netsec-sig - [Security-WG] Interesting post re:RPKI on nanog...
Subject: Internet2 Network Security SIG
List archive
- From: Steven Wallace <>
- To: ,
- Subject: [Security-WG] Interesting post re:RPKI on nanog...
- Date: Fri, 13 Jul 2018 09:17:45 -0400
- Ironport-phdr: 9a23:uXCJ0BQtQf6X/7BPgs8KO1jUYdpsv+yvbD5Q0YIujvd0So/mwa6yYheN2/xhgRfzUJnB7Loc0qyK6/6mATRIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TW94jEIBxrwKxd+KPjrFY7OlcS30P2594HObwlSizexfbJ/IA+qoQnNq8IbnZZsJqEtxxXTv3BGYf5WxWRmJVKSmxbz+MK994N9/ipTpvws6ddOXb31cKokQ7NYCi8mM30u683wqRbDVwqP6WACXWgQjxFFHhLK7BD+Xpf2ryv6qu9w0zSUMMHqUbw5Xymp4qF2QxHqlSgHLSY0/mHLhcN/kaxVoxyvqQJkzo7bfI2VMeBzcr/Bcd8EQ2dKQ8ZfVzZGAoO5d4YBEvYBMvhGr4bjoVsFsBuxChOoBOPr0DBHmmH51rA93uQ6CgHH0hctH9MTsHjOstr6KboSXPmzwaLVwzvDaPZW1i386IjOah0hvf+NXbNsccrN10YvDRnJgUmXqYzgJz+azOENs3Oa7+pnT+6gl2knqwRprjih28cskYjJh40PxlDC8SV0xps+K96gSENjf9KoDIdcuzyfOodrQc4tXWJltSM0yr0IpZK3YC0HxIopyhPabvGKcYiF7xT+X+iLOzh4nmhqeLenihay70egzur8W9Gx0FlQrypFlsPAuWwR1xPP8MSHReF9/kGm2TmTzQzT6/xELVoqmqXGNp4t2r8wlpwNvkTfBiL6hln6gLOLekgh5+Sl6Prob7bjq5+SOY94lh3yP6EwlsGxBOk1NwoDUmiD9eS5zrLj/En5QLtQjv0xl6nUqIvaJd8Vp6OiAg9Vz5wv5AiiADe7yNgYh2UILEpZeBKbiIjkI1fOIOziAvijmFmslDZrx+vaPr36HJnBNHnDkLH9fblj8U5czhQ8zcxB655OFL4OPe/zUFfrtNPEFh85LxC0w+H/BdVmyIwRRX+PArWYMKPOsV6E/+wuI+aXaY8RuTb9MOQl5+XwgXMjmF8de7Wp0oUNaHC+APtmP1uVbWDyjdgcDGdZ9jY5Gffng0CYUCJCImm9d6M6+jwhDo+6V8HOSp3pyLqd1SyTH5tKa3pAB0zWV3rkataqQfAJPRmOL9FslHQ7XLylQoQsnUW1rxDSyqchI+bJrH5L/an/3cR4srWA3So58iZ5WpyQ
Date: Thu, 12 Jul 2018 17:50:29 +0000 From: Job Snijders <> To: Subject: deploying RPKI based Origin Validation Message-ID: <> Content-Type: text/plain; charset=us-ascii Hi all, I wanted to share with you that a ton of activity is taking place in the Dutch networker community to deploy RPKI based BGP Origin Validation. The mantra is "invalid == reject" on all EBGP sessions. What's of note here is that we're now seeing the first commercial ISPs doing Origin Validation. This is a significant step forward compared to what we observed so far (it seemed OV was mostly limited to academic institutions & toy networks). But six months ago Amsio (https://www.amsio.com/en/) made the jump, and today Fusix deployed (https://fusix.nl/deploying-rpki/). We've also seen an uptake of Origin Validation at Internet Exchange route servers: AMS-IX and FranceIX have already deployed. I've read that RPKI OV is under consideration at a number of other exchanges. Other cool news is that Cloudflare launched a Certificate Transparency initiative to help keep everyone honest. Announcement at: https://twitter.com/grittygrease/status/1017224762542587907 Certificate Transparency is a fascinating tool, really a necessity to build confidence in any PKI systems. Anyone here working to deploy RPKI based Origin Validation in their network and reject invalid announcements? Anything of note to share? Kind regards, Job |
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] Interesting post re:RPKI on nanog..., Steven Wallace, 07/13/2018
Archive powered by MHonArc 2.6.19.