Re: [sidr] draft-ymbk-rpki-origin-ops-00

Roque Gagliano <rogaglia@cisco.com> Tue, 16 November 2010 14:45 UTC

Return-Path: <rogaglia@cisco.com>
X-Original-To: sidr@core3.amsl.com
Delivered-To: sidr@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 95C7F3A6B73 for <sidr@core3.amsl.com>; Tue, 16 Nov 2010 06:45:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SE1SSlyqF7IK for <sidr@core3.amsl.com>; Tue, 16 Nov 2010 06:45:26 -0800 (PST)
Received: from ams-iport-1.cisco.com (ams-iport-1.cisco.com [144.254.224.140]) by core3.amsl.com (Postfix) with ESMTP id C34C43A6A2E for <sidr@ietf.org>; Tue, 16 Nov 2010 06:45:25 -0800 (PST)
Authentication-Results: ams-iport-1.cisco.com; dkim=neutral (message not signed) header.i=none
X-Files: smime.p7s : 3815
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AvIEALsn4kyQ/khNgWdsb2JhbACiXxUBARYiIqN4myaFSwSKWA
X-IronPort-AV: E=Sophos; i="4.59,206,1288569600"; d="p7s'?scan'208,217"; a="69367358"
Received: from ams-core-4.cisco.com ([144.254.72.77]) by ams-iport-1.cisco.com with ESMTP; 16 Nov 2010 14:46:08 +0000
Received: from ams3-vpn-dhcp7405.cisco.com (ams3-vpn-dhcp7405.cisco.com [10.61.92.236]) by ams-core-4.cisco.com (8.14.3/8.14.3) with ESMTP id oAGEk8Kk006305; Tue, 16 Nov 2010 14:46:08 GMT
Mime-Version: 1.0 (Apple Message framework v1082)
Content-Type: multipart/signed; boundary="Apple-Mail-58-226456544"; protocol="application/pkcs7-signature"; micalg="sha1"
From: Roque Gagliano <rogaglia@cisco.com>
In-Reply-To: <m2hbfsxsqi.wl%randy@psg.com>
Date: Tue, 16 Nov 2010 15:46:25 +0100
Message-Id: <69FD7AD2-A398-419C-BDEE-31845426CF30@cisco.com>
References: <20101108055538.655EC3A69B6@core3.amsl.com> <m2hbfsxsqi.wl%randy@psg.com>
To: Randy Bush <randy@psg.com>
X-Mailer: Apple Mail (2.1082)
Cc: sidr wg <sidr@ietf.org>
Subject: Re: [sidr] draft-ymbk-rpki-origin-ops-00
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Nov 2010 14:45:27 -0000

Hi Randy

I have a comment on section 5 of this draft based on our experience playing with this.

When you say:
 "  Announcements with invalid origins MAY be used, but SHOULD be less
   preferred than those with valid or unknown."
It would be worthy to write a note warning that invalid announcements which are more specific that an existing valid announcement SHOULD be discarded as they will always be preferred, independently of validation state of BGP attributes (longest prefix match).

Regards,

Roque

PS: we are working on code for this feature.



On Nov 8, 2010, at 6:57 AM, Randy Bush wrote:

> 
> From: IETF I-D Submission Tool <idsubmission@ietf.org>
> Date: November 8, 2010 6:55:37 AM GMT+01:00
> To: randy@psg.com
> Subject: New Version Notification for draft-ymbk-rpki-origin-ops-00 
> 
> 
> 
> A new version of I-D, draft-ymbk-rpki-origin-ops-00.txt has been successfully submitted by Randy Bush and posted to the IETF repository.
> 
> Filename:	 draft-ymbk-rpki-origin-ops
> Revision:	 00
> Title:		 RPKI-Based Origin Validation Operations
> Creation_date:	 2010-11-08
> WG ID:		 Independent Submission
> Number_of_pages: 7
> 
> Abstract:
> Deployment of the RPKI-based BGP origin validation has many
> operational considerations.  This document attempts to collect and
> present them.  It is expected to evolve as RPKI-based origin
> validation is deployed and the dynamics are better understood.
> 
> 
> 
> The IETF Secretariat.
> 
> 
> 
> A new version of I-D, draft-ymbk-rpki-origin-ops-00.txt has been successfully submitted by Randy Bush and posted to the IETF repository.
> 
> Filename:	 draft-ymbk-rpki-origin-ops
> Revision:	 00
> Title:		 RPKI-Based Origin Validation Operations
> Creation_date:	 2010-11-08
> WG ID:		 Independent Submission
> Number_of_pages: 7
> 
> Abstract:
> Deployment of the RPKI-based BGP origin validation has many
> operational considerations.  This document attempts to collect and
> present them.  It is expected to evolve as RPKI-based origin
> validation is deployed and the dynamics are better understood.
> 
> 
> 
> The IETF Secretariat.
> 
> 
> 
> 
> _______________________________________________
> sidr mailing list
> sidr@ietf.org
> https://www.ietf.org/mailman/listinfo/sidr