nanog mailing list archives

Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security)


From: George Michaelson <ggm () apnic net>
Date: Thu, 24 Nov 2005 11:31:04 +1000



According to what I understand, there have to be two certificates per
entity:

        one is the CA-bit enabled certificate, used to sign subsidiary
        certificates about resources being given to other people to use.

        the other is a self-signed NON-CA certificate, used to sign
        route assertions you are attesting to yourself: you make this
        cert using the CA cert you get from your logical parent.

-George


Current thread: