Re: [sidr] RPKI <-> allocation consistency

2012-09-12 Thread Robert Loomans
sted service simultaneously for some time, allowing relying parties to pick up the new objects, before switching off the hosted service. Similarly, when someone wants to wholesale replace their RPKI infrastructure with a new implementation they may choose to run old and new side-by-side. Rob --

Re: [sidr] [Technical Errata Reported] RFC6487 (3168)

2012-03-26 Thread Robert Loomans
22) > -- > Title : A Profile for X.509 PKIX Resource Certificates > Publication Date: February 2012 > Author(s) : G. Huston, G. Michaelson, R. Loomans > Category: PROPOSED STANDARD > Source : S

Re: [sidr] SIDR ReCharter - to capture/cover path validation work

2011-02-23 Thread Robert Loomans
st such an object: http://tools.ietf.org/html/draft-huston-sidr-aao-profile-03 Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone:

Re: [sidr] WGLC for draft-ietf-sidr-roa-format-09

2010-11-18 Thread Robert Loomans
> opposed. If you are opposed, please indicate why. > > --Sandy, speaking with wg chair bonnet on > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- Robert Loomans email:

Re: [sidr] WGLC for draft-ietf-sidr-keyroll-04

2010-11-18 Thread Robert Loomans
please indicate why. > > --Sandy, speaking with wg chair derby on > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- Robert Loomans email: robe...@apnic.net Se

Re: [sidr] WG LC for draft-ietf-sidr-roa-validation-10

2010-11-18 Thread Robert Loomans
he IESG or if you are > opposed. If you are opposed, please indicate why. > > --Sandy, speaking with wg chair turban on > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- Robert Loo

Re: [sidr] WGLC for draft-ietf-sidr-rpki-manifests-09

2010-11-18 Thread Robert Loomans
> opposed. If you are opposed, please indicate why. > > --Sandy, speaking with wg chair beret on > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- Robert Loomans

Re: [sidr] WGLC for draft-ietf-sidr-rpki-algs-04

2010-11-18 Thread Robert Loomans
mission to the IESG or if you are > opposed. If you are opposed, please indicate why. > > --Sandy, speaking with wg chair homburg on > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- R

Re: [sidr] WG adoption of draft-huston-sidr-keyroll-00.txt

2010-08-25 Thread Robert Loomans
doption will end in two weeks on 8 Sep > 2010. > > --Sandy, speaking as wg chair > > > ___ > sidr mailing list > sidr@ietf.org > https://www.ietf.org/mailman/listinfo/sidr -- Robert Loomans email:

Re: [sidr] some questions / comments on provisioning (up/down)

2010-08-15 Thread Robert Loomans
00 Bad Data There is an existing HTTP code for this: 503 Service Unavailable. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone:

Re: [sidr] WG adoption for draft-pmohapat-sidr-pfx-validate-07

2010-05-23 Thread Robert Loomans
o see one set of terminology for results from the RPKI. Hopefully, one that doesn't conflict with other PKI usage. Rob -- Robert Loomans On 24/05/2010, at 10:15, Terry Manderson wrote: On 22/05/10 10:30 PM, "Robert Loomans" wrote: [ If you were to base a comparison f

Re: [sidr] WG adoption for draft-pmohapat-sidr-pfx-validate-07

2010-05-22 Thread Robert Loomans
valid = 1 unknown = 0 invalid = -1 ] I don't think that "unverified" quite cuts it in this context, as it is not the negative counterpart to the positive "verified" assertion. A naive reader/implementer might believe that "unverified" is less du

Re: [sidr] WG adoption for draft-reynolds-rpki-ltamgmt-00.txt

2010-05-18 Thread Robert Loomans
I'm in favour, and I'm happy to review drafts. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone: +61 7

Re: [sidr] Question about manifest document

2009-11-18 Thread Robert Loomans
with this: A MUST would be too strong here; I believe that a SHOULD is appropriate. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone:

Re: [sidr] Call for WG adoption of draft-manderson-sidr-usecases-01.txt

2009-11-08 Thread Robert Loomans
Please accept, I'm happy to review. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone: +61 7 3858

Re: [sidr] Request for WGLC

2009-10-29 Thread Robert Loomans
dation is sufficient as-is, needs nit fixes, or more. Thanks, Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone:

Re: [sidr] draft-pmohapat-sidr-pfx-validate-03.txt as SIDR WG document

2009-10-29 Thread Robert Loomans
see a clear statement as to what this draft says for which the existing draft-ietf-sidr-roa-validation is insufficient. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/

Re: [sidr] Working Group Last Call - draft-ietf-sidr-arch-09.txt

2009-10-28 Thread Robert Loomans
operational routing decisions (e.g., ISPs, RIRs, NIRs) SHOULD download and validate updates at least once every three hours. Rob -- Robert Loomans Email: robe...@apnic.net Senior Software Engineer, APNICPhone:+61 7 3858 3100 http

Re: [sidr] sidr-arch-09 refresh cycle time

2009-10-26 Thread Robert Loomans
sted best practice (and the default installed by relying party tools) is 12 hours, say, then a large percentage of installations will be using 12 hours, because people don't bother to change defaults. Rob -- Robert Loomans email: robe...@apnic.net Senior Software E

Re: [sidr] Request for WG adoption

2009-08-02 Thread Robert Loomans
I support adoption, and I will review. Rob -- Robert Loomans email: robe...@apnic.net Senior Software Engineer, APNICsip:robe...@voip.apnic.net http://www.apnic.net/ phone: +61 7 3858 3100

Re: [sidr] request for wg adoption of draft-ietf-sidr-ta-00.txt

2009-03-27 Thread Robert Loomans
Yes, please adopt this draft as a WG item. Rob -- Robert Loomans On 26/03/2009, at 12:32, Sandra Murphy wrote: There were objections yesterday in the sidr meeting to the way that draft-ietf-sidr-ta-00.txt became a wg draft. draft-ietf-sidr-ta-00.txt was an extract of an important

Re: [sidr] I-D Action:draft-ietf-sidr-arch-06.txt

2009-03-11 Thread Robert Loomans
> ... where resources are listed in the 3779 attributes following the > paradigm that no two TA organisations can be authoritative for the > same information? (in that model) I'm not sure that's a valid assumption. I believe that this would preclude make-before-break transfer

Re: [sidr] Request for WG Last Call for draft-ietf-sidr-bogons-02.txt and draft-ietf-sidr-roa-validation-01.txt

2008-11-24 Thread Robert Loomans
a BOA, it means that neither AS5 *nor* prefixes 10.0.0.0/8 and more specific should *ever* appear in routing, together or separately. Geoff, George, Terry, is my understanding correct? Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC

Re: [sidr] RPSLSIG adoption?

2008-11-22 Thread Robert Loomans
txt > http://www3.ietf.org/proceedings/08nov/slides/sidr-3.pdf I'm happy to see this adopted as a WG item... and I will participate in discussion and review. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC

Re: [sidr] only one RPKI

2008-11-20 Thread Robert Loomans
http://www.imc.org/ietf-pkix/pkix-oid.asn Both id-cp(id-pkix 14) and id-cp-sbgpCertificatePolicy(id-cp 1) are already assigned. Cheers, Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNICPhone:+61 7 3858 3100

Re: [sidr] request for wg adoption

2008-10-12 Thread Robert Loomans
Friday, Oct 22. I'm for adoption: I would like to see the idea explored. I will participate in any discussion. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.ne

Re: [sidr] draft-sidr-fetch-00.txt

2008-08-27 Thread Robert Loomans
uld be counter to the purpose of the manifest. > IMHO, of course. Yes, a partial manifest is useless. You can't validate it. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7

Re: [sidr] draft-sidr-fetch-00.txt

2008-08-26 Thread Robert Loomans
such >a case this situation should result in a warning to the effect that: >"The following files that should have been present in the repository > at , are missing . This indicates an >attack against this publication point, or the repository, or an error >by the

Re: [Sidr] Question about draft-ietf-sidr-roa-format-03.txt

2008-07-16 Thread Robert Loomans
the way of value to enforce this within the ROA. The noise it adds is harmless. Having a canonical form can reduce the number of interoperability problems and makes writing test cases easier. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Soft

Re: [Sidr] adoption of draft-huston-sidr-repos-struct-01.txt as a working group work item

2008-04-04 Thread Robert Loomans
[ Disclaimer: I am a co-author of this draft ] I believe this is appropriate for SIDR adopt, and I will comment on it. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net

Re: [Sidr] Request for SIDR to adopt draft-huston-sidr-bogons-00.txt as a work item

2008-04-04 Thread Robert Loomans
-- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net Fax: +61 7 3858 3199 smime.p7s Description: S/MIME Cryptographic Signature

[Sidr] Request for SIDR to adopt draft-huston-sidr-bogons-00.txt as a work item

2008-04-03 Thread Robert Loomans
Sandy, I would like to request that draft-huston-sidr-bogons-00.txt be adopted as a SIDR WG document. As a counterpart to the ROA draft, I believe this falls within SIDR's charter. http://www.potaroo.net/ietf/all-ids/draft-huston-sidr-bogons-00.txt Cheers, Rob -- Robert Lo

Re: [Sidr] Rsync

2008-03-18 Thread Robert Loomans
be in place :) Cheers, Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net Fax: +61 7 3858 3199 smime.p7s Description: S/MIM

Re: [Sidr] rsync discussion history

2008-03-17 Thread Robert Loomans
t's certainly possible assuming the manifest is there. Currently the manifests are optional. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net

Re: [Sidr] Rsync

2008-03-17 Thread Robert Loomans
note that as these are all signed, foreign objects are detectable by relying parties. Ok, what I said was poorly worded. I'll rephrase: None of the current drafts specify the mechanisms or protocols used to modify the contents of the repositories. Rob -- Robert Lo

Re: [Sidr] rsync discussion history

2008-03-17 Thread Robert Loomans
m, is called an > “aggregate” if the compilation and its resulting copyright are not > used to limit the access or legal rights of the compilation's users > beyond what the individual works permit. Inclusion of a covered work > in an aggregate does not cause this License t

Re: [Sidr] Rsync

2008-03-17 Thread Robert Loomans
cribe fetching from them. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net Fax: +61 7 3858 3199 smime.p7s Description: S/MIME Cryptogr

Re: [Sidr] Rsync

2008-03-17 Thread Robert Loomans
-- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net Fax: +61 7 3858 3199 smime.p7s Description: S/MIME Cryptographic Signature

Re: [Sidr] Rsync

2008-03-17 Thread Robert Loomans
appropriate certificates, CRLs, etc. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Software Engineer, APNIC Phone: +61 7 3858 3100 http://www.apnic.net Fax: +61 7 3858 3199 smime.p7s Description: S/MIME

Re: [Sidr] accept resource certificates provisioning protocol as work item?

2007-12-10 Thread Robert Loomans
I would like this adopted. I will continue to help with writing and reviewing. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Programmer/Analyst, APNIC Phone:+61 7 3858 3100 http://www.apnic.net Fax:+61 7

Re: [Sidr] accept manifests as a work item?

2007-12-10 Thread Robert Loomans
I'd like to see manifests adopted. I will read and comment on the drafts. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Senior Programmer/Analyst, APNIC Phone:+61 7 3858 3100 http://www.apnic.net Fax:+61 7

Re: [Sidr] I-D ACTION:draft-ietf-sidr-roa-format-01.txt

2007-07-10 Thread Robert Loomans
the encoding match. If it did, it would conflict with RFC3779 which requires the minimal encoding. eg, A ROA could have two prefixes, say 11.0.0.0/8 and 12.0.0.0/8, encoded as two IPAddress fields, whereas RFC3779 would dictate that they would be encoded as a range 11.0.0.0-12.255.255.255. Rob

Re: [Sidr] draft-ietf-sidr-res-certs-05.txt comments

2007-04-04 Thread Robert Loomans
if the TA is provided as a self-signed cert. Alternatively, if there isn't a URL in the TA material, where do we start pulling pulling certs from? Rob -- Robert Loomans Email: [EMAIL PROTECTED] Programmer/Analyst, APNIC Phone:

Re: [Sidr] comments on draft-ietf-sidr-res-certs-02

2006-10-30 Thread Robert Loomans
y minimising the "chattiness" of the protocol and thus the effect of round-trip times. I think that is another property of rsync that would be useful to retain. Rob -- Robert Loomans Email: [EMAIL PROTECTED] Programmer/Analyst, APNIC

Re: [Sidr] comments on draft-ietf-sidr-res-certs-02

2006-10-06 Thread Robert Loomans
ts/files, and, if you already have an old tree, just the changes. We could implement this in any transport, but RSYNC does this for free. > In general, the draft seems to systematically misspell words like > "authorise" and "recognise", in defiance of the authors'