netsec-sig - [Security-WG] TechX Security WG meeting and RPKI BoF notes
Subject: Internet2 Network Security SIG
List archive
- From: Karl Newell <>
- To: "" <>
- Subject: [Security-WG] TechX Security WG meeting and RPKI BoF notes
- Date: Thu, 29 Sep 2016 22:02:10 +0000
- Accept-language: en-US
- Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
- Ironport-phdr: 9a23:wrktIh0kOnY9LauHsmDT+DRfVm0co7zxezQtwd8ZsesfLfad9pjvdHbS+e9qxAeQG96Eu7QZ0KGP7ujJYi8p39WoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6i760TlHUA7yPhdvJ/jkX5Hdp8Wxy+2o/ZDPOUNFiCf3KedpIR6rtwTNp4wJjqNjLLo80B3EviEOduhLkzBGP1WWyjX1/MP42pN8/iBU86Yi8cNfXKH+V6U+UbFCCjk6aSY46NC95kqLdheG+nZJCjZeqRFPGQWQtBw=
- Spamdiagnosticoutput: 1:0
I did not write down the names of attendees.
-Vice chair – we need to nominate and elect a vice chair. We’ll do that on the next call -Should we develop a best practice on how we allow access to the control plane (e.g., out of band management network)? -We decided that the Security WG would focus on RPKI -Develop a reference implementation -Launch a pilot. I will send out an email early next week with more detail -Internet2 could validate routes and advertise status via BGP communities -The strategy needs to be developed with various entities in mind – campus vs regional vs Internet2 There was a follow up RPKI BoF where we outlined the pilot and success factors (meeting notes below). Documentation Pilot Education Operational effort Use of signed objects outside BGP validation Signal validation via community Focus on v6 space (no legacy) Workshop Architecture levels - backbone, regional, campus Interop tests - validators and routers Success factors - what are they? Percentage routes signed Percentage with valid ROA availability/accessibility of caches and validators Cookbook for arch levels Are we making things more stable What’s the effective validation model (campus, regional, backbone) Interop tests How many caches do you need? Redundancy? Signing I2 objects Proxy signing? -- Karl Newell Cyberinfrastructure Security Engineer Internet2 520-344-0459 |
- [Security-WG] TechX Security WG meeting and RPKI BoF notes, Karl Newell, 09/29/2016
Archive powered by MHonArc 2.6.19.