RPKI Client
#1

L'annonce du jour concernant OpenBSD est la sortie officielle de la version 6.6 du client RPKI !

https://www.rpki-client.org/

Cette version semble particulière dans le sens où c'est la première version "portable".
https://ftp.openbsd.org/pub/OpenBSD/rpki...-6.6p2.txt

Ce client RPKI est intégré dans le système de base d'OpenBSD

GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF  9EA2 B85E 9ADA C377 5E8E
GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D  5B62 D0FF 7361 59BF 1733
Répondre
#2

Une idée de ce à quoi ça sert concrètement ? Si j'ai bien compris c'est pour utiliser des clés temporaires de chiffrement...
Répondre
#3

Suite au correctif d'hier, une nouvelle version du client rpki est de sortie aujourd'hui !

la 6.7p1…

GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF  9EA2 B85E 9ADA C377 5E8E
GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D  5B62 D0FF 7361 59BF 1733
Répondre
#4

la version 6.8p0 est sortie hier, 20 octobre 2020 :

Citation :rpki-client is a FREE, easy-to-use implementation of the Resource
Public Key Infrastructure (RPKI) for Relying Parties (RP) to
facilitate validation of the Route Origin of a BGP announcement. The
program queries the RPKI repository system and outputs Validated ROA
Payloads in the configuration format of OpenBGPD, BIRD, and also as
CSV or JSON objects for consumption by other routing stacks.

See RFC 6811 for a description of how BGP Prefix Origin Validation
secures the Internet's global routing system.

rpki-client was primarily developed by Kristaps Dzonsons, Claudio
Jeker, Job Snijders, and Sebastian Benoit as part of the OpenBSD
Project and gets released as a base component of OpenBSD every six
months, and follows the OpenBSD release numbering scheme.

This is the first release based on OpenBSD 6.8. It includes the following
changes to the previous release:

* Improve how repositories are downloaded: do not fetch symlinks and
clean extraneous files in the repositories after download using the
cryptographically signed RPKI manifest listings.

* Fix a bug where rpki-client could hang after calling rsync.

* Remove the -f option, no longer needed.

* Improved validation of the trust anchors.

* Add new option '-s timeout' to make rpki-client automatically
terminate after a timeout (default 1 hour). This helps when
rpki-client is run via cron to prevent a hanging process to cause
problems.

Portability improvements:

* Replace warnc() with warnx() + strerror()

* Replace b64_pton() with code using the libcrypto EVP_Decode*
functionality.

* Adjust for OpenSSL 1.1.x compatible use of the EVP_ENCODE_CTX
struct.

rpki-client is known to compile and run on at least the following
Linux distributions: Alpine 3.12, Debian 9, Debian 10, Fedora 31,
Fedora 32, Fedora 33, RHEL/CentOS 7, RHEL/CentOS 8.
It is our hope that packagers take interest and help adapt
OpenBGPD-portable to more distributions.

The mirrors where rpki-client can be found are on
https://www.rpki-client.org/portable.html

GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF  9EA2 B85E 9ADA C377 5E8E
GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D  5B62 D0FF 7361 59BF 1733
Répondre
#5

la version 7.0 est sortie, aujourd'hui, 16/04/2021 :

Citation :This release includes the following changes to the previous release:

* Added RRDP (The RPKI Repository Delta Protocol, RFC 8182) support
as a 'technology preview'. To use it, the "-r" flag needs to be used.
* Support the use of more than one URI in the TAL file sorting with a
preference for https.
* Validation of ghostbuster records (RFC 6493)
* Fixed checks of the manifest validity interval.
* The rsync connection is now killed when the rsync server stalls.
* Limited the URL embedded in .cer files to alphanumeric characters
and punctuation.
* Added a "-V" option to show version.
* Included the default cert.pem file path in tls_load_file error
messages.
* Use of the ibuf (imsg) API for data exchange between the
rpki-client processes.

In the portable version,

* Emit all output formats, no need to choose with options.
* Changes to for using github actions forautomatic testing.
* The RRDP support requires HTTPS connections, necessitating a
dependency for libtls from LibreSSL.
* Support for building rpki-client on MacOSX.
* Added expat as an extra dependency, needed for RRDP support.

GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF  9EA2 B85E 9ADA C377 5E8E
GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D  5B62 D0FF 7361 59BF 1733
Répondre


Atteindre :


Utilisateur(s) parcourant ce sujet : 1 visiteur(s)