IETF RFC 8360 PDF

IETF RFC 8360 PDF

Name:
IETF RFC 8360 PDF

Published Date:
04/01/2018

Status:
[ Active ]

Description:

Resource Public Key Infrastructure (RPKI) Validation Reconsidered

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$12
Need Help?

This document specifies an alternative to the certificate validation procedure specified in RFC 6487 that reduces aspects of operational fragility in the management of certificates in the Resource Public Key Infrastructure (RPKI), while retaining essential security features

The procedure specified in RFC 6487 requires that Resource Certificates are rejected entirely if they are found to overclaim any resources not contained on the issuing certificate, whereas the validation process defined here allows an issuing Certification Authority (CA) to chose to communicate that such Resource Certificates should be accepted for the intersection of their resources and the issuing certificate.

It should be noted that the validation process defined here considers validation under a single trust anchor (TA) only. In particular, concerns regarding overclaims where multiple configured TAs claim overlapping resources are considered out of scope for this document.

This choice is signaled by a set of alternative Object Identifiers (OIDs) per "X.509 Extensions for IP Addresses and AS Identifiers" (RFC 3779) and "Certificate Policy (CP) for the Resource Public Key Infrastructure (RPKI)" (RFC 6484). It should be noted that in case these OIDs are not used for any certificate under a trust anchor, the validation procedure defined here has the same outcome as the procedure defined in RFC 6487.

Furthermore, this document provides an alternative to Route Origin Authorization (ROA) (RFC 6482) and BGPsec Router Certificate (BGPsec PKI Profiles -- publication requested) validation


Edition : 18
File Size : 1 file , 37 KB
Number of Pages : 29
Published : 04/01/2018

History


Related products

IETF RFC 7394
Published Date: 11/01/2014
Definition of Time to Live TLV for LSP-Ping Mechanisms
$9.6
IETF RFC 8709
Published Date: 02/01/2020
Ed25519 and Ed448 Public Key Algorithms for the Secure Shell (SSH) Protocol
$9.3
IETF RFC 5178
Published Date: 05/01/2008
Generic Security Service Application Program Interface (GSS-API) Internationalization and Domain-Based Service Names and Name Type
$9.6

Best-Selling Products

DOT 23 CFR PART 625
Published Date: 04/01/2020
DESIGN STANDARDS FOR HIGHWAYS
$9
DOT 23 CFR PART 645
Published Date: 04/01/2019
UTILITIES
$10.8
DOT 23 CFR PART 655
Published Date: 04/01/2018
TRAFFIC OPERATIONS
$9.3
DOT 33 CFR PART 127
Published Date: 07/01/2019
WATERFRONT FACILITIES HANDLING LIQUEFIED NATURAL GAS AND LIQUEFIED HAZARDOUS GAS
$11.7
DOT 33 CFR PART 154
Published Date: 07/01/2017
FACILITIES TRANSFERRING OIL OR HAZARDOUS MATERIAL IN BULK
$18.3
DOT 33 CFR PART 154
Published Date: 07/01/2019
FACILITIES TRANSFERRING OIL OR HAZARDOUS MATERIAL IN BULK
$18.3