>> The new PDU assumes the wg agrees to the revision of the router cert
>> draft.  Correct?  So this is tied to progress of a revised router cert
>> draft?  Is somebody already on board to provide that new draft?>
>
>maybe you missed draft-ymbk-rpki-rtr-keys-01.txt

Rob's message said that the new PDU would "support binding a single router key 
to multiple ASNs".

I presumed that this came from the change to the router cert that Rob spoke 
about in the sidr meeting this week.  I presumed he was speaking about a change 
to draft-ietf-sidr-bgpsec-pki-profiles-06, in this part 

   Each BGPSEC Router Certificate MUST include the AS Resource
   Identifier Delegation extension, as specified in section 4.8.11 of
   [RFC6487].  The AS Resource Identifier Delegation extension MUST
   include exactly one AS number, and the "inherit" element MUST NOT be
   specified.

The 6810 change Rob suggests (and draft-ymbk-rpki-rtr-keys-01.txt, too) define 
a new PDU carrying the router cert's AS info to the router.  But 
draft-ietf-sidr-bgpsec-pki-profiles-06 needs to change, too, if multiple ASNs 
are going to be there to carry.

>how much bureaucracy can we create here?

This isn't a big job - a change from "exactly one" to "at least one" might be 
sufficient.  I think that's substantive, not bureaucratic.

--Sandy

________________________________________
From: Randy Bush [ra...@psg.com]
Sent: Thursday, March 06, 2014 1:37 PM
To: Murphy, Sandra
Cc: Rob Austein; sidr@ietf.org
Subject: Re: [sidr] Updates to rpki-rtr protocol (RFC 6810 bis)

> I would expect that adding a new PDU would be a new document, not a
> revision to the protocol document.  Would you agree?

the version numbers all change

> The new PDU assumes the wg agrees to the revision of the router cert
> draft.  Correct?  So this is tied to progress of a revised router cert
> draft?  Is somebody already on board to provide that new draft?

maybe you missed draft-ymbk-rpki-rtr-keys-01.txt

how much bureaucracy can we create here?

randy

_______________________________________________
sidr mailing list
sidr@ietf.org
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to