<div dir="auto">Hi guys<div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto">As far as i know, no vendor supports bgpsec, so what's the point of adding bgpsec support to hosted rpki?</div><div dir="auto">also cause of encryption/decryption process via async encryption method, it's a resource intensive process so not all routers are able to handle it, also the more important part is bgpsec changes the normal behavior of bgp, for instance, update packing (update group) will be disabled. Are we just discussing the support of bgpsec certs on hosted rpki, and we would discuss bgpsec deployment impacts and open issues later?</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Oct 4, 2021, 2:55 PM Simon Muyal <<a href="mailto:smuyal@franceix.net">smuyal@franceix.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  
    
  
  <div>
    <br>
    <br>
    <div>Le 01/10/2021 à 17:06,
      <a href="mailto:marco@lamehost.it" target="_blank" rel="noreferrer">marco@lamehost.it</a> a écrit :<br>
    </div>
    <blockquote type="cite">
      <pre>On Mon, 2021-09-20 at 00:28 +0200, job at <a href="http://fastly.com" target="_blank" rel="noreferrer">fastly.com</a> wrote:
</pre>
      <blockquote type="cite">
        <pre>Dear all,

[ TL;DR: What does the working group think about supporting an
extension
         to the RPKI Dashboard to enable publication of BGPsec certs?
]

At the moment the hosted "RPKI Dashboard" at
<a href="https://my.ripe.net/#/rpki" target="_blank" rel="noreferrer">https://my.ripe.net/#/rpki</a>,
only permits Resource Holders to create RPKI objects of one specific
type: ROAs. However, a wider range of RPKI cryptographic product
types
also exists, for example: BGPsec Router Certificates [RFC 8209].

BGPsec is a RPKI-based technology which enables network operators to
transitively validate whether a given BGP UPDATE - indeed - passed
through the Autonomous Systems listed in the path. One way to think
of
BGPsec is as an ECDSA protected network of channels between a
receiving
EBGP node; and one (or many) routers in the BGP route's Origin AS.

I think BGPsec can be useful to protect "private peering" at large
scale, and another use case is to increase confidence in routing
information distributed via IXP Route/Blackhole Servers.

Right now, routing protocol researchers and network operators wishing
to
publish BGPsec Router Keys, also have to learn how to master
"Delegated
RPKI": a deployment model with a steep learning curve. I think there
are
benefits to the community if RIPE NCC appends an activity to the
"RPKI
Planning and Roadmap" to implement procedures to sign and publish
BGPsec
Router Keys via a PKCS#10 / PKCS#7 exchange, callable via both API
and
dashboard WebUI.

What do others think?

Kind regards,

Job

Relevant documentation:
<a href="https://datatracker.ietf.org/doc/html/rfc8209" target="_blank" rel="noreferrer">https://datatracker.ietf.org/doc/html/rfc8209</a>
<a href="https://datatracker.ietf.org/doc/html/rfc8635" target="_blank" rel="noreferrer">https://datatracker.ietf.org/doc/html/rfc8635</a>

</pre>
      </blockquote>
      <pre>
Hello,

I support the idea as it would enable network operators to explore the
benefits of BGPsec in production environment. And the effort sounds
small
</pre>
    </blockquote>
    Hello all,<br>
    <br>
    +1<br>
    The effort to enable publication of BGPsec certs on the RPKI
    dashboard seems reasonable as there is already an hosted RPKI and a
    portal to manage ROAs.<br>
    Having an hosted RPKI for BGPSec objects will help definitely
    operators who do not have the resources to manage a PKI<br>
    <br>
    <blockquote type="cite">
      <pre>
Regards


</pre>
    </blockquote>
    <br>
    <div>-- <br>
      
      <hr style="background-color:#cccccc;height:1px;border:0">
      <table>
        <tbody>
          <tr>
            <td rowspan="2">
              <table style="background:none;border-width:0px;border:0px;margin:0;padding:0" cellspacing="0" cellpadding="0" border="0">
                <tbody>
                  <tr>
                    <td> <a href="https://franceix.net" style="border-width:0px;border:0px;text-decoration:none" target="_blank" rel="noreferrer"> <img style="width:140px;padding-bottom:0" id="m_2743192209354858805preview-image-url" src="https://www.franceix.net/media/cms_page_media/811/Logo-france-ix.png">
                      </a> </td>
                  </tr>
                  <tr>
                    <td> <a href="https://franceix.net" style="border-width:0px;border:0px;text-decoration:none" target="_blank" rel="noreferrer"> <img style="width:120px;padding-bottom:0" id="m_2743192209354858805preview-image-url" src="https://www.franceix.net/media/cms_page_media/811/logo-rezopole.png">
                      </a> </td>
                  </tr>
                </tbody>
              </table>
            </td>
          </tr>
          <tr>
            <td style="padding-left:15px;border-left:solid 1px #c6d0dc">
              <table style="background:none;border-width:0px;border:0px;margin:0;padding:0" cellspacing="0" cellpadding="0" border="0">
                <tbody>
                  <tr>
                    <td colspan="2" style="padding-bottom:2px;color:#292f36;font-size:16px;font-family:Arial,Helvetica,sans-serif">Simon <strong>MUYAL</strong></td>
                  </tr>
                  <tr>
                    <td colspan="2" style="padding-bottom:1px;color:#fb4d3d;font-size:13px;font-family:Arial,Helvetica,sans-serif" width="300"><strong>Directeur
                        Technique / Chief Technical Officer</strong></td>
                  </tr>
                  <tr>
                    <td><br>
                    </td>
                  </tr>
                  <tr>
                    <td style="padding-bottom:1px;vertical-align:top;width:70px;color:#333333;font-size:13px;font-family:Arial,Helvetica,sans-serif" width="70" valign="top"><span style="color:#292f36">Tel :</span><strong>+33 1 70 61 97 74</strong></td>
                  </tr>
                  <tr>
                    <td style="padding-bottom:1px;vertical-align:top;width:151px;color:#333333;font-size:13px;font-family:Arial,Helvetica,sans-serif" width="151" valign="top"><span style="color:#292f36">Site : </span><a href="http://www.franceix.net" style="padding-bottom:1px;color:#333333;text-decoration:none;font-weight:normal;font-size:13px" target="_blank" rel="noreferrer">www.franceix.net</a> </td>
                  </tr>
                </tbody>
              </table>
            </td>
          </tr>
          <tr>
            <td colspan="2"> <a href="https://blog.franceix.net/france-ix-and-rezopole-become-one/" target="_blank" rel="noreferrer"> </a> <br>
            </td>
          </tr>
          <tr>
            <td> <a href="https://fr-fr.facebook.com/ixpfranceix/" style="border-width:0px;border:0px;text-decoration:none" target="_blank" rel="noreferrer"> <img style="border:none;width:25px;max-width:25px!important;height:25px;max-height:25px!important" src="https://franceix.net/media/pictos/downloads/facebook-logo-button.png" width="25" height="25"></a>   <a href="https://twitter.com/ixpfranceix" style="border-width:0px;border:0px;text-decoration:none" target="_blank" rel="noreferrer"> <img style="border:none;width:25px;max-width:25px!important;height:25px;max-height:25px!important" src="https://franceix.net/media/pictos/downloads/twitter-logo-button.png" width="25" height="25"></a>   <a href="https://www.linkedin.com/company/france-ix/?originalSubdomain=fr" style="border-width:0px;border:0px;text-decoration:none" target="_blank" rel="noreferrer"> <img style="border:none;width:25px;max-width:25px!important;height:25px;max-height:25px!important" src="https://franceix.net/media/pictos/downloads/linkedin-logo-button.png" width="25" height="25"> </a> </td>
          </tr>
        </tbody>
      </table>
    </div>
  </div>

</blockquote></div>