WVkGh6cKsZ50d37w
Date: Tue, 20 Oct 2015 15:01:35 +0000
Message-ID: <SN1PR09MB0799F875835DA02F5F89F39684390@SN1PR09MB0799.namprd09.prod.outlook.com>
References: <20151019220332.9222.33714.idtracker@ietfa.amsl.com>
In-Reply-To: <20151019220332.9222.33714.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=kotikalapudi.sriram@nist.gov; 
x-originating-ip: [129.6.140.100]
x-microsoft-exchange-diagnostics: 1; SN1PR09MB0800; 5:dH/yMiDR9pd5dyp7VRp9t/teDChPca0DsO07Plj9b8aRQs8Bf++Y9iU0PvUcxD+UL7aniHtmqZB8mmmBWiYDwiJ7JnibQYoAAWyLdN7juC0oXG8NIASVezM2/vG9dJaFygit8V4StLeYx7DAoDx1kw==; 24:OoRGuOTTgrUq3zDSOeJ6y+C1KBGbrMYfualoS2OE7H39dU+uRBLbMY3OOK+ZZqiFz7XUi1rAAeeJqEyA+3LxfJe7F+R8eHQ97yrD77Btwig=; 20:2dpWjJGcw+pX/wQNaGAFjDfa1gVfXzuXmIsIZoY4dajxVQ8U84QzlgdOXiA6DwKztQOvJ6D0CPVC6o1aq/sLeg==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:SN1PR09MB0800;
x-microsoft-antispam-prvs: <SN1PR09MB08009F86AE9D4C39366837E684390@SN1PR09MB0800.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(95692535739014)(51492898944892)(65766998875637); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(520078)(8121501046)(3002001); SRVR:SN1PR09MB0800; BCL:0; PCL:0; RULEID:; SRVR:SN1PR09MB0800; 
x-forefront-prvs: 073515755F
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(13464003)(199003)(377454003)(377424004)(189002)(66066001)(122556002)(230783001)(76176999)(2501003)(189998001)(97736004)(81156007)(40100003)(5004730100002)(106116001)(11100500001)(5003600100002)(5007970100001)(101416001)(99286002)(106356001)(5008740100001)(2900100001)(19580395003)(92566002)(4001150100001)(19580405001)(87936001)(54356999)(64706001)(2950100001)(77096005)(74316001)(50986999)(5001920100001)(102836002)(86362001)(15975445007)(450100001)(10400500002)(110136002)(5001960100002)(46102003)(76576001)(2351001)(33656002)(105586002)(5002640100001); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR09MB0800; H:SN1PR09MB0799.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Oct 2015 15:01:35.9392 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR09MB0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/fCbQgNxzCfUA59Ky6f07jiPhx4A>
Cc: "sidr wg list \(sidr@ietf.org\)" <sidr@ietf.org>
Subject: Re: [sidr] New Version Notification for draft-ietf-idr-route-leak-detection-mitigation-01.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 15:08:17 -0000

V2UgKGF1dGhvcnMpIGhhdmUgbWFkZSBhIHNpZ25pZmljYW50IGNoYW5nZXMvdXBkYXRlcyBpbiB0
aGlzIG5ldyB2ZXJzaW9uLTAxIA0Kb2YgdGhlIHJvdXRlIGxlYWtzIHNvbHV0aW9uIGRyYWZ0LiBU
aGUgY2hhbmdlcyBhcmUgYXMgZm9sbG93Og0KDQoxLiAgVGhlIHJvdXRlIGxlYWsgdHlwZXMgYXJl
IHJlYWxpZ25lZCB3aXRoIHRoZSBuZXcgb3JkZXIgdGhhdCBpcyB1c2VkIGluIHRoZSBuZXcgDQp2
ZXJzaW9uLTAzIG9mIHRoZSByb3V0ZSBsZWFrcyBkZWZpbml0aW9uIGRyYWZ0IHRoYXQgaXMgaW4g
cHJvZ3Jlc3MgaW4gdGhlIEdST1cgV0c6DQpodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJh
ZnQtaWV0Zi1ncm93LXJvdXRlLWxlYWstcHJvYmxlbS1kZWZpbml0aW9uLTAzICANCg0KMi4gU2V2
ZXJhbCBjb21tZW50cywgc3VnZ2VzdGlvbnMgdGhhdCB3ZXJlIHJlY2VpdmVkIG9uIHRoZSBtYWls
aW5nIGxpc3RzIHByaW9yIHRvIFByYWd1ZSwgDQphdCB0aGUgSURSIGludGVyaW0gKHdlYmV4KSBt
ZWV0aW5nIGluIEp1bHksIGFuZCBhdCB0aGUgU0lEUiBtZWV0aW5nIGluIFByYWd1ZSANCmhhdmUg
YmVlbiBpbmNvcnBvcmF0ZWQuDQoNCjIuIFdlIHByb3ZpZGUgYSBzaW1wbGVyLCBjbGVhcmVyIGRl
c2NyaXB0aW9uIG9mIHRoZSByb3V0ZSBsZWFrIGRldGVjdGlvbiBhbGdvcml0aG0gKHNlZSBTZWN0
aW9uIDMpLg0KDQozLiBJbiBTZWN0aW9uIDUuMSwgd2UgaGF2ZSBhZGRlZCBkaXNjdXNzaW9ucyBv
ZiB1cGdyYWRlIGFuZCBkb3duZ3JhZGUNCmF0dGFjayBwb3NzaWJpbGl0aWVzIChpbiB0aGUgYWJz
ZW5jZSBvZiBCR1BzZWMgc2VjdXJpdHkgcHJvdGVjdGlvbiBmb3IgdGhlIFJMUCBiaXRzKS4NClRo
aXMgdG9waWMgd2FzIGRpc2N1c3NlZCBvbiB0aGUgSURSIGxpc3QgaW4gSnVseSBhbmQgDQp3YXMg
cHJlc2VudGVkIGFuZCBkaXNjdXNzZWQgYXQgdGhlIFNJRFIgV0cgbWVldGluZyBpbiBQcmFndWUu
DQoNCjQuIFNlY3Rpb24gNS4yIGlzIG5ldyBhbmQgZGlzY3Vzc2VzIHRoZSB0b3BpYyDigJxBcmUg
dGhlcmUgY2FzZXMgDQp3aGVuIHZhbGxleS1mcmVlIHZpb2xhdGlvbnMgY2FuIGJlIGNvbnNpZGVy
ZWQgbGVnaXRpbWF0ZT/igJnigJkNClRoaXMgcXVlc3Rpb24gd2FzIGRpc2N1c3NlZCBicmllZmx5
IGF0IHRoZSBTSURSIFdHIG1lZXRpbmcgaW4gUHJhZ3VlLiANCg0KNi4gS2V5dXIgUGF0ZWwgYW5k
IEFuZHJlaSBSb2JhY2hldnNreSBoYXZlIGJlZW4gY29udHJpYnV0aW5nLCBhbmQgaGF2ZSBqb2lu
ZWQgaW4gYXMgYXV0aG9ycy4gICAgIA0KDQpTcmlyYW0NCg0KLS0tLS1PcmlnaW5hbCBNZXNzYWdl
LS0tLS0NCkZyb206IGludGVybmV0LWRyYWZ0c0BpZXRmLm9yZyBbbWFpbHRvOmludGVybmV0LWRy
YWZ0c0BpZXRmLm9yZ10gDQpTZW50OiBNb25kYXksIE9jdG9iZXIgMTksIDIwMTUgNjowNCBQTQ0K
VG86IEJyaWFuIERpY2tzb24gPGJyaWFuLnBldGVyLmRpY2tzb25AZ21haWwuY29tPjsgTW9udGdv
bWVyeSwgRG91Z2xhcyA8ZG91Z21AbmlzdC5nb3Y+OyBLZXl1ciBQYXRlbCA8a2V5dXBhdGVAY2lz
Y28uY29tPjsgQW5kcmVpIFJvYmFjaGV2c2t5IDxyb2JhY2hldnNreUBpc29jLm9yZz47IFNyaXJh
bSwgS290aWthbGFwdWRpIDxrb3Rpa2FsYXB1ZGkuc3JpcmFtQG5pc3QuZ292Pg0KU3ViamVjdDog
TmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZvciBkcmFmdC1pZXRmLWlkci1yb3V0ZS1sZWFrLWRl
dGVjdGlvbi1taXRpZ2F0aW9uLTAxLnR4dA0KDQoNCkEgbmV3IHZlcnNpb24gb2YgSS1ELCBkcmFm
dC1pZXRmLWlkci1yb3V0ZS1sZWFrLWRldGVjdGlvbi1taXRpZ2F0aW9uLTAxLnR4dA0KaGFzIGJl
ZW4gc3VjY2Vzc2Z1bGx5IHN1Ym1pdHRlZCBieSBLb3Rpa2FsYXB1ZGkgU3JpcmFtIGFuZCBwb3N0
ZWQgdG8gdGhlIElFVEYgcmVwb3NpdG9yeS4NCg0KTmFtZToJCWRyYWZ0LWlldGYtaWRyLXJvdXRl
LWxlYWstZGV0ZWN0aW9uLW1pdGlnYXRpb24NClJldmlzaW9uOgkwMQ0KVGl0bGU6CQlNZXRob2Rz
IGZvciBEZXRlY3Rpb24gYW5kIE1pdGlnYXRpb24gb2YgQkdQIFJvdXRlIExlYWtzDQpEb2N1bWVu
dCBkYXRlOgkyMDE1LTEwLTE5DQpHcm91cDoJCWlkcg0KUGFnZXM6CQkxOA0KVVJMOiAgICAgICAg
ICAgIGh0dHBzOi8vd3d3LmlldGYub3JnL2ludGVybmV0LWRyYWZ0cy9kcmFmdC1pZXRmLWlkci1y
b3V0ZS1sZWFrLWRldGVjdGlvbi1taXRpZ2F0aW9uLTAxLnR4dA0KU3RhdHVzOiAgICAgICAgIGh0
dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvZG9jL2RyYWZ0LWlldGYtaWRyLXJvdXRlLWxlYWst
ZGV0ZWN0aW9uLW1pdGlnYXRpb24vDQpIdG1saXplZDogICAgICAgaHR0cHM6Ly90b29scy5pZXRm
Lm9yZy9odG1sL2RyYWZ0LWlldGYtaWRyLXJvdXRlLWxlYWstZGV0ZWN0aW9uLW1pdGlnYXRpb24t
MDENCkRpZmY6ICAgICAgICAgICBodHRwczovL3d3dy5pZXRmLm9yZy9yZmNkaWZmP3VybDI9ZHJh
ZnQtaWV0Zi1pZHItcm91dGUtbGVhay1kZXRlY3Rpb24tbWl0aWdhdGlvbi0wMQ0KDQpBYnN0cmFj
dDoNCiAgIEluIFtJLUQuaWV0Zi1ncm93LXJvdXRlLWxlYWstcHJvYmxlbS1kZWZpbml0aW9uXSwg
dGhlIGF1dGhvcnMgaGF2ZQ0KICAgcHJvdmlkZWQgYSBkZWZpbml0aW9uIG9mIHRoZSByb3V0ZSBs
ZWFrIHByb2JsZW0sIGFuZCBhbHNvIGVudW1lcmF0ZWQNCiAgIHNldmVyYWwgdHlwZXMgb2Ygcm91
dGUgbGVha3MuICBJbiB0aGlzIGRvY3VtZW50LCB3ZSBmaXJzdCBleGFtaW5lDQogICB3aGljaCBv
ZiB0aG9zZSByb3V0ZS1sZWFrIHR5cGVzIGFyZSBkZXRlY3RlZCBhbmQgbWl0aWdhdGVkIGJ5IHRo
ZQ0KICAgZXhpc3Rpbmcgb3JpZ2luIHZhbGlkYXRpb24gKE9WKSBbUkZDIDY4MTFdIGFuZCBCR1BT
RUMgcGF0aCB2YWxpZGF0aW9uDQogICBbSS1ELmlldGYtc2lkci1iZ3BzZWMtcHJvdG9jb2xdLiAg
V2hlcmUgdGhlIGN1cnJlbnQgT1YgYW5kIEJHUFNFQw0KICAgcHJvdG9jb2xzIGRvbid0IG9mZmVy
IGEgc29sdXRpb24sIHRoaXMgZG9jdW1lbnQgc3VnZ2VzdHMgYW4NCiAgIGVuaGFuY2VtZW50IHRo
YXQgd291bGQgZXh0ZW5kIHRoZSByb3V0ZS1sZWFrIGRldGVjdGlvbiBhbmQgbWl0aWdhdGlvbg0K
ICAgY2FwYWJpbGl0eSBvZiBCR1BTRUMuICBUaGUgc29sdXRpb24gY2FuIGJlIGltcGxlbWVudGVk
IGluIEJHUCB3aXRob3V0DQogICBuZWNlc3NhcmlseSB0eWluZyBpdCB0byBCR1BTRUMuICBJbmNv
cnBvcmF0aW5nIHRoZSBzb2x1dGlvbiBpbiBCR1BTRUMNCiAgIGlzIG9uZSB3YXkgb2YgaW1wbGVt
ZW50aW5nIGl0IGluIGEgc2VjdXJlIHdheS4gIFdlIGRvIG5vdCBjbGFpbSB0bw0KICAgaGF2ZSBw
cm92aWRlZCBhIHNvbHV0aW9uIGZvciBhbGwgcG9zc2libGUgdHlwZXMgb2Ygcm91dGUgbGVha3Ms
IGJ1dA0KICAgdGhlIHNvbHV0aW9uIGNvdmVycyBzZXZlcmFsLCBlc3BlY2lhbGx5IGNvbnNpZGVy
aW5nIHNvbWUgc2lnbmlmaWNhbnQNCiAgIHJvdXRlLWxlYWsgYXR0YWNrcyBvciBvY2N1cnJlbmNl
cyB0aGF0IGhhdmUgYmVlbiBvYnNlcnZlZCBpbiByZWNlbnQNCiAgIHllYXJzLiAgVGhlIGRvY3Vt
ZW50IGFsc28gaW5jbHVkZXMgYSBzdG9wZ2FwIG1ldGhvZCBmb3IgZGV0ZWN0aW9uIGFuZA0KICAg
bWl0aWdhdGlvbiBvZiByb3V0ZSBsZWFrcyBmb3IgdGhlIHBoYXNlIHdoZW4gQkdQU0VDIChwYXRo
IHZhbGlkYXRpb24pDQogICBpcyBub3QgeWV0IGRlcGxveWVkIGJ1dCBvbmx5IG9yaWdpbiB2YWxp
ZGF0aW9uIGlzIGRlcGxveWVkLg0KDQoNCg==


From nobody Tue Oct 20 10:06:26 2015
Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B076E1ACCE0 for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 10:06:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AZpvERcXNwhn for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 10:06:23 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0107.outbound.protection.outlook.com [207.46.100.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3762E1ACC83 for <sidr@ietf.org>; Tue, 20 Oct 2015 10:06:23 -0700 (PDT)
Received: from SN1PR09MB0799.namprd09.prod.outlook.com (10.162.101.145) by SN1PR09MB0798.namprd09.prod.outlook.com (10.162.101.144) with Microsoft SMTP Server (TLS) id 15.1.300.14; Tue, 20 Oct 2015 17:06:21 +0000
Received: from SN1PR09MB0799.namprd09.prod.outlook.com ([10.162.101.145]) by SN1PR09MB0799.namprd09.prod.outlook.com ([10.162.101.145]) with mapi id 15.01.0300.010; Tue, 20 Oct 2015 17:06:21 +0000
From: "Sriram, Kotikalapudi" <kotikalapudi.sriram@nist.gov>
To: "Stephen Kent (kent@bbn.com)" <kent@bbn.com>, "sidr wg list (sidr@ietf.org)" <sidr@ietf.org>
Thread-Topic: New Version Notification for draft-sriram-replay-protection-design-discussion-05.txt
Thread-Index: AQHRCsgx63Hz4NMkw0C45R4kayT6dJ50k9DQ
Date: Tue, 20 Oct 2015 17:06:21 +0000
Message-ID: <SN1PR09MB0799B4B9115CE2C71D41644E84390@SN1PR09MB0799.namprd09.prod.outlook.com>
References: <20151019234507.4182.51437.idtracker@ietfa.amsl.com>
In-Reply-To: <20151019234507.4182.51437.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=kotikalapudi.sriram@nist.gov; 
x-originating-ip: [129.6.140.100]
x-microsoft-exchange-diagnostics: 1; SN1PR09MB0798; 5:ITu5VvDkROypy1Shy43GA/3c+0A0NM/E7OrybpURxFPp0clT7FOQWjpvnXM/J306K88McobwNomCHt7g38ZvkfAGEGU1WJ2l+5sQm5O68R/Wk112ggXKXqMJD40tJZsz34MnaKX8Fpi/n9Wg33b+eQ==; 24:cyIDIoG0VHc1U1kstJWxGw7rUq7ug0tA+QxougDT96VSYqCCFeqNfIbOMh2jJfLLyaupxW+Agqp196jOnaIuTUog+ozwrd81yWs6FLv8TO4=; 20:ODxOwLODPmyoRG6jjxx32jmdEOkdf1uVrEYQg3N1CDXXR2f3vCCgSg3j/2NtyP8QTsI0pZrZtRKJBFppyZ5QkA==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:SN1PR09MB0798;
x-microsoft-antispam-prvs: <SN1PR09MB079832E0713115B9F762BFFB84390@SN1PR09MB0798.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(65766998875637);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(520078)(5005006)(8121501046)(3002001); SRVR:SN1PR09MB0798; BCL:0; PCL:0; RULEID:; SRVR:SN1PR09MB0798; 
x-forefront-prvs: 073515755F
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(377424004)(189002)(199003)(377454003)(13464003)(92566002)(107886002)(33656002)(106116001)(101416001)(5008740100001)(99286002)(106356001)(46102003)(105586002)(230783001)(50986999)(54356999)(76176999)(10400500002)(4001150100001)(86362001)(2900100001)(97736004)(2950100001)(102836002)(81156007)(77096005)(76576001)(15975445007)(5001960100002)(5001770100001)(74316001)(11100500001)(64706001)(66066001)(19580405001)(5004730100002)(122556002)(19580395003)(5007970100001)(40100003)(5002640100001)(5003600100002)(189998001)(87936001); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR09MB0798; H:SN1PR09MB0799.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Oct 2015 17:06:21.3124 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR09MB0798
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/j1PQ8wQzdW7k48ZaBe7NwrW3CB4>
Subject: Re: [sidr] New Version Notification for draft-sriram-replay-protection-design-discussion-05.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 17:06:25 -0000

V2UgKGF1dGhvcnMpIGhhdmUgbWFkZSBzaWduaWZpY2FudCBjaGFuZ2VzL3VwZGF0ZXMgaW4gdGhp
cyBuZXcgdmVyc2lvbi0wNSANCm9mIHRoZSBpbmRpdmlkdWFsIEktRC4gZHJhZnQtc3JpcmFtLXJl
cGxheS1wcm90ZWN0aW9uLWRlc2lnbi1kaXNjdXNzaW9uLiANClRoZSBkcmFmdCBoYWQgYmVlbiBp
biBrZWVwLWFsaXZlIG1vZGUuIEJ1dCBub3cgdGhhdCB0aGVyZSBpcyByZW5ld2FsIG9mIGludGVy
ZXN0DQppbiB0aGlzIHRvcGljIHdpdGggdGhlIHJldmlzZWQvdXBkYXRlZCB2ZXJzaW9ucyBvZiBb
ZHJhZnQtaWV0Zi1zaWRyLWJncHNlYy1yb2xsb3Zlcl0gaW4gTWFyY2ggDQphbmQgSnVseSAyMDE1
LCB3ZSBkZWNpZGVkIHRvIHVwZGF0ZSB0aGUgcmVwbGF5LXByb3RlY3Rpb24gZGVzaWduIGRpc2N1
c3Npb24gZHJhZnQgYXMgd2VsbC4NCg0KSW4gcHJpdmF0ZSBlbWFpbHMgdG8gdGhlIGF1dGhvcnMg
KGJhY2sgaW4gT2N0b2JlciwgTm92ZW1iZXIgMjAxMyksIA0KU3RldmUgS2VudCBoYWQgZ2l2ZW4g
dXMgZXh0ZW5zaXZlIGNvbW1lbnRzIGFuZCBzdWdnZXN0aW9ucyBvbiB2ZXJzaW9uLTAyIG9mIHRo
ZSBkcmFmdC4gDQpbU29ycnksIFN0ZXZlLCBmb3IgcG9zdHBvbmluZyBpdCB1bnRpbCBub3cgYnV0
IHdlIGhhZCBuZXZlciBmb3Jnb3R0ZW4gaXQuIA0KQW5kIHRoYW5rIHlvdSBvbmNlIGFnYWluLl0g
DQoNCldlIGhhdmUgaW5jb3Jwb3JhdGVkIG1vc3Qgb2YgU3RldmUncyBjb21tZW50cy9zdWdnZXN0
aW9ucyBpbiB0aGlzIG5ldyB2ZXJzaW9uLiANCkhlIHN1Z2dlc3RlZCBjaGFuZ2luZyB0aGUgInJl
cGxheSBhdHRhY2siIG5hbWUgdG8gc29tZXRoaW5nIGJldHRlciB0aGF0IHJlY29nbml6ZXMgdGhh
dCANCml0IGlzIGFjdHVhbGx5IHdpdGhkcmF3YWwgc3VwcHJlc3Npb24gbW9yZSBvZnRlbiB0aGFu
IHJlcGxheS4gDQpTbyBpbiB0aGlzIG5ldyB2ZXJzaW9uLCB3ZSBoYXZlIGNvaW5lZCBhIG5ldyBu
YW1lIGFuZCBhY3JvbnltIHRoYXQgY292ZXJzIGJvdGg6DQpSZXBsYXkgQXR0YWNrIGFuZCBXaXRo
ZHJhd2FsIFN1cHByZXNzaW9uIChSQVdTKSANClRoYXQgbmFtZSBzZWVtcyB0byBoYXZlIHNlcnZl
ZCB0aGUgcHVycG9zZSB3ZWxsIGluIHRoaXMgcmV2aXNlZCBkb2MuIA0KV2UgZmVlbCB0aGF0IHRo
ZSBkb2N1bWVudCBub3cgaGFzIGdvb2QgY2xhcml0eSBhbmQgcHJlc2VudGF0aW9uIGR1ZSB0byAN
ClN0ZXZlJ3Mgc3VnZ2VzdGlvbnMgYXMgd2VsbCBhcyBzb21lIG9mIG91ciBvd24gcmV0aGlua2lu
Zy4gIA0KDQpGZWVkYmFjaywgY29tbWVudHMgYXJlIHdlbGNvbWUgb24gdGhlIHVwZGF0ZWQgZHJh
ZnQuIFRoYW5rIHlvdS4NCg0KU3JpcmFtDQoNCi0tLS0tT3JpZ2luYWwgTWVzc2FnZS0tLS0tDQpG
cm9tOiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmcgW21haWx0bzppbnRlcm5ldC1kcmFmdHNAaWV0
Zi5vcmddIA0KU2VudDogTW9uZGF5LCBPY3RvYmVyIDE5LCAyMDE1IDc6NDUgUE0NClRvOiBNb250
Z29tZXJ5LCBEb3VnbGFzIDxkb3VnbUBuaXN0Lmdvdj47IFNyaXJhbSwgS290aWthbGFwdWRpIDxr
b3Rpa2FsYXB1ZGkuc3JpcmFtQG5pc3QuZ292Pg0KU3ViamVjdDogTmV3IFZlcnNpb24gTm90aWZp
Y2F0aW9uIGZvciBkcmFmdC1zcmlyYW0tcmVwbGF5LXByb3RlY3Rpb24tZGVzaWduLWRpc2N1c3Np
b24tMDUudHh0DQoNCg0KQSBuZXcgdmVyc2lvbiBvZiBJLUQsIGRyYWZ0LXNyaXJhbS1yZXBsYXkt
cHJvdGVjdGlvbi1kZXNpZ24tZGlzY3Vzc2lvbi0wNS50eHQNCmhhcyBiZWVuIHN1Y2Nlc3NmdWxs
eSBzdWJtaXR0ZWQgYnkgS290aWthbGFwdWRpIFNyaXJhbSBhbmQgcG9zdGVkIHRvIHRoZQ0KSUVU
RiByZXBvc2l0b3J5Lg0KDQpOYW1lOgkJZHJhZnQtc3JpcmFtLXJlcGxheS1wcm90ZWN0aW9uLWRl
c2lnbi1kaXNjdXNzaW9uDQpSZXZpc2lvbjoJMDUNClRpdGxlOgkJRGVzaWduIERpc2N1c3Npb24g
YW5kIENvbXBhcmlzb24gb2YgUHJvdGVjdGlvbiBNZWNoYW5pc21zIGZvciBSZXBsYXkgQXR0YWNr
IGFuZCBXaXRoZHJhd2FsIFN1cHByZXNzaW9uIGluIEJHUHNlYw0KRG9jdW1lbnQgZGF0ZToJMjAx
NS0xMC0xOQ0KR3JvdXA6CQlJbmRpdmlkdWFsIFN1Ym1pc3Npb24NClBhZ2VzOgkJMTcNClVSTDog
ICAgICAgICAgICBodHRwczovL3d3dy5pZXRmLm9yZy9pbnRlcm5ldC1kcmFmdHMvZHJhZnQtc3Jp
cmFtLXJlcGxheS1wcm90ZWN0aW9uLWRlc2lnbi1kaXNjdXNzaW9uLTA1LnR4dA0KU3RhdHVzOiAg
ICAgICAgIGh0dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvZG9jL2RyYWZ0LXNyaXJhbS1yZXBs
YXktcHJvdGVjdGlvbi1kZXNpZ24tZGlzY3Vzc2lvbi8NCkh0bWxpemVkOiAgICAgICBodHRwczov
L3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtc3JpcmFtLXJlcGxheS1wcm90ZWN0aW9uLWRlc2ln
bi1kaXNjdXNzaW9uLTA1DQpEaWZmOiAgICAgICAgICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvcmZj
ZGlmZj91cmwyPWRyYWZ0LXNyaXJhbS1yZXBsYXktcHJvdGVjdGlvbi1kZXNpZ24tZGlzY3Vzc2lv
bi0wNQ0KDQpBYnN0cmFjdDoNCiAgIEluIHRoZSBjb250ZXh0IG9mIEJHUHNlYywgYSB3aXRoZHJh
d2FsIHN1cHByZXNzaW9uIG9jY3VycyB3aGVuIGFuDQogICBhZHZlcnNhcnkgQVMgc3VwcHJlc3Nl
cyBhIHByZWZpeCB3aXRoZHJhd2FsIHdpdGggdGhlIGludGVuc2lvbiBvZg0KICAgY29udGludWlu
ZyB0byBhdHRyYWN0IHRyYWZmaWMgZm9yIHRoYXQgcHJlZml4IGJhc2VkIG9uIGEgcHJldmlvdXMN
CiAgIChzaWduZWQgYW5kIHZhbGlkKSBCR1BzZWMgYW5ub3VuY2VtZW50IHRoYXQgd2FzIGVhcmxp
ZXIgcHJvcGFnYXRlZC4NCiAgIFN1YnNlcXVlbnRseSBpZiB0aGUgYWR2ZXJzYXJ5IEFTIGhhZCBh
IEJHUHNlYyBzZXNzaW9uIHJlc2V0IHdpdGggYQ0KICAgbmVpZ2hib3JpbmcgQkdQc2VjIHNwZWFr
ZXIgYW5kIHdoZW4gdGhlIHNlc3Npb24gaXMgcmVzdG9yZWQsIHRoZSBBUw0KICAgcmVwbGF5cyBz
YWlkIHByZXZpb3VzIEJHUHNlYyBhbm5vdW5jZW1lbnQgKGV2ZW4gdGhvdWdoIGl0IHdhcw0KICAg
d2l0aGRyYXduKSwgdGhlbiBzdWNoIGEgcmVwbGF5IGFjdGlvbiBpcyBjYWxsZWQgYSByZXBsYXkg
YXR0YWNrLiAgVGhlDQogICBCR1BzZWMgcHJvdG9jb2wgc2hvdWxkIGluY29ycG9yYXRlIGEgbWV0
aG9kIGZvciBwcm90ZWN0aW9uIGZyb20NCiAgIFJlcGxheSBBdHRhY2sgYW5kIFdpdGhkcmF3YWwg
U3VwcHJlc3Npb24gKFJBV1MpLCBhdCBsZWFzdCB0byBjb250cm9sDQogICB0aGUgd2luZG93IG9m
IGV4cG9zdXJlLiAgVGhpcyBpbmZvcm1hdGlvbmFsIGRvY3VtZW50IHByb3ZpZGVzIGRlc2lnbg0K
ICAgZGlzY3Vzc2lvbiBhbmQgY29tcGFyaXNvbiBvZiBtdWx0aXBsZSBhbHRlcm5hdGl2ZSBSQVdT
IHByb3RlY3Rpb24NCiAgIG1lY2hhbmlzbXMgd2VpZ2hpbmcgdGhlaXIgcHJvcyBhbmQgY29ucy4g
IFRoaXMgaXMgbWVhbnQgdG8gYmUgYQ0KICAgY29tcGFuaW9uIGRvY3VtZW50IHRvIHRoZSBzdGFu
ZGFyZHMgdHJhY2sgSS1ELi1pZXRmLXNpZHItYmdwc2VjLQ0KICAgcm9sbG92ZXIgdGhhdCB3aWxs
IHNwZWNpZnkgYSBtZXRob2QgdG8gYmUgdXNlZCB3aXRoIEJHUHNlYyBmb3IgUkFXUw0KICAgcHJv
dGVjdGlvbi4NCg0K


From nobody Tue Oct 20 16:10:54 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A80961A902B for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 16:10:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0tLSxWdD2Umc for <sidr@ietfa.amsl.com>; Tue, 20 Oct 2015 16:10:52 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 745551A902A for <sidr@ietf.org>; Tue, 20 Oct 2015 16:10:52 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id A071828B003D for <sidr@ietf.org>; Tue, 20 Oct 2015 19:10:51 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 873781F8035; Tue, 20 Oct 2015 19:10:51 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_D4209283-5764-4B29-BA9F-E03FB8B22AB2"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Tue, 20 Oct 2015 19:10:56 -0400
Message-Id: <81916335-8622-4807-96A6-B2D01618E048@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/K62ZOFF4DHxYbb7Ooqxqy9UKd30>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] draft agenda uploaded
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 23:10:53 -0000

--Apple-Mail=_D4209283-5764-4B29-BA9F-E03FB8B22AB2
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

The agenda has been uploaded.

Several people communicated their desire for time to speak at the =
meeting off-list, sometimes in person.

That is not the wisest move.

Those who believe they have requested time on the agenda, please do =
check the agenda for accuracy and completeness.  Send errors to the =
list.

The agenda is not full.  If you have topics you would like to discuss =
with the entire group, you may still request time on the agenda.

Revised agenda are due 2015-10-26 (Monday) UTC 23:59.

Note that there are special circumstances for the Friday morning =
meeting.  We are sharing the room with another wg during the session.  =
SIDR gets 90 minutes, the other wg gets 60.  Right now, the agenda says =
the other wg is opsec.  There=92s reason to think that will change to =
grow.

=97Sandy

--Apple-Mail=_D4209283-5764-4B29-BA9F-E03FB8B22AB2
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWJsoAAAoJEHplpQeet0IZC+AQAJ+jt7iI0T1e+uJCK+HmTsFU
DH0pgWekV0QUBYiQMjt+S/1lmkKlo7BnnfvkQyH1NWMEJWuqB/WkdpR20LOeHGKX
GgspbA5vtz80MopB+lwOnQ72uBUacr4XQLCVxk0WM1wMK8RK6jfAZCk5ytvo6POV
hVdSLueMuKH/aL+r/yXbrei8/pMDAaDtmn/y12GKOF7rZ5MVOaCs/WIgcjQ0U7A2
Y36Km7kjneXo1e2SSc2D+Y+D2YeZuHIz3e8ZWHRcs/4sVNAN5KBJEUt2FCHpkuiw
eMEh8VwsPjYUoUx+L0Z02sbbNnC4w3Ss5jr8l0ZdNTIYoyE9bXxi/++HG6UJuIvN
D4vOTVHbBuK7KJPq2Um/dCohpKPcDUmMABkkhHRhjA5No9Lj6ciu0qm7eiV7tJ/O
VIIEEGkfBDUGFBJx7ibBWVf3JwojS1ad24QMz8Z9+f62zc3fAYjRVXe6YvxFxhGD
WQ2c84vOdMvSBW+7kZst/6SRZx6U7nxVH4UFNuBaQPeyW4X9xx2Ghp9R0I7xa8el
l4xDWIoXuyeFNfVYpbM5bXaPhd5NSpOYcFzHvAYyoz5cErMCNZdS5L26tW3WxpFj
5E31oMW1sgTbeIL1Lr3+Z3hqCnKn41mZRK5LiVR2tPuA2PPPdPBe0fuN5pXa1nwG
VL8r1S+lpE+iWwNVtYLC
=BBII
-----END PGP SIGNATURE-----

--Apple-Mail=_D4209283-5764-4B29-BA9F-E03FB8B22AB2--


From nobody Wed Oct 21 05:03:31 2015
Return-Path: <oleg@ripe.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 03C091ACCEA for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 05:03:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 86xn6m5I45z9 for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 05:03:27 -0700 (PDT)
Received: from molamola.ripe.net (molamola.ripe.net [IPv6:2001:67c:2e8:11::c100:1371]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DF1D81ACCFF for <sidr@ietf.org>; Wed, 21 Oct 2015 05:03:26 -0700 (PDT)
Received: from titi.ripe.net ([193.0.23.11]) by molamola.ripe.net with esmtps (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.84) (envelope-from <oleg@ripe.net>) id 1Zos57-0006bd-86 for sidr@ietf.org; Wed, 21 Oct 2015 14:03:25 +0200
Received: from dog.ripe.net ([193.0.1.217] helo=[IPv6:::1]) by titi.ripe.net with esmtp (Exim 4.72) (envelope-from <oleg@ripe.net>) id 1Zos45-000464-01; Wed, 21 Oct 2015 14:00:21 +0200
From: Oleg Muravskiy <oleg@ripe.net>
Content-Type: multipart/signed; boundary="Apple-Mail=_D188E7DF-0009-4A84-BACA-6DD9BCA3DC5B"; protocol="application/pkcs7-signature"; micalg=sha1
Message-Id: <FD641551-8A7F-4702-8886-4632FA8EB83F@ripe.net>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Date: Wed, 21 Oct 2015 14:00:19 +0200
References: <20151019192516.30519.3725.idtracker@ietfa.amsl.com>
To: sidr@ietf.org
X-Mailer: Apple Mail (2.1878.6)
X-ACL-Warn: Delaying message
X-RIPE-Signature: c408758d4ce2e8eb06762a65a3365b74728f591c6b001381b3a590f744f023a7
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Ibk2O-u5D5k1xl1Kcqqr-VuJ9YA>
Subject: [sidr] Fwd: New Version Notification for draft-tbruijnzeels-sidr-validation-local-cache-02.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2015 12:03:29 -0000

--Apple-Mail=_D188E7DF-0009-4A84-BACA-6DD9BCA3DC5B
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

This is a new version of our individual submission I-D that describes =
the implementation of RIPE NCC's RPKI validator.

It is a complete rewrite from the previous version, so the diff in not =
very useful. It is still an initial revision, and more details will be =
added. In this version, the document is purely informational, and only =
contains the implementation description, no discussion topics. Our =
intention is to provide users of our validator with the description of =
it's validation algorithm, and gather feedback. It is not a WG item =
(yet?), but we want to get your opinion on whether having and =
maintaining such document is useful for the WG (or community in =
general), and whether we should expand it's content and purpose.

Cheers,
Oleg

Begin forwarded message:

> From: internet-drafts@ietf.org
> Subject: New Version Notification for =
draft-tbruijnzeels-sidr-validation-local-cache-02.txt
> Date: 19 Oct 2015 21:25:16 GMT+2
> To: "Tim Bruijnzeels" <tim@ripe.net>, "Oleg Muravskiy" <oleg@ripe.net>
>=20
>=20
> A new version of I-D, =
draft-tbruijnzeels-sidr-validation-local-cache-02.txt
> has been successfully submitted by Oleg Muravskiy and posted to the
> IETF repository.
>=20
> Name:		draft-tbruijnzeels-sidr-validation-local-cache
> Revision:	02
> Title:		RPKI Repository Validation Using Local Cache
> Document date:	2015-10-19
> Group:		Individual Submission
> Pages:		9
> URL:            =
https://www.ietf.org/internet-drafts/draft-tbruijnzeels-sidr-validation-lo=
cal-cache-02.txt
> Status:         =
https://datatracker.ietf.org/doc/draft-tbruijnzeels-sidr-validation-local-=
cache/
> Htmlized:       =
https://tools.ietf.org/html/draft-tbruijnzeels-sidr-validation-local-cache=
-02
> Diff:           =
https://www.ietf.org/rfcdiff?url2=3Ddraft-tbruijnzeels-sidr-validation-loc=
al-cache-02
>=20
> Abstract:
>   This document describes the approach to validate the content of the
>   RPKI repository, which is independent of a particular object
>   retrieval mechanism.  This allows it to be used with repositories
>   available over rsync protocol (see Section 3 of[RFC6481]), and delta
>   protocol ( [I-D.tbruijnzeels-sidr-delta-protocol]), as well as
>   repositories that use a mix of both.
>=20
>=20
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> The IETF Secretariat

--Apple-Mail=_D188E7DF-0009-4A84-BACA-6DD9BCA3DC5B
Content-Disposition: attachment;
	filename=smime.p7s
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIG8zCCBu8w
ggXXoAMCAQICCi6gUgsAAgAAA7cwDQYJKoZIhvcNAQEFBQAwYDETMBEGCgmSJomT8ixkARkWA25l
dDEUMBIGCgmSJomT8ixkARkWBHJpcGUxFjAUBgoJkiaJk/IsZAEZFgZzaW5nZWwxGzAZBgNVBAMT
EnNpbmdlbC1DSEFLT1RBWS1DQTAeFw0xNDEyMjMwNjA1MjlaFw0xNTEyMjMwNjA1MjlaMIGbMRMw
EQYKCZImiZPyLGQBGRYDbmV0MRQwEgYKCZImiZPyLGQBGRYEcmlwZTEWMBQGCgmSJomT8ixkARkW
BnNpbmdlbDERMA8GA1UECxMIYWNjb3VudHMxDDAKBgNVBAsTA0JBRDEXMBUGA1UEAxMOT2xlZyBN
dXJhdnNraXkxHDAaBgkqhkiG9w0BCQEWDW9sZWdAcmlwZS5uZXQwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQC5B2KHja5sh/t200nIyHcKJ812Iiq5r0jSXCO80/dCVbFyv7NsI1joXM3m
NURFNeXna89ydMOYb5WQXuvbgsE65Kkl8Nwo1ry7bmjG62kF/Cy+2kJnamOUMaE+D4En6eIAsICk
lrqql9RrwwIBY4PtOzsMHXEusQEDN+GBTMnWlANcxWotg7wcVbx3iLDQ3CW7Sne3RHnzPnRPYrLU
hubKl7a4BB/d1bQMjLYghCLudaXOcwPKGYbqgHrtBsC5An3ZIMZr6N2BKJqahYPj+LzGOIb4fXC2
+BAVKltlvqnnYfXUGIsGYmZvfpBKYjf1/cuqPFoSngOE/mI+dIQcBiWpAgMBAAGjggNtMIIDaTAX
BgkrBgEEAYI3FAIECh4IAFUAcwBlAHIwKQYDVR0lBCIwIAYKKwYBBAGCNwoDBAYIKwYBBQUHAwQG
CCsGAQUFBwMCMA4GA1UdDwEB/wQEAwIFoDBEBgkqhkiG9w0BCQ8ENzA1MA4GCCqGSIb3DQMCAgIA
gDAOBggqhkiG9w0DBAICAIAwBwYFKw4DAgcwCgYIKoZIhvcNAwcwHQYDVR0OBBYEFPV9DQczha7h
xGxUybLGS0e+dYkNMB8GA1UdIwQYMBaAFHFA2ZvEPKoU0iSyAcVgcifvgOuAMIIBFwYDVR0fBIIB
DjCCAQowggEGoIIBAqCB/4aBvWxkYXA6Ly8vQ049c2luZ2VsLUNIQUtPVEFZLUNBLENOPVBJS0Us
Q049Q0RQLENOPVB1YmxpYyUyMEtleSUyMFNlcnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3Vy
YXRpb24sREM9c2luZ2VsLERDPXJpcGUsREM9bmV0P2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/
YmFzZT9vYmplY3RDbGFzcz1jUkxEaXN0cmlidXRpb25Qb2ludIY9aHR0cDovL3Bpa2Uuc2luZ2Vs
LnJpcGUubmV0L0NlcnRFbnJvbGwvc2luZ2VsLUNIQUtPVEFZLUNBLmNybDCCATAGCCsGAQUFBwEB
BIIBIjCCAR4wgbgGCCsGAQUFBzAChoGrbGRhcDovLy9DTj1zaW5nZWwtQ0hBS09UQVktQ0EsQ049
QUlBLENOPVB1YmxpYyUyMEtleSUyMFNlcnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRp
b24sREM9c2luZ2VsLERDPXJpcGUsREM9bmV0P2NBQ2VydGlmaWNhdGU/YmFzZT9vYmplY3RDbGFz
cz1jZXJ0aWZpY2F0aW9uQXV0aG9yaXR5MGEGCCsGAQUFBzAChlVodHRwOi8vcGlrZS5zaW5nZWwu
cmlwZS5uZXQvQ2VydEVucm9sbC9QSUtFLnNpbmdlbC5yaXBlLm5ldF9zaW5nZWwtQ0hBS09UQVkt
Q0EoMikuY3J0MD4GA1UdEQQ3MDWgJAYKKwYBBAGCNxQCA6AWDBRvbGVnQHNpbmdlbC5yaXBlLm5l
dIENb2xlZ0ByaXBlLm5ldDANBgkqhkiG9w0BAQUFAAOCAQEAChlAWH3Hg24Ixyp0mvKh9Mc2mQTQ
1IwWNETLouozmkPeLNNZwSGlg1TJQiMKv+uWNKgEvVbCs/2l9Tp3behOo64w1hE81Ej7420BU96m
+FHd/S2FQekxomqPdGWYBiNYO2CK3GYVhPrVPAVIr/qLYRRADkG/+Ya73hLEKXLEyiLXXz2AQFJH
lt/5b+WwjI4TBVvMrqgvhFlL74/fJFNvcJvGQKyGWySazEtlum6j1iwDQHDcobQ31gCUb73EvuFw
NqR9XmaHni5tJO/Wp0bsFiQiYkY9ZWALz9axUQ6HFnpWxqrnxUbFEDL/HinVWFdek/B2jyE16Hit
QP0LT+kfFDGCAvYwggLyAgEBMG4wYDETMBEGCgmSJomT8ixkARkWA25ldDEUMBIGCgmSJomT8ixk
ARkWBHJpcGUxFjAUBgoJkiaJk/IsZAEZFgZzaW5nZWwxGzAZBgNVBAMTEnNpbmdlbC1DSEFLT1RB
WS1DQQIKLqBSCwACAAADtzAJBgUrDgMCGgUAoIIBXTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcB
MBwGCSqGSIb3DQEJBTEPFw0xNTEwMjExMjAwMjBaMCMGCSqGSIb3DQEJBDEWBBR7WDLfTk1dFkD3
zFcZvCGxcwXizjB9BgkrBgEEAYI3EAQxcDBuMGAxEzARBgoJkiaJk/IsZAEZFgNuZXQxFDASBgoJ
kiaJk/IsZAEZFgRyaXBlMRYwFAYKCZImiZPyLGQBGRYGc2luZ2VsMRswGQYDVQQDExJzaW5nZWwt
Q0hBS09UQVktQ0ECCi6gUgsAAgAAA7cwfwYLKoZIhvcNAQkQAgsxcKBuMGAxEzARBgoJkiaJk/Is
ZAEZFgNuZXQxFDASBgoJkiaJk/IsZAEZFgRyaXBlMRYwFAYKCZImiZPyLGQBGRYGc2luZ2VsMRsw
GQYDVQQDExJzaW5nZWwtQ0hBS09UQVktQ0ECCi6gUgsAAgAAA7cwDQYJKoZIhvcNAQEBBQAEggEA
Moo26Ya7Dbq/gsoysx72AhdKhdnlmqCw3/pP/Tz6M6J8/m/MRkxx5lf14OMtMMVJJskrO1NF/J3R
qMP+ylv+IbVLs5Ge6gz4/B25fzW7rIwRR+4a1hXwTFnZH13LgJ4PktFpJSV7cK/26fBHzLfU9AsV
FT+QQDVcOUH6SmfydaH289ozBeDYRoSmBsRhBCsleSQLFa+Sdh98nwjO2DkRoHZkCQaz7PiMsYrQ
umax2kFVqXkOS9hahwRYFFwum75i9V5Mshr5lQplq1SWwHR98raR8sCt5+4tXsRcTGUUWfvmbm5U
iQ9c0jvzpgz2AK2n9z4zK1RCsklohHaIr/ToVAAAAAAAAA==

--Apple-Mail=_D188E7DF-0009-4A84-BACA-6DD9BCA3DC5B--


From nobody Wed Oct 21 06:32:42 2015
Return-Path: <tim@ripe.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 325501A873B for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 06:32:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ktQOP_IO9Ehu for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 06:32:39 -0700 (PDT)
Received: from mahimahi.ripe.net (mahimahi.ripe.net [IPv6:2001:67c:2e8:11::c100:1372]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A40141A8724 for <sidr@ietf.org>; Wed, 21 Oct 2015 06:32:39 -0700 (PDT)
Received: from titi.ripe.net ([193.0.23.11]) by mahimahi.ripe.net with esmtps (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.84) (envelope-from <tim@ripe.net>) id 1ZotVM-0004hB-Li for sidr@ietf.org; Wed, 21 Oct 2015 15:32:38 +0200
Received: from sslvpn.ripe.net ([193.0.20.230] helo=vpn-131.ripe.net) by titi.ripe.net with esmtps (TLSv1:AES256-SHA:256) (Exim 4.72) (envelope-from <tim@ripe.net>) id 1ZotVM-00073R-3j for sidr@ietf.org; Wed, 21 Oct 2015 15:32:36 +0200
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2104\))
From: Tim Bruijnzeels <tim@ripe.net>
In-Reply-To: <20151019162205.15865.68267.idtracker@ietfa.amsl.com>
Date: Wed, 21 Oct 2015 15:32:35 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <7C0FD497-4D8A-4CC7-AF5A-6130D9A8C0FA@ripe.net>
References: <20151019162205.15865.68267.idtracker@ietfa.amsl.com>
To: sidr wg list <sidr@ietf.org>
X-Mailer: Apple Mail (2.2104)
X-ACL-Warn: Delaying message
X-RIPE-Spam-Level: --
X-RIPE-Spam-Report: Spam Total Points:   -2.9 points pts rule name              description ---- ---------------------- ------------------------------------ -1.0 ALL_TRUSTED            Passed through trusted hosts only via SMTP 0.0 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain -1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1% [score: 0.0000]
X-RIPE-Signature: 784d7acfe6559f2a0b602ec6519a0719b10ddcbef92526f82ba2e4d003a3e00d
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/LlRgbQf0pJn3hqqVHGY7DNgYKyk>
Subject: Re: [sidr] I-D Action: draft-ietf-sidr-delta-protocol-01.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2015 13:32:41 -0000

Hi all,

Changes in this version:
=3D Now using https consistently to retrieve notification, snapshot and =
delta files
=3D Simplified xml examples
=3D Simplified text on cache concerns
   - Leaving some of the discussion out of the document - but welcome to =
discuss on list
   - Lowering max time to cache 'notification.xml' to one minute only
     (enough to reduce load, and helps RPs get things faster)
=3D For now.. removed the hashes (checksums) for delta and snapshot =
files
   - an adversary who can modify snapshot/deltas fetched with https, can =
also modify the notification file
   - but.. we may put it back if there are other uses (file corruption, =
somehow?)
=3D Improved readability (without changing protocol)

Questions and comments welcome.

There is time planned for an update on this in Yokohama. I was *not* =
planning to go into an overview of the protocol again, but please let me =
know if you would value if I did. If there is enough interest in this =
then I am happy to ask the chairs for a bit more time and go over this =
once more, but if not then I would rather save everyone some time and =
only focus on the bits that changed and keep it brief.


Thanks

Tim


> On 19 Oct 2015, at 18:22, internet-drafts@ietf.org wrote:
>=20
>=20
> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> This draft is a work item of the Secure Inter-Domain Routing Working =
Group of the IETF.
>=20
>        Title           : RPKI Repository Delta Protocol
>        Authors         : Tim Bruijnzeels
>                          Oleg Muravskiy
>                          Bryan Weber
>                          Rob Austein
>                          David Mandelberg
> 	Filename        : draft-ietf-sidr-delta-protocol-01.txt
> 	Pages           : 15
> 	Date            : 2015-10-19
>=20
> Abstract:
>   In the Resource Public Key Infrastructure (RPKI), certificate
>   authorities publish certificates, including end entity certificates,
>   and CRLs to repositories on repository servers.  Relying Parties =
(RP)
>   retrieve the published information from the repository and MAY store
>   it in a cache.  This document specifies a delta protocol which
>   provides relying parties with a mechanism to query a repository for
>   changes, thus enabling the RP to keep its state in sync with the
>   repository.
>=20
>=20
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-sidr-delta-protocol/
>=20
> There's also a htmlized version available at:
> https://tools.ietf.org/html/draft-ietf-sidr-delta-protocol-01
>=20
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-sidr-delta-protocol-01
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>=20
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr


From nobody Wed Oct 21 10:11:38 2015
Return-Path: <housley@vigilsec.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 657F31B2ABA for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 10:11:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y2CMe4xrvpvC for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 10:11:35 -0700 (PDT)
Received: from odin.smetech.net (x-bolt-wan.smeinc.net [209.135.219.146]) by ietfa.amsl.com (Postfix) with ESMTP id AD7121B29DE for <sidr@ietf.org>; Wed, 21 Oct 2015 10:11:35 -0700 (PDT)
Received: from localhost (unknown [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id 3280CF2416E for <sidr@ietf.org>; Wed, 21 Oct 2015 13:11:25 -0400 (EDT)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id TZHVHppZ2c0e for <sidr@ietf.org>; Wed, 21 Oct 2015 13:10:24 -0400 (EDT)
Received: from [10.196.207.51] (122-194.icannmeeting.org [199.91.194.122]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id 9C6BBF24180 for <sidr@ietf.org>; Wed, 21 Oct 2015 13:11:12 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Date: Wed, 21 Oct 2015 13:11:00 -0400
Message-Id: <57F4BB8A-AB70-49C6-A9F7-EF435DCF8831@vigilsec.com>
To: IETF SIDR <sidr@ietf.org>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/J8zNEiN2PwLc4jLscHaIPdJbsfI>
Subject: [sidr] draft-ietf-sidr-rpki-validation-reconsidered-02
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2015 17:11:37 -0000

I noticed that an update to draft-ietf-sidr-rpki-validation-reconsidered =
has been posted.  I remain confused.

Section 3 includes these paragraphs:

   The first is that of the robustness of the operational management
   procedures in the issuance of certificates.  If a subordinate
   Certification Authority (CA) issues a certificate that contains an
   Internet Number Resource (INR) collection that is not either exactly
   equal to, or a strict subset of, its parent CA, then this issued
   certificate, and all subordinate certificates of this issued
   certificate are invalid.  These certificates are not only defined as
   invalid when being considered to validate an INR that is not in the
   parent CA certificate, but are defined as invalid for all INRs in the
   certificate.

   This constraint creates a degree of operational fragility in the
   issuance of certificates, as all CA's are now required to exercise
   extreme care in the issuance and reissuance of certificates to ensure
   that at no time do they overclaim on the resources described in the
   parent CA, as the consequences of an operational lapse or oversight
   implies that all the subordinate certificates from the point of INR
   mismatch are invalid.  It would be preferred if the consequences of
   such an operational lapse were limited in scope to the specific INRs
   that formed the mismatch, rather than including the entire set of
   INRs within the scope of damage from this point of mismatch downward
   across the entire sub-tree of descendant certificates in the RPKI
   certificate hierarchy.

I do not understand why it is hard for a CA to not overclaim.

I cannot figure out why a CA at any level of the RPKI would ever issue a =
certificate that includes INRs that are outside its scope.  =46rom =
previous discussions, I understand the desire to add INRs to one =
certificate before they are removed from another.  This seems to mean =
that the new INRs get added to the receiving CA and subordinate =
certificates before they are removed from the previous one.  Since this =
seems to work in a straightforward way, I'm just not seeing the =
motivation for this reconsideration.

Russ



From nobody Wed Oct 21 11:01:03 2015
Return-Path: <weiler@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D69BB1B2BFE for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 11:01:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wi320qbvectn for <sidr@ietfa.amsl.com>; Wed, 21 Oct 2015 11:01:00 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAAFD1B2BFC for <sidr@ietf.org>; Wed, 21 Oct 2015 11:01:00 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 08DEE28B0043 for <sidr@ietf.org>; Wed, 21 Oct 2015 14:01:00 -0400 (EDT)
Received: from nova.tislabs.com (nova.tislabs.com [10.66.1.77]) by nova.tislabs.com (Postfix) with ESMTP id E72B41F804E for <sidr@ietf.org>; Wed, 21 Oct 2015 14:00:59 -0400 (EDT)
Date: Wed, 21 Oct 2015 14:00:59 -0400 (EDT)
From: Samuel Weiler <weiler@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Message-ID: <alpine.LRH.2.03.1510211400250.22643@tislabs.com>
User-Agent: Alpine 2.03 (LRH 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format=flowed; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/PWoDohJaBfLBLKTN_Xp4VICIYxA>
Subject: Re: [sidr] posted: draft-huston-sidr-validity-00.txt
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2015 18:01:02 -0000

> You are joking - right?

No.

> I believe that this is a very clear, concise and accurate
> description of WHAT is being changed. i.e. go look up section 7.2 of
> RFC6487 and replace it with the procedure described in this
> document. What exactly gives you a problem with such a explanation
> of the proposed update to the RPKI validation procedure?

It is concise, accurate, and absolutely devoid of substance.  Try
telling the reader something that will make sense to a well-read
practitioner of the art without requiring reference to an external doc
or even reference within the doc.

-- Sam


From nobody Mon Oct 26 19:58:00 2015
Return-Path: <weiler@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9697D1B33AD for <sidr@ietfa.amsl.com>; Mon, 26 Oct 2015 19:57:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KttTMCfCMDLB for <sidr@ietfa.amsl.com>; Mon, 26 Oct 2015 19:57:58 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B0F91B33AE for <sidr@ietf.org>; Mon, 26 Oct 2015 19:57:57 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 7E86E28B003D for <sidr@ietf.org>; Mon, 26 Oct 2015 22:57:56 -0400 (EDT)
Received: from nova.tislabs.com (nova.tislabs.com [10.66.1.77]) by nova.tislabs.com (Postfix) with ESMTP id 37AAB1F8035 for <sidr@ietf.org>; Mon, 26 Oct 2015 22:57:56 -0400 (EDT)
Date: Mon, 26 Oct 2015 22:57:56 -0400 (EDT)
From: Samuel Weiler <weiler@tislabs.com>
To: sidr@ietf.org
Message-ID: <alpine.LRH.2.03.1510261740320.25993@tislabs.com>
User-Agent: Alpine 2.03 (LRH 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format=flowed; charset=US-ASCII
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/M8dgbPafs6mXNgs789hOG-9dT7s>
Subject: Re: [sidr] WGLC on draft-ietf-sidr-bgpsec-algs-11 (ENDS 30-Oct-2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Oct 2015 02:57:59 -0000

I have read the draft and have no objections to it going forward.

Suggestions:

Section 5 talks about some of the requirements for (future) algorithm and 
key size agility, but says "The recommended procedures to implement such a 
transition of key sizes and algorithms is not specified in this document." 
(sic)  I think it would be good to cite some discussion of that, e.g. 
section 6 of -protocol.  (I'm not saying that section 6 of -protocol is 
complete or great, but it may be the best set of words we have right now.)

Nail down the initial codepoint in the IANA registry (this doc is 
creating the registry, so we can be specific).  I suggest "1".


From nobody Wed Oct 28 16:51:44 2015
Return-Path: <sean@sn3rd.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E852D1B5F6E for <sidr@ietfa.amsl.com>; Wed, 28 Oct 2015 16:51:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jvD4Jnrv5J6V for <sidr@ietfa.amsl.com>; Wed, 28 Oct 2015 16:51:41 -0700 (PDT)
Received: from mail-pa0-x22a.google.com (mail-pa0-x22a.google.com [IPv6:2607:f8b0:400e:c03::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6B1D71B5F6D for <sidr@ietf.org>; Wed, 28 Oct 2015 16:51:41 -0700 (PDT)
Received: by padhk11 with SMTP id hk11so20937416pad.1 for <sidr@ietf.org>; Wed, 28 Oct 2015 16:51:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=2TEMHsh55nM9dCbOyMCqCGy6K+Zg1oW45kePRHv0DwA=; b=C6GQFo8/RNhdDFRMPsHkCfTpBnDVEQUNJYzDsnkqJ0h5gc3Rojz1sUYEnypeBqG00F WBhW0gC6E5tz/k8ZC03AFDY9ff/F06DewUsCOPoDNUEatTRvak2WftoeLBGZ8cHcVhXo 6jmJbENF87P4zCc0LmJL8gU+sIF3D6jnBp4uM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=2TEMHsh55nM9dCbOyMCqCGy6K+Zg1oW45kePRHv0DwA=; b=dSMffp/3XOVmq+2utniPJaLCdtQW/fJB6gJAWwwTYS4QRDQnT2KMo+YelRZiis4yGi RFA5rJcxoaZou3hBX/TJdEegnhwsYEN/4zdAIyhrNDNVOVkdRpmmWXao0AFbiRCeFJDn ukxjghmF7EcUxUNemTVnPDJeaYQuIFl3nyutuxRP5ml0AYggPswFOVNp6i24ANwLRAYS tNzTmmQEMgh4Y4B84j68RTjWu5+dBP1vbmIVXWwVjo8Blop+IEG64u2ngAwp+dotSyiW +BwkAPpqCy6oO1zXwk8RcotrKxuwLD1mv1FOjv3fkLy21HbWN7kUUYMHzhMvilGSl9ed aqmQ==
X-Gm-Message-State: ALoCoQnC2dp8qRjcEHZlRbrgc6nr/i4dnwzfwpF0dgXAvVGnOPNKjYTElEXZxpcXIfiuQVTSByBV
X-Received: by 10.68.139.2 with SMTP id qu2mr37476662pbb.135.1446076301022; Wed, 28 Oct 2015 16:51:41 -0700 (PDT)
Received: from [5.5.33.244] (vpn.snozzages.com. [204.42.252.17]) by smtp.gmail.com with ESMTPSA id l16sm47485424pbq.22.2015.10.28.16.51.38 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 28 Oct 2015 16:51:40 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 9.1 \(3096.5\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <alpine.LRH.2.03.1510261740320.25993@tislabs.com>
Date: Thu, 29 Oct 2015 08:51:37 +0900
Content-Transfer-Encoding: quoted-printable
Message-Id: <B410F584-389F-4A9A-9E0B-76484D5A0021@sn3rd.com>
References: <alpine.LRH.2.03.1510261740320.25993@tislabs.com>
To: Sam Weiller <weiler@tislabs.com>
X-Mailer: Apple Mail (2.3096.5)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/absQmdaH06dxKi271CBL9wNgNRw>
Cc: sidr@ietf.org
Subject: Re: [sidr] WGLC on draft-ietf-sidr-bgpsec-algs-11 (ENDS 30-Oct-2015)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Oct 2015 23:51:43 -0000

On Oct 27, 2015, at 11:57, Samuel Weiler <weiler@tislabs.com> wrote:
>=20
> I have read the draft and have no objections to it going forward.
>=20
> Suggestions:
>=20
> Section 5 talks about some of the requirements for (future) algorithm =
and key size agility, but says "The recommended procedures to implement =
such a transition of key sizes and algorithms is not specified in this =
document." (sic)  I think it would be good to cite some discussion of =
that, e.g. section 6 of -protocol.  (I'm not saying that section 6 of =
-protocol is complete or great, but it may be the best set of words we =
have right now.)

Fair =E2=80=98nuff I=E2=80=99ll add =E2=80=9C, see Section 6 in =
[ID.sidr-bgpsec-protocol] for more information."

> Nail down the initial codepoint in the IANA registry (this doc is =
creating the registry, so we can be specific).  I suggest "1=E2=80=9D.

Do you think this is a blocking issue?

I=E2=80=99d prefer to have IANA make the allocation and stick it in the =
document when it=E2=80=99s approved.  YMMV on this but since the =
registry isn=E2=80=99t yet created I=E2=80=99d rather not set an example =
that others might follow of making up registry names and numbers in =
drafts that have not yet reached consensus.

To expand on this issue though should we also reserve the low value and =
the high value too?  i.e.,=20

OLD (please forgive the formatting):

       Digest        Signature     Algorithm Suite    Specification
      Algorithm      Algorithm       Identifier          Pointer
 +----------------------------------------------------------------+
 |   SHA-256   |   ECDSA P-256   |       TBD       |   RFC 5480   |
 +----------------------------------------------------------------+

NEW:

       Digest        Signature     Algorithm Suite    Specification
      Algorithm      Algorithm       Identifier          Pointer
 +----------------------------------------------------------------+
 |   Reserved   |   Reserved   |       0x0       |   This draft   |
 +----------------------------------------------------------------+
 |   SHA-256   |   ECDSA P-256   |       TBD       |   RFC 5480   |
 +----------------------------------------------------------------+
 |   Unassigned   |   Unassigned   |   TBD..0xF       |   This draft   |
 +----------------------------------------------------------------+
 |   Reserved   |   Reserved   |      0xF       |   This draft   |
 +----------------------------------------------------------------+

spt

PS I also got some other minor nits from David that I=E2=80=99ll =
incorporate in the next version that will pop out Sunday/Monday.=


From nobody Thu Oct 29 11:29:13 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 26BB31B3141 for <sidr@ietfa.amsl.com>; Thu, 29 Oct 2015 11:29:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z4f6TIq_uER8 for <sidr@ietfa.amsl.com>; Thu, 29 Oct 2015 11:29:11 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A2C011B3146 for <sidr@ietf.org>; Thu, 29 Oct 2015 11:29:10 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id 0915B28B003D for <sidr@ietf.org>; Thu, 29 Oct 2015 14:29:10 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id E599C1F8035; Thu, 29 Oct 2015 14:29:09 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_6EE32F24-68E4-4AAA-8E8D-919F0F492A5D"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Thu, 29 Oct 2015 14:29:03 -0400
Message-Id: <1EA831E8-C5D4-4D09-82BE-21D9667DD79C@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/8zwCss9tFBzZaX6gj8vvPwVu_lk>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] request for volunteer for jabber scribe and minutes taker
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Oct 2015 18:29:12 -0000

--Apple-Mail=_6EE32F24-68E4-4AAA-8E8D-919F0F492A5D
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

We need jabber scribe and minutes taker for each of our sessions - Tue =
and Fri.

The chairs request volunteers.

Please do consider volunteering.  We will be unable to continue the =
meeting without someone taking minutes and jabber scribing.

=97Sandy, speaking as wg co-chair

--Apple-Mail=_6EE32F24-68E4-4AAA-8E8D-919F0F492A5D
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWMmV3AAoJEHplpQeet0IZYWMP/A/ADK9nUNHwewUEpEbDvt7m
EbH68As0Vrhh56tGO3btgB7ZcIdxNVGVjOOTSxlpGgGrohOks1A8s4hKzBkN8Jk2
UnDcYGWuqqRiCOcQUjzam+n1POExCTL6jpsC3sPq27Icd6eSd4pdv+G3R6zQaYUN
okwX2+zRtTvXmwSwwsIicIn68ElDuo/DrjDCC7FCEfLzr/fB0THr4ejpOUQd6hV3
t9347ImhkZawDEfDNZ0rY4m1SpfjZrEWCb75J9HUqcaym8jHWirdVhTLuC3ie7hQ
HBvmZ06ydstWC4BGJPwtvJaOuID5BCzJqUKFjrLD7940BP/rvJB5dF9af1bO1yC/
W/lyrURBnXNhjFgatyQ+1oVCOGqvB6J7b4NK1zFu87FCyUBZhNa4uxlMMdqDCLzy
yeCIpAsRlKRk1CvssINPvJxdGe2Swh+IE5grwlC1YonIH9lpn4XoqYzWdmhJp+l+
oA2GO7YNv62TZJjgIE+TOlK5SMi0uKIypnBk7mBUlsF/SWjrSAU41AYxtIZx+EZh
D/zE018ZA/Ar5loBHeN9bHnVQhRCoukdE1/P3jJzdeFkL1ADPSOk2XPOWYpvTOQB
hr7SLWizmOYioNR1NBr7joD+ZO7XjSFmjoD6HNUkOLZ2AM92sbP6M35FvHHSN4El
NUqxrj8+WUI6LjBw6eEJ
=r1JT
-----END PGP SIGNATURE-----

--Apple-Mail=_6EE32F24-68E4-4AAA-8E8D-919F0F492A5D--


From nobody Thu Oct 29 11:33:57 2015
Return-Path: <sandy@tislabs.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E45E1B3162 for <sidr@ietfa.amsl.com>; Thu, 29 Oct 2015 11:33:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xSWY2eReFAfV for <sidr@ietfa.amsl.com>; Thu, 29 Oct 2015 11:33:49 -0700 (PDT)
Received: from walnut.tislabs.com (walnut.tislabs.com [192.94.214.200]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 539541B3154 for <sidr@ietf.org>; Thu, 29 Oct 2015 11:33:49 -0700 (PDT)
Received: from nova.tislabs.com (unknown [10.66.1.77]) by walnut.tislabs.com (Postfix) with ESMTP id ADF0128B003D for <sidr@ietf.org>; Thu, 29 Oct 2015 14:33:48 -0400 (EDT)
Received: from [IPv6:::1] (localhost.localdomain [127.0.0.1]) by nova.tislabs.com (Postfix) with ESMTP id 857AB1F8035; Thu, 29 Oct 2015 14:33:48 -0400 (EDT)
From: Sandra Murphy <sandy@tislabs.com>
X-Pgp-Agent: GPGMail 2.5.1
Content-Type: multipart/signed; boundary="Apple-Mail=_4CDD4B6D-93A0-4B06-B632-0A96C1A7CEFD"; protocol="application/pgp-signature"; micalg=pgp-sha512
Date: Thu, 29 Oct 2015 14:33:50 -0400
Message-Id: <BDB1D0EA-F422-4F27-B3D9-77D6E147B92B@tislabs.com>
To: sidr wg list <sidr@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/qAaG5dm7H6TCQEX046INJoH-x5M>
Cc: Sandra Murphy <sandy@tislabs.com>
Subject: [sidr] presenters: slides needed early
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Oct 2015 18:33:50 -0000

--Apple-Mail=_4CDD4B6D-93A0-4B06-B632-0A96C1A7CEFD
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

To those who are presenting:

If your presentation is on Tuesday, please have the slides to the chairs =
by Monday evening.

If you presentation is on Friday, please have your slides to the chairs =
by Thursday noon.

In each case, that gives us a chance to nag you.

=97Sandy, speaking as one of the wg co-chairs


--Apple-Mail=_4CDD4B6D-93A0-4B06-B632-0A96C1A7CEFD
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJWMmaOAAoJEHplpQeet0IZZLkQAKNYRxSU9gJwkDlrCWrVDyV6
JVJxzLP6Ib5D88H3Cz6CsykSSoqK1Fz5FTepbQvm37/+MEf6foFr19Ml3uCNjcDF
4Q2kLXj0B/r94hCUYbza1gztxaksWJEpMwQCSTFQaYGj7dlfoEJaX7TrL4PH71aa
jVVMLnHW9Y+BM+TLwpkx/T3iNDQPSmWFPtJcuBklNxwK8Nss2BJiNKGOKxlwP/Nq
/JrJu5hN61hUQq9o50EwNumxACMgkmQfrdN07a/bl8Bytuvov4kx6pHG6kj+qHK0
91KBpLO6yqPCTudnfCkavCOBPpNhQBHrP55iZwaOBoUmKAr65Up67/0t2meSiAq2
tpsRNamoO1UGM3qXXUplwvwLVf4QeAC5dQxU65HNwGrDLXe3HuZvXVmU4Xewe224
m6z3M5bGA847di4tRE9xCfbsqvWsS23M4B79xsR33ZvPPJhwQOXlcDY0XSTej1BT
B984KouG9F2KBvNMhZQ2ngL266MQLdb4vk06y6uDp27KY+GuBWcVcURCZ6afrpZV
KTCTKTCR/WASNaifw6NkTCe0gSFS8YJrvyKQJ9yRXnZTO5HSrjEIcgm1AAWQKhvN
ky9DnaP99y4Bl7bnpud50nqrXrhRk22xyQW40B72nGqrQEhqITX9JOjIW3bXYwFX
bS2wUh8Wl/WmTxQYpOhF
=DFmM
-----END PGP SIGNATURE-----

--Apple-Mail=_4CDD4B6D-93A0-4B06-B632-0A96C1A7CEFD--


From nobody Fri Oct 30 13:24:55 2015
Return-Path: <kent@bbn.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E6AD31B3BBC for <sidr@ietfa.amsl.com>; Fri, 30 Oct 2015 13:24:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.81
X-Spam-Level: 
X-Spam-Status: No, score=-2.81 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SpHNfIJe34Pe for <sidr@ietfa.amsl.com>; Fri, 30 Oct 2015 13:24:38 -0700 (PDT)
Received: from smtp.bbn.com (smtp.bbn.com [128.33.1.81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B73C41B30E3 for <sidr@ietf.org>; Fri, 30 Oct 2015 13:24:37 -0700 (PDT)
Received: from ssh.bbn.com ([192.1.122.15]:43641 helo=COMSEC.fios-router.home) by smtp.bbn.com with esmtp (Exim 4.77 (FreeBSD)) (envelope-from <kent@bbn.com>) id 1ZsGE0-000B7R-72 for sidr@ietf.org; Fri, 30 Oct 2015 16:24:36 -0400
To: sidr <sidr@ietf.org>
From: Stephen Kent <kent@bbn.com>
Message-ID: <5633D203.1010803@bbn.com>
Date: Fri, 30 Oct 2015 16:24:35 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="------------080408000705040703010004"
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/Ovg7oAygJdCaKQ2_oYtNwjGNF6U>
Subject: [sidr] draft-huston-sidr-validity-00
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Oct 2015 20:24:41 -0000

This is a multi-part message in MIME format.
--------------080408000705040703010004
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

Geoff,

I have a major concern about the proposed change to the RPKI certificate 
validation algorithm as described in draft-huston-sidr-validity-00, and 
some detailed technical comments on that draft.

The major concern is that the proposed mechanism, even if modified to 
address the problems I note below, seems to focus only on a few 
sub-types of modification or injection actions targeting ROAs, CA 
certificates, or router certificates. That’s a total of at most 6 
adverse actions out of the 36 that Di Ma and I describe in 
draft-kent-sidr-adverse-actions-01. I believe the WG should be pursuing 
mechanisms that address a much larger set of the actions identified in 
that I-D. I welcome your feedback on that draft; let us know if we’re 
missing some actions or if you disagree with the characterization of the 
impact of any of the actions.

With regard to the current draft, I agree with Sam and several other 
folks who noted that draft-huston-sidr-validity-00 lacks an clear 
background discussion. If there were detailed (but generic) examples of 
the problems being addressed, a reader would be better able to 
understand the motivations for the proposed change. A reader would be 
able to evaluate whether he/she believes the change addresses the 
problems. I suggest using the terms introduced in
draft-kent-sidr-adverse-actions-01 when discussing the problems.

The discussion of the proposed validation algorithm can be shortened 
considerably, and made clearer at the same time. Specifically, since the 
only change to the validation procedure from 6487 appears to be step 6, 
it would seem preferable to state that, and describe the new step 6 
(rather than reproducing all of the text from Section 7.2 of 6487 with 
this one change).

The text in step 6 isn't clear to me. It refers to a “resource set” but 
that phrase is not defined in this document. Looking at 6487, the phrase 
appears twice, in Sections 4.8.10 and 4.8.11. In those sections it is 
referring to the set of resources acquired from a parent when the 
inherit bit is set. If the intent is to use this phrase to refer to the 
set of resources extracted from an RPKI certificate, irrespective of 
whether the inherit bit is set, the I-D should say so.

The security considerations section says “… the validation path 
encompass the resources that are included in the validation query.” One 
might read this and infer that a set of INRs is an input to the 
validation algorithm. But 6487 does not say INRs are a separate input to 
validation. A certificate to be validated is an input to this algorithm, 
and I assume that was what is implied in step 6, and in the text quoted 
above. If my assumption is correct, this should be stated clearly in 
both places.

Thinking about this in more detail, I fear that the results from the 
modified algorithm will not yield what you seem to want, at least not in 
all cases. If one validates only router certificates and EE certificates 
for (non-PKI) signed objects, e.g., for ROAs or Manifests, then the 
outcome will yield what I think you want. However, when validating a CA 
certificate that “over claims” the certificate will be considered 
invalid by the revised step 6, just as with the current validation 
algorithm. (The over claiming could result from some types of CA errors 
or attacks, or during a resource transfer.)

RP software may validate each CA certificate that it initially acquires, 
before fetching subordinate signed products. This is a reasonable 
strategy to avoid DoS attacks based on returning bogus certificates to 
an RP. Also, when a cached CA certificate is discovered to have changed, 
an RP probably will validate it before adding the certificate to the 
cache. In these cases, the revised step 6 will treat this certificate as 
invalid, if it contains resources not present in all parent 
certificates. Thus all certificates and signed products below it will 
become invalid. So, I don’t believe the change to step 6, as described 
in your I-D, and as interpreted above, will accommodate the motivations 
described in the I-D that you plan to replace with this one.

If I have misunderstood the proposed change to step 6, or the set of 
problems that it is intended to address, please let me know.

Steve


--------------080408000705040703010004
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <meta name="Title" content="">
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">Geoff,<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">I have a
        major concern about the proposed change to the RPKI certificate
        validation
        algorithm as described in draft-huston-sidr-validity-00, and
        some detailed
        technical comments on that draft.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">The major
        concern is that the proposed mechanism, even if modified to
        address the
        problems I note below, seems to focus only on a few sub-types of
        <span style="mso-spacerun:yes"> </span>modification or injection
        actions targeting
        ROAs, CA certificates, or router certificates. That’s a total of
        at most 6 adverse
        actions out of the 36 that Di Ma and I describe in
        draft-kent-sidr-adverse-actions-01.
        I believe the WG should be pursuing mechanisms that address a
        much larger set
        of the actions identified in that I-D. I welcome your feedback
        on that draft;
        let us know if we’re missing some actions or if you disagree
        with the
        characterization of the impact of any of the actions.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">With
        regard to the current draft, I agree with Sam and several other
        folks who noted
        that draft-huston-sidr-validity-00 lacks an clear background
        discussion. If
        there were detailed (but generic) examples of the problems being
        addressed, a
        reader would be better able to understand the motivations for
        the proposed
        change. A reader would be able to evaluate whether he/she
        believes the change
        addresses the problems. I suggest using the terms introduced in
        <br>
      </span><span style="font-size:11.0pt;font-family:Courier"><span
          style="font-size:11.0pt;font-family:Courier">draft-kent-sidr-adverse-actions-01</span>
        when discussing the problems.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">The
        discussion of the proposed validation algorithm can be shortened
        considerably,
        and made clearer at the same time. Specifically, since the only
        change to the
        validation procedure from 6487 appears to be step 6, it would
        seem preferable to
        state that, and describe the new step 6 (rather than reproducing
        all of the
        text from Section 7.2 of 6487 with this one change).<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">The text
        in step 6 isn't clear to me. It refers to a “resource set” but
        that phrase is
        not defined in this document. Looking at 6487, the phrase
        appears twice, in
        Sections 4.8.10 and 4.8.11. In those sections it is referring to
        the set of
        resources acquired from a parent when the inherit bit is set. If
        the intent is
        to use this phrase to refer to the set of resources extracted
        from an RPKI
        certificate, irrespective of whether the inherit bit is set, the
        I-D should
        say so.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">The
        security considerations section says “… the validation path
        encompass the
        resources that are included in the validation query.” One might
        read this and
        infer that a set of INRs is an input to the validation
        algorithm. But 6487 does
        not say INRs are a separate input to validation. A certificate
        to be validated is
        an input to this algorithm, and I assume that was what is
        implied in step 6, and
        in the text quoted above. If my assumption is correct, this
        should be stated clearly
        in both places.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">Thinking
        about this in more detail, I fear that the results from the
        modified algorithm
        will not yield what you seem to want, at least not in all cases.
        If one
        validates only router certificates and EE certificates for
        (non-PKI) signed
        objects, e.g., for ROAs or Manifests, then the outcome will
        yield what I think
        you want. However, when validating a CA certificate that “over
        claims” the certificate
        will be considered invalid by the revised step 6, just as with
        the current
        validation algorithm. (The over claiming could result from some
        types of CA
        errors or attacks, or during a resource transfer.) <o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">RP
        software may validate each CA certificate that it initially
        acquires, before
        fetching subordinate signed products. This is a reasonable
        strategy to avoid
        DoS attacks based on returning bogus certificates to an RP.
        Also, when a cached
        CA certificate is discovered to have changed, an RP probably
        will validate it
        before adding the certificate to the cache. In these cases, the
        revised step 6
        will treat this certificate as invalid, if it contains resources
        not present
        in all parent certificates. Thus all certificates and signed
        products below it
        will become invalid. So, I don’t believe the change to step 6,
        as described in
        your I-D, and as interpreted above, will accommodate the
        motivations described
        in the I-D that you plan to replace with this one. <o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">If I have
        misunderstood the proposed change to step 6, or the set of
        problems that it is
        intended to address, please let me know.<o:p></o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier"><o:p> </o:p></span></p>
    <p class="MsoNormal"><span
        style="font-size:11.0pt;font-family:Courier">Steve<o:p></o:p></span></p>
    <meta name="Keywords" content="">
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    <meta name="ProgId" content="Word.Document">
    <meta name="Generator" content="Microsoft Word 14">
    <meta name="Originator" content="Microsoft Word 14">
    <link rel="File-List"
href="file://localhost/Users/stk/Library/Caches/TemporaryItems/msoclip/0clip_filelist.xml">
    <!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Revision>0</o:Revision>
  <o:TotalTime>0</o:TotalTime>
  <o:Pages>1</o:Pages>
  <o:Words>629</o:Words>
  <o:Characters>3590</o:Characters>
  <o:Company>BBN Technologies</o:Company>
  <o:Lines>29</o:Lines>
  <o:Paragraphs>8</o:Paragraphs>
  <o:CharactersWithSpaces>4211</o:CharactersWithSpaces>
  <o:Version>14.0</o:Version>
 </o:DocumentProperties>
 <o:OfficeDocumentSettings>
  <o:AllowPNG/>
 </o:OfficeDocumentSettings>
</xml><![endif]-->
    <link rel="themeData"
href="file://localhost/Users/stk/Library/Caches/TemporaryItems/msoclip/0clip_themedata.xml">
    <!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:TrackMoves/>
  <w:TrackFormatting/>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>EN-US</w:LidThemeOther>
  <w:LidThemeAsian>JA</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:SplitPgBreakAndParaMark/>
   <w:EnableOpenTypeKerning/>
   <w:DontFlipMirrorIndents/>
   <w:OverrideTableStyleHps/>
   <w:UseFELayout/>
  </w:Compatibility>
  <m:mathPr>
   <m:mathFont m:val="Cambria Math"/>
   <m:brkBin m:val="before"/>
   <m:brkBinSub m:val="&#45;-"/>
   <m:smallFrac m:val="off"/>
   <m:dispDef/>
   <m:lMargin m:val="0"/>
   <m:rMargin m:val="0"/>
   <m:defJc m:val="centerGroup"/>
   <m:wrapIndent m:val="1440"/>
   <m:intLim m:val="subSup"/>
   <m:naryLim m:val="undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="276">
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/>
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]-->
    <style>
<!--
 /* Font Definitions */
@font-face
	{font-family:"ＭＳ 明朝";
	panose-1:0 0 0 0 0 0 0 0 0 0;
	mso-font-alt:"Optima ExtraBlack";
	mso-font-charset:128;
	mso-generic-font-family:roman;
	mso-font-format:other;
	mso-font-pitch:fixed;
	mso-font-signature:1 134676480 16 0 131072 0;}
@font-face
	{font-family:"ＭＳ 明朝";
	panose-1:0 0 0 0 0 0 0 0 0 0;
	mso-font-alt:"Optima ExtraBlack";
	mso-font-charset:128;
	mso-generic-font-family:roman;
	mso-font-format:other;
	mso-font-pitch:fixed;
	mso-font-signature:1 134676480 16 0 131072 0;}
@font-face
	{font-family:Cambria;
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:-536870145 1073743103 0 0 415 0;}
 /* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	mso-bidi-font-size:10.0pt;
	font-family:Cambria;
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"ＭＳ 明朝";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:JA;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	font-size:10.0pt;
	mso-ansi-font-size:10.0pt;
	mso-bidi-font-size:10.0pt;
	font-family:Cambria;
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"ＭＳ 明朝";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:JA;}
@page WordSection1
	{size:8.5in 792.7pt;
	margin:.75in .75in .75in .75in;
	mso-header-margin:0in;
	mso-footer-margin:.65in;
	mso-paper-source:0;}
div.WordSection1
	{page:WordSection1;}
-->
</style><!--[if gte mso 10]>
<style>
 /* Style Definitions */
table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:Cambria;
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:minor-latin;
	mso-fareast-language:JA;}
</style>
<![endif]--><!--StartFragment--><!--EndFragment-->
  </body>
</html>

--------------080408000705040703010004--


From nobody Fri Oct 30 15:43:28 2015
Return-Path: <gih902@gmail.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 506F61B3227 for <sidr@ietfa.amsl.com>; Fri, 30 Oct 2015 15:43:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.75
X-Spam-Level: 
X-Spam-Status: No, score=-1.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tdrxooWdCLox for <sidr@ietfa.amsl.com>; Fri, 30 Oct 2015 15:43:25 -0700 (PDT)
Received: from mail-pa0-x22c.google.com (mail-pa0-x22c.google.com [IPv6:2607:f8b0:400e:c03::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E2D41B3224 for <sidr@ietf.org>; Fri, 30 Oct 2015 15:43:25 -0700 (PDT)
Received: by pasz6 with SMTP id z6so86170077pas.2 for <sidr@ietf.org>; Fri, 30 Oct 2015 15:43:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=M9v3vOkNywZBU/hyis/8ebtcMW7XAMkoae5udCOltyc=; b=OeWZ/Hn7skxyYzWoZRLEZXfnXNMrfHruG6s6cJKJcYps4BbcwW0DA+vrSoknHgOAAX m4jlLQKyM3hmOy5rN6VNkaXuJczkYdrYFtYxDuH+/s41Ts9sWQ0xOIXj3Oeb2oTkdZmb arud36FJOx8wFMQxqLaJ1h6b0vriH/NK3uXeW+wc5JlbFC8zjx6u07pVsnqGEx4NleuL 9gDNXzW/DL/SJIU60Mt2TSEZ7gG1g3ewYDelFpwYl6/wNWjss8Oi7xGy3fcbBUOn4n78 PVxRAEYrhPEX9nB/fvfl3cCDPRltNqVgVGq5j0LqLkbbjB/cURMn1Wvv7b17MgJl1blH CH+Q==
X-Received: by 10.68.200.104 with SMTP id jr8mr11173253pbc.91.1446245004876; Fri, 30 Oct 2015 15:43:24 -0700 (PDT)
Received: from [10.7.21.131] ([119.225.135.183]) by smtp.gmail.com with ESMTPSA id uy1sm5093933pac.39.2015.10.30.15.43.21 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 30 Oct 2015 15:43:24 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 9.1 \(3096.5\))
From: Geoff Huston <gih902@gmail.com>
In-Reply-To: <5633D203.1010803@bbn.com>
Date: Sat, 31 Oct 2015 09:43:17 +1100
Content-Transfer-Encoding: quoted-printable
Message-Id: <CBBAD73B-B883-44C2-98B9-21FB07A9E42A@gmail.com>
References: <5633D203.1010803@bbn.com>
To: Stephen Kent <kent@bbn.com>
X-Mailer: Apple Mail (2.3096.5)
Archived-At: <http://mailarchive.ietf.org/arch/msg/sidr/XxGRFgCc8sj5qSStCAB6AK1cufs>
Cc: sidr chairs <sidr-chairs@tools.ietf.org>, sidr <sidr@ietf.org>
Subject: Re: [sidr] draft-huston-sidr-validity-00
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Oct 2015 22:43:27 -0000

Thanks indeed for this detailed review Steve.=20

I have to admit to a certain sense of confusion over the evolution of =
this work - earlier "validation reconsidered=E2=80=9D drafts which =
described the motivation in more detail triggered a WG consideration of =
transfers which to some extent was, in my view, heading off topic, while =
a trimmed draft that removed the motivational text and just described =
the mechanics of a revised validation algorithm apparently have headed =
too far in the other direction. In reviewing your review comments, and =
thinking about what this particular pair of drafts  was attempting to =
achieve, I also feel that the work as it stands is wide of the mark in =
terms of detail, terminology  and the revised algorithm could be defined =
differently to improve its clarity, which is largely consistent with =
your review comments.

However, that said, I think I have reached the end of my road with the =
"validation reconsidered=E2=80=9D work. If others feel that this =
approach offers some aspects of increased operational robustness by =
slightly altering the pairwise condition of =E2=80=9Cencompassing=E2=80=9D=
 on the INRs in the ordered list of certificates in a validation path, =
then they should pipe up and take over the work, but its not something =
that I feel sufficiently motivated to push in the SIDR WG any more.

So if the WG Chairs still want to discuss this work at the SIDR WG =
meeting this week, my only contribution to the discussion on this topic =
would be something I can already say here on the mailing list: I=E2=80=99m=
 no longer in a position to further develop this work, and I am happy =
for others to take the current state of the drafts, and Steve=E2=80=99s =
detailed review comments, and carry on the effort from this point.

thanks,

   Geoff
=20





> On 31 Oct 2015, at 7:24 AM, Stephen Kent <kent@bbn.com> wrote:
>=20
> Geoff,
> =20
> I have a major concern about the proposed change to the RPKI =
certificate validation algorithm as described in =
draft-huston-sidr-validity-00, and some detailed technical comments on =
that draft.
> =20
> The major concern is that the proposed mechanism, even if modified to =
address the problems I note below, seems to focus only on a few =
sub-types of modification or injection actions targeting ROAs, CA =
certificates, or router certificates. That=E2=80=99s a total of at most =
6 adverse actions out of the 36 that Di Ma and I describe in =
draft-kent-sidr-adverse-actions-01. I believe the WG should be pursuing =
mechanisms that address a much larger set of the actions identified in =
that I-D. I welcome your feedback on that draft; let us know if we=E2=80=99=
re missing some actions or if you disagree with the characterization of =
the impact of any of the actions.
> =20
> With regard to the current draft, I agree with Sam and several other =
folks who noted that draft-huston-sidr-validity-00 lacks an clear =
background discussion. If there were detailed (but generic) examples of =
the problems being addressed, a reader would be better able to =
understand the motivations for the proposed change. A reader would be =
able to evaluate whether he/she believes the change addresses the =
problems. I suggest using the terms introduced in=20
> draft-kent-sidr-adverse-actions-01 when discussing the problems.
> =20
> The discussion of the proposed validation algorithm can be shortened =
considerably, and made clearer at the same time. Specifically, since the =
only change to the validation procedure from 6487 appears to be step 6, =
it would seem preferable to state that, and describe the new step 6 =
(rather than reproducing all of the text from Section 7.2 of 6487 with =
this one change).
> =20
> The text in step 6 isn't clear to me. It refers to a =E2=80=9Cresource =
set=E2=80=9D but that phrase is not defined in this document. Looking at =
6487, the phrase appears twice, in Sections 4.8.10 and 4.8.11. In those =
sections it is referring to the set of resources acquired from a parent =
when the inherit bit is set. If the intent is to use this phrase to =
refer to the set of resources extracted from an RPKI certificate, =
irrespective of whether the inherit bit is set, the I-D should say so.
> =20
> The security considerations section says =E2=80=9C=E2=80=A6 the =
validation path encompass the resources that are included in the =
validation query.=E2=80=9D One might read this and infer that a set of =
INRs is an input to the validation algorithm. But 6487 does not say INRs =
are a separate input to validation. A certificate to be validated is an =
input to this algorithm, and I assume that was what is implied in step =
6, and in the text quoted above. If my assumption is correct, this =
should be stated clearly in both places.
> =20
> Thinking about this in more detail, I fear that the results from the =
modified algorithm will not yield what you seem to want, at least not in =
all cases. If one validates only router certificates and EE certificates =
for (non-PKI) signed objects, e.g., for ROAs or Manifests, then the =
outcome will yield what I think you want. However, when validating a CA =
certificate that =E2=80=9Cover claims=E2=80=9D the certificate will be =
considered invalid by the revised step 6, just as with the current =
validation algorithm. (The over claiming could result from some types of =
CA errors or attacks, or during a resource transfer.)=20
> =20
> RP software may validate each CA certificate that it initially =
acquires, before fetching subordinate signed products. This is a =
reasonable strategy to avoid DoS attacks based on returning bogus =
certificates to an RP. Also, when a cached CA certificate is discovered =
to have changed, an RP probably will validate it before adding the =
certificate to the cache. In these cases, the revised step 6 will treat =
this certificate as invalid, if it contains resources not present in all =
parent certificates. Thus all certificates and signed products below it =
will become invalid. So, I don=E2=80=99t believe the change to step 6, =
as described in your I-D, and as interpreted above, will accommodate the =
motivations described in the I-D that you plan to replace with this one.=20=

> =20
> If I have misunderstood the proposed change to step 6, or the set of =
problems that it is intended to address, please let me know.
> =20
> Steve
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr

