[routing-wg]Re: AW: [db-wg] Call for agenda items, DB-WG Meeting during RIPE53, Amsterdam
[Copying routing-wg. Brief background; this is about relaxing the restrictions on creating/modifying route: objects in the RIPE database, as previously discussed in the threads starting at the following messages: http://www.ripe.net/ripe/maillists/archives/db-wg/2006/msg00053.html http://www.ripe.net/ripe/maillists/archives/db-wg/2006/msg00017.html ]
In any case, I guess there will be some RFC/s that need/s changing if and when we can reach consensus in the community along the lines of your thoughts.
Right. This came up before the Istanbul meeting, then during the meeting it was mentioned again (in the routing WG), and Andrei talked briefly about the current scheme. However, there was pretty much no feedback from the floor or via jabber, so it was decided that it would be moved to the mailing list. There was a brief discussion on the list, but that fizzled out too. If there is enough desire to do this, then somebody needs to write a document. I guess that initially it could be a RIPE document, but eventually it should aim to update RFC2725 section 9.9, so maybe it would be good to have it as close to internet-draft format as possible from the start. I'm open to having another slot during the Amsterdam meeting if there is interest. As I see it, that could be one of two things: 1) A quick call for help in editing the document to create a proposal. 2) If we've got a draft of a proposal by then, discussion on it. Either way, we need to have someone willing to talk and an idea of how long you want to talk for! :-) All the best, Rob
Rob Evans wrote: [...]
1) A quick call for help in editing the document to create a proposal.
2) If we've got a draft of a proposal by then, discussion on it.
[ NOT waering my DB-WG Chair hat right now, just my Security Team Member's hat ] Any such document should be very clear and broad in describing the potential security and/or operational impacts and risks incurred by relaxing the established rules. (IRR Sanity and filter Configuration Tools) Some stuff that occurs to me immediately is - impact on ability to use (own or hi-jacked) IP-Address-Blocks for Spam-Runs, - to get address blocks routed differently for the duration of DoS Attacks, - to impede connectivity tracking mechanisms for Phishing Sites - to punch more specific holes into a PA Block - to claim customer relationship without a contract in place - to effectively make a (subset) of a PI block usable as PI - to cheat with eXchange Point Access Policy Requirements - to ....
Either way, we need to have someone willing to talk and an idea of how long you want to talk for! :-)
All the best, Rob
Another bout of CERT Paranoia maybe, yours, Wilfried.
participants (2)
-
Rob Evans
-
Wilfried Woeber, UniVie/ACOnet