<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.17 (Ruby 2.7.2) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-meynell-panrg-scion-deployment-00" category="info" submissionType="IRTF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.22.0 -->
  <front>
    <title abbrev="SCION DI">SCION Deployment Issues</title>
    <seriesInfo name="Internet-Draft" value="draft-meynell-panrg-scion-deployment-00"/>
    <author initials="K." surname="Meynell" fullname="Kevin Meynell">
      <organization>SCION Association</organization>
      <address>
        <email>kme@scion.org</email>
      </address>
    </author>
    <author initials="N." surname="Rustignoli" fullname="Nicola Rustignoli">
      <organization>SCION Association</organization>
      <address>
        <email>nic@scion.org</email>
      </address>
    </author>
    <date year="2024" month="July" day="08"/>
    <area>IRTF</area>
    <workgroup>PANRG</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 88?>

<t>TODO Abstract here</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://scionassociation.github.io/scion-deployment_I-D/draft-meynell-panrg-scion-deployment.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-meynell-panrg-scion-deployment/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        WG Working Group mailing list (<eref target="mailto:panrg@irtf.org"/>),
        which is archived at <eref target="https://datatracker.ietf.org/rg/panrg"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/panrg/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/scionassociation/scion-deployment_I-D"/>.</t>
    </note>
  </front>
  <middle>
    <?line 93?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>The goal of this draft is two-fold: it tries to document lessons learned in deploying SCION to some if its productive early adopters, and it tries to tries to answer questions 2.7 - Operating a Path-Aware Network, and 2.8 - Deploying a Path-Aware Network posed in <xref target="RFC9217"/>.</t>
      <t><strong>Note:</strong> This is the very first version of the SCION deployment draft, and it merely contains a skeleton of potential topics to be further discussed in this draft. Any feedback is welcome and much appreciated. Thanks!</t>
      <ul spacing="normal">
        <li>
          <t>This draft assumes the reader is familiar with the overall core SCION specification, outlined in <xref target="I-D.scion-dataplane"/>, <xref target="I-D.scion-cppki"/>, <xref target="I-D.scion-cp"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="deployment-models">
      <name>Deployment Models</name>
      <section anchor="scion-network-how-to-roll-it-out">
        <name>SCION Network - How to roll it out.</name>
      </section>
      <section anchor="scion-ip-gateway">
        <name>SCION-IP Gateway</name>
        <t>Introduction to IP in SCION tunneling for ecosystems. See S. Hitz IETF118 presentation: https://datatracker.ietf.org/meeting/118/materials/slides-118-panrg-operational-aspects-of-scion-00</t>
      </section>
      <section anchor="scion-enabled-applicationsnative-scion-endpoint">
        <name>SCION-enabled Applications/Native SCION Endpoint</name>
      </section>
      <section anchor="implications-for-the-transport-layer">
        <name>Implications for the transport layer</name>
        <t>Address section 2.5 of <xref target="RFC9217"/>.</t>
      </section>
    </section>
    <section anchor="establishing-and-running-an-isolation-domain">
      <name>Establishing and running an Isolation Domain</name>
      <t>See F. Steinmann presentation IETF118 - https://datatracker.ietf.org/meeting/118/materials/slides-118-panrg-scion-deployment-experience-the-secure-swiss-finance-network-ssfn</t>
      <section anchor="description-and-use-case">
        <name>Description and use case</name>
      </section>
      <section anchor="governance">
        <name>Governance</name>
      </section>
      <section anchor="core-members-trc-signers">
        <name>Core Members - TRC signers</name>
      </section>
      <section anchor="issuing-members-issuers-of-as-certifications">
        <name>Issuing Members - issuers of AS certifications</name>
        <t>(may be the same as Core Members)</t>
      </section>
      <section anchor="non-core-members">
        <name>Non-Core Members</name>
      </section>
      <section anchor="coordination">
        <name>Coordination</name>
      </section>
      <section anchor="required-contact-information">
        <name>Required contact information</name>
      </section>
      <section anchor="methods-of-communication-and-authentication-requirements">
        <name>Methods of Communication and Authentication requirements</name>
      </section>
      <section anchor="isd-policy-development-maintenance">
        <name>ISD Policy Development &amp; Maintenance</name>
      </section>
      <section anchor="assignment-and-registration-of-isd-numbers">
        <name>Assignment and registration of ISD numbers</name>
      </section>
      <section anchor="assignment-and-registration-of-scion-as-numbers">
        <name>Assignment and registration of SCION AS numbers</name>
      </section>
      <section anchor="trust-root-configuration">
        <name>Trust Root Configuration</name>
        <ul spacing="normal">
          <li>
            <t>TRC signing</t>
          </li>
          <li>
            <t>TRC distribution &amp; installation</t>
          </li>
          <li>
            <t>Maintaining cryptographic material</t>
          </li>
          <li>
            <t>Certificate issuance</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="establishing-and-running-a-scion-network">
      <name>Establishing and running a SCION network</name>
      <section anchor="prerequisites-eg-as-number-running-existing-intra-domain-protocol-if-applicable">
        <name>Prerequisites - e.g. AS number, running existing intra-domain protocol if applicable</name>
      </section>
      <section anchor="how-to-join-an-isd">
        <name>How to join an ISD</name>
      </section>
      <section anchor="obtaining-a-scion-as-number-and-as-certificate">
        <name>Obtaining a SCION AS number and AS certificate</name>
      </section>
      <section anchor="setting-up-the-control-services-beacon-path-and-certificate-servers">
        <name>Setting up the Control Services (Beacon, Path and Certificate servers)</name>
        <t>Also cover Availability &amp; scalability of such services.</t>
      </section>
      <section anchor="setting-up-scion-border-routers">
        <name>Setting up SCION border routers</name>
      </section>
      <section anchor="configuring-path-segment-attributesparameters">
        <name>Configuring path (segment) attributes/parameters</name>
        <t>How do customers select paths?</t>
      </section>
      <section anchor="scion-network-address-translation">
        <name>SCION &amp; Network Address Translation</name>
      </section>
      <section anchor="software-change-management">
        <name>Software Change Management</name>
      </section>
    </section>
    <section anchor="adding-and-removing-networks-from-an-isolation-domain">
      <name>Adding and removing networks from an Isolation Domain</name>
      <section anchor="adding-a-new-core-network">
        <name>Adding a new Core network</name>
      </section>
      <section anchor="removing-an-existing-core-network">
        <name>Removing an existing Core network</name>
      </section>
      <section anchor="changes-between-existing-core-networks">
        <name>Changes between existing Core networks</name>
      </section>
      <section anchor="adding-a-new-non-core-network">
        <name>Adding a new non-Core network</name>
      </section>
      <section anchor="removing-an-existing-non-core-network">
        <name>Removing an existing non-Core network</name>
      </section>
      <section anchor="changes-between-core-network-and-non-core-network">
        <name>Changes between Core network and non-core network</name>
      </section>
    </section>
    <section anchor="connecting-to-other-isolation-domains">
      <name>Connecting to other Isolation Domains</name>
      <section anchor="inter-isd-governance">
        <name>Inter-ISD Governance</name>
        <ul spacing="normal">
          <li>
            <t>Inter-ISD Governance (is this applicable?)</t>
          </li>
          <li>
            <t>Inter-ISD Policy Development &amp; Maintenance</t>
          </li>
          <li>
            <t>Inter-ISD Path selection</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="performance-monitoring">
      <name>Performance Monitoring</name>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="security-incident-handling">
        <name>Security Incident Handling</name>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="RFC9217">
        <front>
          <title>Current Open Questions in Path-Aware Networking</title>
          <author fullname="B. Trammell" initials="B." surname="Trammell"/>
          <date month="March" year="2022"/>
          <abstract>
            <t>In contrast to the present Internet architecture, a path-aware internetworking architecture has two important properties: it exposes the properties of available Internet paths to endpoints, and it provides for endpoints and applications to use these properties to select paths through the Internet for their traffic. While this property of "path awareness" already exists in many Internet-connected networks within single domains and via administrative interfaces to the network layer, a fully path-aware internetwork expands these concepts across layers and across the Internet.</t>
            <t>This document poses questions in path-aware networking, open as of 2021, that must be answered in the design, development, and deployment of path-aware internetworks. It was originally written to frame discussions in the Path Aware Networking Research Group (PANRG), and has been published to snapshot current thinking in this space.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="9217"/>
        <seriesInfo name="DOI" value="10.17487/RFC9217"/>
      </reference>
      <reference anchor="I-D.scion-cp" target="https://datatracker.ietf.org/doc/draft-dekater-scion-controlplane/">
        <front>
          <title>SCION Control Plane</title>
          <author initials="C." surname="de Kater" fullname="Corine de Kater">
            <organization>SCION Association</organization>
          </author>
          <author initials="N." surname="Rustignoli" fullname="Nicola Rustignoli">
            <organization>SCION Association</organization>
          </author>
          <author initials="S." surname="Hitz" fullname="Samuel Hitz">
            <organization>Anapaya Systems</organization>
          </author>
          <date year="2023"/>
        </front>
      </reference>
      <reference anchor="I-D.scion-cppki" target="https://datatracker.ietf.org/doc/draft-dekater-scion-pki/">
        <front>
          <title>SCION Control-Plane PKI</title>
          <author initials="C." surname="de Kater" fullname="Corine de Kater">
            <organization>SCION Association</organization>
          </author>
          <author initials="N." surname="Rustignoli" fullname="Nicola Rustignoli">
            <organization>SCION Association</organization>
          </author>
          <author initials="S." surname="Hitz" fullname="Samuel Hitz">
            <organization>Anapaya Systems</organization>
          </author>
          <date year="2023"/>
        </front>
      </reference>
      <reference anchor="I-D.scion-dataplane" target="https://datatracker.ietf.org/doc/draft-dekater-scion-dataplane/">
        <front>
          <title>SCION Data Plane</title>
          <author initials="C." surname="de Kater" fullname="Corine de Kater">
            <organization>SCION Association</organization>
          </author>
          <author initials="N." surname="Rustignoli" fullname="Nicola Rustignoli">
            <organization>SCION Association</organization>
          </author>
          <author initials="S." surname="Hitz" fullname="Samuel Hitz">
            <organization>Anapaya Systems</organization>
          </author>
          <date year="2023"/>
        </front>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
    </references>
    <?line 236?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO acknowledge.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1YbW8bNxL+vr+CVYAgCbKr2M0hqdBrqkpOIiSWfZaCojgc
DtTuSOJ5l9ySXKm6wP+lv6W/7J4hV2+2W7dA71uNJF6S8/rMcGaYNE0Tr3xJ
PdGZDEYXYzGkujSbirQXI+cacp1EzmaWVnuKUSfJpaeFsZueUHpuEtfMKuWc
MtpvasgaXU3fJklhci0rLAsr5z6taKOpLNNaartIXQ7qtNhpS1+8SBIo+TKR
lmQrYm3s9cKapu6Jy/746l1yTRvsFTjWnqwmnw5ZdrIi3VAvEaKl/v4dvqMt
30OG0gvxjk+wW0lV9kQw4ltl/TwzdoFtafNlTyy9r12v2y2kl97K/JpspigS
dfEnsLEa5ZfNrCeCF9I5kyvp8dm97da/R+kQ9CXwcn4v/zZfFgVmytwroft7
EMyWviqTRDZ+aSywSIVAdFxPfMjEeeSEJfiJQflAK6WPD+BkT8Qg9/e2xTOK
uF1X9G1QHGA7UDLOxFXjvFpoU6pDPWOVm1LeOfwdurTKD3VpYysQrUKcr94O
vjo9ecWfwCeLWOR1LwhoMzpKHyAprSnFZSk1hWMEF6enL06/jNTSLsg/EHvk
chuEgq7Bb1v48yi9ZuHdIG6Hf/hJ298tSoNMFCQ+sIDdQYRpYKzSdPf0t3C6
Lf2eGDwUhj+oYZKJ98r/95bsiawaKo9PgtS+lrXcSDHZOE+VuxWs+lr9erzS
EC9x+WH0p8cMev8K1R8JFaMbMvyecA1x9n+6Wzu1f0XroWhxF95VxyRJ01TI
mWOkfZJML4YXot8uxZIstSSVKooSi0fcTq0pmjwYmEyXJBZGlsLMhV8qFxu4
wIdfm3RuSjRg5YW3irBlBALYhImhJPipHX5LNOcCronYn7gBRyRA7kxFQs0h
wom6VbsiAZ5yI2RhaoTJPRdSF0dadh9SuzVZ8SOGE7bXidPsFRrRRU0WCEAT
ElL6ZdpfY5QQY/I8RkR5p9lrUA53Nt1HKWrjou2fP7dt5uYmS5Jnz8YGyf3s
mZgyJowGcFqR3Yi5ss7zJ49AETVq/d3354jizq8KcYC/3EAkUgCmuGsqyUcB
NVRprxADb2qVB79nJOaNhWgrCuXyxrVm7kOUITFgDVExwx1jE9dU5gw3K62a
fClkXVviVKQigyNSX7sv4Fv0KcYZcwnCGd3DLFZAH87mslKlklasMaqEMwOH
ZVnCBbv11tWQPVd5yPTnwjS+VHoL5j0F5ebm+dFBaAp3NwP+SFP0hhXDwkFn
j4Y0V1qFdcxazIeCB0QnOuefJtPO8/hbjC/C99XZPz6Nrs6G/D153//4cfeR
tBST9xefPg73X3vOwcX5+dl4GJmxK462ks55/4dODG7n4nIKMPofO/vobG8I
51kMpeIJFrFAIIB4UpDLrZpFrL4bXP7y88lLoPAFMvD05OSrm5t28frk1Uss
1kvSUZvRyKK4RFA2CQKMm8RSQmxkrbws+To54ZZmrUMB4HT+JyPzr574epbX
Jy+/aTfY4aPNLWZHmwGzuzt3mCOI92zdo2aH5tH+LaSP7e3/cLTe4n6w+fUb
TkCRnrx+801IoYP3zbkpqETiPHrUZu+2AKTivVlzmDCHlHxXkcfZni4dXYp3
uEBruUmSw8rJLDgD9G2tazSGa64zqM6CcuNiuc7EhGhb8sXobPr25OQ1SiE5
mBWuzgMdsyLiQtcFW7firoZC4bquVMiiFJvtC8HEioiXRplKvprepWbedld+
b+08Ii1nJXKvX9dle3tddxz6SevLmS5qg5wNTKNqTxZ843IAK7WrjUUbkBs0
2qRfFHAJaUcRndPsb1zajqsqQnLmPLQrtwwVGSltgVv8xhsUzTVwDw1eBWhO
DN1bIOhJ6UpqfYTbDsz0TwHwziOVfgKkinROKVxO4Vlj8WuNx2+KUiT5QMcs
Sp2b64DWMFztOtjH7jWOcC8dhcN3XEUDY1gOuJaeUzVDL4ET06uBcBgrsIrA
ozQzMnsKxY90fAHY/kTkZP2u/oLlSSU3XGw4Pk5yH3BHKp4GqWM4ebjbWoI6
CpfiSICNK/qxURZJEloWJond0NESnBMGtCKYMjBV1ejWjuB0H9Mbl+52y0Zh
DGrr2WQoLjE95RvgtaLS1OGOPhbnkivlHiGMUgAkFlPOFVoonmx823lZjm72
bjxA3o5nkyOeqcUwJ66M8dxx5mrRRAZuk21AEIR2VbA8NWuCxMc8zaHellv6
YD3+ctByu6m9WVhZL1UutmkHosEuahTiGX397avRWt4mWzD70lKA1SlPnBqU
LbK9a893vPQTTOYPmGZlWoSLxZOYNxhleTKTsQzMygh5Ww3/Y7ipaIY4bF/M
tp7J2zjGkB/mY5Q0IR80N3VIye3bfEJ2pXIY/eQ7kjlPDjyWBSGH2DiQxaTt
l84gD7ES/ZVUpZxhNvEb4O9yuVshvo5nHteKz27bEK2eIdEhyKLKhwyI2R/j
zoQ12/LE0YKz6KmQPsabXLeWFpcqcjFIBYxC6mDgslz2ShS+wO3eHHSZx7s+
sy2QU66c5f4iTczch4l0gPlsgWsptVyEu8I5Aa5dNlBlVrxo0wDF2Jrq/rr5
aM8J8nUsA4fpc7UVBvZdityhiiY5FBW/JvoVSndXnd7WmAdV3kt5W+0hQYBC
h/+MOeLiIGruPRCK9DVhcr4NTFt9eBhLuXYc1uNn9+6LJ2H0xz/7a/Lm6RHx
g4XsiJjTKyZLSAAYfkk2lFbWdm4w4fIbdhGOJtxyOLnhnEO7sttS/+jgbKRz
HEHre0BTbllH/XH/Dtv0aDxdoj9oEyllsIcvTXgs8osipF9+rc0aw8IiFu/P
vXjlqfh7Z44uSp2b9skpd5SYN/8HIKk6oWoWAAA=

-->

</rfc>
