Skip to Content.
Sympa Menu

netsec-sig - [Security-WG] TechX Security WG meeting and RPKI BoF notes

Subject: Internet2 Network Security SIG

List archive

[Security-WG] TechX Security WG meeting and RPKI BoF notes


Chronological Thread 
  • From: Karl Newell <>
  • To: "" <>
  • Subject: [Security-WG] TechX Security WG meeting and RPKI BoF notes
  • Date: Thu, 29 Sep 2016 22:02:10 +0000
  • Accept-language: en-US
  • Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
  • Ironport-phdr: 9a23:wrktIh0kOnY9LauHsmDT+DRfVm0co7zxezQtwd8ZsesfLfad9pjvdHbS+e9qxAeQG96Eu7QZ0KGP7ujJYi8p39WoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6i760TlHUA7yPhdvJ/jkX5Hdp8Wxy+2o/ZDPOUNFiCf3KedpIR6rtwTNp4wJjqNjLLo80B3EviEOduhLkzBGP1WWyjX1/MP42pN8/iBU86Yi8cNfXKH+V6U+UbFCCjk6aSY46NC95kqLdheG+nZJCjZeqRFPGQWQtBw=
  • Spamdiagnosticoutput: 1:0

I did not write down the names of attendees.

 

-Vice chair – we need to nominate and elect a vice chair.  We’ll do that on the next call

-Should we develop a best practice on how we allow access to the control plane (e.g., out of band management network)?

-We decided that the Security WG would focus on RPKI

                -Develop a reference implementation

                -Launch a pilot.  I will send out an email early next week with more detail

-Internet2 could validate routes and advertise status via BGP communities

-The strategy needs to be developed with various entities in mind – campus vs regional vs Internet2

 

 

There was a follow up RPKI BoF where we outlined the pilot and success factors (meeting notes below).

 

Documentation

 

Pilot

                Education

                Operational effort

                Use of signed objects outside BGP validation

                Signal validation via community

                Focus on v6 space (no legacy)

                Workshop

                Architecture levels - backbone, regional, campus

                Interop tests - validators and routers

 

Success factors - what are they?

                Percentage routes signed

                Percentage with valid ROA

                availability/accessibility of caches and validators

                Cookbook for arch levels

                Are we making things more stable

                What’s the effective validation model (campus, regional, backbone)

                Interop tests

 

How many caches do you need?  Redundancy?

 

Signing I2 objects

 

Proxy signing?

 

--

Karl Newell

Cyberinfrastructure Security Engineer

Internet2

520-344-0459



  • [Security-WG] TechX Security WG meeting and RPKI BoF notes, Karl Newell, 09/29/2016

Archive powered by MHonArc 2.6.19.

Top of Page