Re: [sidr] TA questions

2009-11-07 Thread Robert Kisteleki
George Michaelson wrote: On 05/11/2009, at 4:50 PM, Robert Kisteleki wrote: Hi, I'm proxying two questions from our development team regarding the TA draft: 1) How do the authors envision key roll overs for the RTA? Even though the draft allows for re-publication of the self-signed RTA w

Re: [sidr] sidr-arch-09 refresh cycle time

2009-11-07 Thread Rob Austein
[Catching up on back mail while in transit to Hiroshima...] At Tue, 27 Oct 2009 16:28:57 -0400, Matt Lepinski wrote: > > Here, I understand that "everyone hitting the repository system at once" > is a bad outcome regardless of the frequency that we recommend. That is, > regardless of whether we

Re: [sidr] draft-pmohapat-sidr-pfx-validate-03.txt as SIDR WG document

2009-11-07 Thread Sandra Murphy
On Fri, 6 Nov 2009, Larry J. Blunk wrote: Sorry, should have provided more context. I was referring to the particular "Partial Adoption" scenario presented in http://www.antd.nist.gov/~ksriram/SIDR_ROA_BOA_Interpretation.pdf. Where more specifics of a registered ROA (that do not not have a

Re: [sidr] draft-pmohapat-sidr-pfx-validate-03.txt as SIDR WG document

2009-11-07 Thread Curtis Villamizar
In message <4af48d1c.4040...@merit.edu> Larry Blunk writes: > > It's my understanding (please correct me if I'm wrong) > that by issuing a CA-Cert a provider is > not only giving the customer authority to register their own > ROA's, but to also issue ROA's or CA-Cert's for > customers of the

[sidr] TA document review

2009-11-07 Thread Roque Gagliano
Hi, Here are some comments on the document, some reflects the conflict that Robert mentioned about being more clear that one EE ETA cert is valid at any particular time, some are typos. Roque. 2.1. A Compound Trust Anchor Structure The ETA issues a CRL and

Re: [sidr] CP changes in response to WGLC comments

2009-11-07 Thread Roque Gagliano
Randy, following this line of thought, should an rpki provider be required to give a significant re-parenting time window before stopping service? Wouldn't that be part of their private contractual relationship? Roque randy ___ sidr mailing list

Re: [sidr] draft-pmohapat-sidr-pfx-validate-03.txt as SIDR WG document

2009-11-07 Thread Stephen Kent
At 3:19 PM -0500 11/7/09, Curtis Villamizar wrote: In message <4af48d1c.4040...@merit.edu> Larry Blunk writes: It's my understanding (please correct me if I'm wrong) that by issuing a CA-Cert a provider is not only giving the customer authority to register their own ROA's, but to also i

Re: [sidr] TA document review

2009-11-07 Thread Robert Kisteleki
Roque Gagliano wrote: 2.1. A Compound Trust Anchor Structure The ETA issues a CRL and one EE certificate. (Roque) I believe it needs to be explained that more than one ETA EE cert may be issued during the life-time of the ETA CA however at any particular moment there is only one valid EE ce