RPKI Trust Anchor Geoff Huston APNIC.

Slides:



Advertisements
Similar presentations
A Profile for Trust Anchor Material for the Resource Certificate PKI Geoff Huston SIDR WG IETF 74.
Advertisements

Local TA Management A TA is a public key and associated data used as the starting point for certificate path validation It need not be a self-signed certificate.
June 2013 Internet Number Resource Report. June 2013 Internet Number Resource Report INTERNET NUMBER RESOURCE STATUS REPORT As of 30 June 2013 Prepared.
December 2013 Internet Number Resource Report. December 2013 Internet Number Resource Report INTERNET NUMBER RESOURCE STATUS REPORT As of 31 December.
March 2014 Internet Number Resource Report. March 2014 Internet Number Resource Report INTERNET NUMBER RESOURCE STATUS REPORT As of 31 March 2014 Prepared.
1 Overview of policy proposals Policy SIG Wednesday 26 August 2009 Beijing, China.
RPKI and Routing Security ICANN 44 June Today’s Routing Environment is Insecure Routing is built on mutual trust models Routing auditing requires.
An Introduction to Routing Security (and RPKI Tools) Geoff Huston May 2013.
Resource Certificate Profile Geoff Huston, George Michaelson, Rob Loomans APNIC IETF 67.
Validation Algorithms for a Secure Internet Routing PKI David Montana Mark Reynolds BBN Technologies.
RPKI Validation - Revisited draft-huston-rpki-validation-01.txt Geoff Huston George Michaelson APNIC Slide 1/19.
RPKI Validation - Revisited draft-huston-rpki-validation-00.txt Geoff Huston George Michaelson APNIC.
Local TA Management In prior WG meetings I presented a model for local management of trust anchors for the RPKI In response to these presentations, a.
Some Lessons Learned from Designing the Resource PKI Geoff Huston Chief Scientist, APNIC May 2007.
APNIC Trial of Certification of IP Addresses and ASes RIPE 52 Plenary George Michaelson Geoff Huston.
Resource Certificate Profile SIDR WG Meeting IETF 66, July 2006 draft-ietf-sidr-res-certs-01 Geoff Huston Rob Loomans George Michaelson.
Progress Report on resource certification February 2007 Geoff Huston Chief Scientist APNIC.
The Resource Public Key Infrastructure Geoff Huston APNIC.
Global policy proposal for the allocation of IPv4 blocks to Regional Internet Registries prop-069-v002.
A PKI for IP Address Space and AS Numbers Stephen Kent.
APNIC eLearning: Intro to RPKI 10 December :30 PM AEST Brisbane (UTC+10)
1 San Diego, California 25 February Securing Routing: RPKI Overview Mark Kosters Chief Technology Officer.
The Status of APNIC’s IPv4 Resources: Exhaustion & Transfers Geoff Huston APNIC Labs.
Copyright © 2007 Japan Network Information Center Global Policy for the Allocation of the remaining IPv4 Address Space  Japan Network Information Center.
Einar Bohlin Regional PDP Report. Proposal topics at the 5 RIRs ARIN portion Q (35) Q (32) Q (50) Q (52) 0 Total.
1 Madison, Wisconsin 9 September14. 2 Security Overlays on Core Internet Protocols – DNSSEC and RPKI Mark Kosters ARIN Engineering.
Updates to the RPKI Certificate Policy I-D Steve Kent BBN Technologies.
1 APNIC Trial of Certification of IP Addresses and ASes RIPE October 2005 Geoff Huston.
Current Policy Topics Emilio Madaio RIPE NCC RIPE November 2010, Rome.
A proposal for ….. Proposer name APNIC 39 Open Policy Meeting Fukuoka, Japan Thursday, 5 March 2015.
November 2006 Geoff Huston APNIC
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
The Status of APNIC’s IPv4 Resources: Exhaustion & Transfers
Proposer name APNIC XX Open Policy Meeting Locations Date
Addressing 2016 Geoff Huston APNIC.
APNIC Trial of Certification of IP Addresses and ASes
Regional Internet Registries
A Coordinated Proposal Regional Internet Registries
IP Addresses in 2016 Geoff Huston APNIC.
Introduction to ARIN and the Internet Registry System
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
July 2016 Internet Number Resource Report.
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
APNIC Trial of Certification of IP Addresses and ASes
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
Resource Certificate Profile
Downstream Allocations by LIRs A Proposal
1.
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
Progress Report on Resource Certification
October 2006 Geoff Huston APNIC
July 2016 Internet Number Resource Report.
ROA Content Proposal November 2006 Geoff Huston.
Resource Certificate Profile SIDR WG Meeting IETF 66, July 2006
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
INTERNET NUMBER RESOURCE STATUS REPORT
July 2016 Internet Number Resource Report.
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
PKI (Public Key Infrastructure)
DNS Operations SIG APNIC , Kyoto
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
July 2016 Internet Number Resource Report.
INTERNET NUMBER RESOURCE STATUS REPORT
IPv6 distribution and policy update
July 2016 Internet Number Resource Report.
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
IPv6 Address Space Management A follow up to RIPE-261
July 2016 Internet Number Resource Report.
Internet Number Resource Status Report Regional Internet Registries
INTERNET NUMBER RESOURCE STATUS REPORT Regional Internet Registries
Presentation transcript:

RPKI Trust Anchor Geoff Huston APNIC

Public Keys How can you “trust” a digital signature? What if you have never met the signer and have no knowledge of them or their keys? One approach is transitive trust via a hierarchy of public key certificates (there are other approaches, based on “web of trust” models, but lets not go there) ? Signed by foo!

Public Key Infrastructure For transitive trust, you have to start somewhere with some initial entity (or entities) in whom you are prepared to trust This is your TRUST ANCHOR set, and you keep a local copy of their public key in your certificate store as Trusted Certificates Each Trust Anchor entry matches a unique PUBLIC KEY can can be used to certify a Certificate issued by this Certification Authority Key Store ? Signed by foo!

Public Key Infrastructure Validation is a process of finding a chain of public key certificates that link a trust anchor to the entity being validated in this manner Key Store ? Signed by foo!

The Resource Public Key Infrastructure The RPKI is a conventional PKI where the Certificate Issuer certifies BOTH the public key of the subject and the subject’s number resource holdings As it is a conventional PKI, the RPKI needs to have Trust Anchor(s) What models can be used to publish proposed Trust Anchors for the RPKI? And who can (or should) publish this Trust Anchor Material?

RPKI Certificates Follow Allocations: A single IANA-issued Trust Anchor 0/0 Public Key AFRINIC APNIC ARIN LACNIC RIPE NCC Number Resource contents of RIR Subordinate CAs issued by the IANA match the contents of the IANA Number Registries

RPKI Certificates Follow Allocations: A single IANA-issued Trust Anchor 0/0 Public Key AFRINIC APNIC ARIN LACNIC RIPE NCC The issue here is how to certify transferred resources. These resources are not separately listed in the IANA registries so will not be included in the IANA-issued CA Certificate. If we want to preserve this clear top-level certificate model then the implication is that modelling transferrred resources in this RPKI will: require RIRs to issue certificates for each other and because the certification validation paths will differ, a user holding transferred resources may be issued with multiple certificates

IANA TA, RPKI Certificates Follow Allocations 0/0 Public Key AFRINIC APNIC ARIN LACNIC RIPE NCC From APNIC From ARIN From LACNIC From AFRINIC From ARIN From LACNIC From AFRINIC From APNIC From LACNIC From AFRINIC From APNIC From ARIN From AFRINIC From APNIC From ARIN From RIPE NCC From RIPE NCC From RIPE NCC From RIPE NCC From LACNIC This results in a complex inter-RIR CA structure to support transfers And ALL RIRs need to be in a position to support this model as a precondition to adoption But if one of more RIRs are not ready to do this, what can be done?

Interim APNIC TA Structure From AFRINIC From ARIN From LACNIC From RIPE NCC The interim model used by APNIC promotes the 5 “top level” certificates where APNIC would be the subject into a compound trust anchor containing 5 self-signed certificates This will allow APNIC to migrate to a single IANA TA without major change (the self signed certificates are changed to certificate signing requests and the local trust structure can be removed)

Other possible interim TA models APNIC All resources in APNIC’s registry This is a much simpler model, and is the one used by other RIRs as an interim per-RIR TA But this is some distance from the requirements to support a single IANA TA in the future So the amount of work and user impact to transform from this self-signed TA cert structure to a single IANA TA would be far larger

Other possible interim TA models APNIC 0/0 All resources This simplifies the TA structure further, as no changes are required to the TA in the event of resource movement. The published per RIR TA is essentially static so off-line (or even one-shot use) keys can be used However it does not reflect APNIC’s current resource holdings in the TA certificate

Comments? Questions?