rpki-client delay deletes also for RRDP repos

2021-04-29 Thread Claudio Jeker
Like for rsync repos files in the RRDP repos should be delayed until after the validation finished. As with anything RPKI related there is little trust in the repositories and their abilities to not botch an update. One thing I'm not sure is what should happen if a file is supposed to be removed b

Re: rpki-client delay deletes also for RRDP repos

2021-04-30 Thread Sebastian Benoit
Claudio Jeker(cje...@diehard.n-r-g.com) on 2021.04.29 15:34:15 +0200: > Like for rsync repos files in the RRDP repos should be delayed until after > the validation finished. As with anything RPKI related there is little > trust in the repositories and their abilities to not botch an update. > > On

Re: rpki-client delay deletes also for RRDP repos

2021-04-30 Thread Theo de Raadt
Sebastian Benoit wrote: > Claudio Jeker(cje...@diehard.n-r-g.com) on 2021.04.29 15:34:15 +0200: > > Like for rsync repos files in the RRDP repos should be delayed until after > > the validation finished. As with anything RPKI related there is little > > trust in the repositories and their abiliti

Re: rpki-client delay deletes also for RRDP repos

2021-05-01 Thread Claudio Jeker
On Sat, May 01, 2021 at 12:14:22AM +0200, Sebastian Benoit wrote: > Claudio Jeker(cje...@diehard.n-r-g.com) on 2021.04.29 15:34:15 +0200: > > Like for rsync repos files in the RRDP repos should be delayed until after > > the validation finished. As with anything RPKI related there is little > > tru

Re: rpki-client delay deletes also for RRDP repos

2021-05-01 Thread Claudio Jeker
On Fri, Apr 30, 2021 at 10:58:25PM -0600, Theo de Raadt wrote: > Sebastian Benoit wrote: > > > Claudio Jeker(cje...@diehard.n-r-g.com) on 2021.04.29 15:34:15 +0200: > > > Like for rsync repos files in the RRDP repos should be delayed until after > > > the validation finished. As with anything RPK

Re: rpki-client delay deletes also for RRDP repos

2021-05-01 Thread Theo de Raadt
Claudio Jeker wrote: > > So, that would suggest some sort of lockout against running multiple > > rpki-client with the correct termination strategy. I don't believe we > > have such a thing right now. We have the timeout, to ensure rpki-client > > doesn't run too long which may prevent simultan