nanog mailing list archives
Re: [ncc-services-wg] RPKI Resource Certification: building features
From: Owen DeLong <owen () delong com>
Date: Sun, 3 Oct 2010 19:38:52 -0700
On Oct 3, 2010, at 7:26 PM, Randy Bush wrote:
Do you think there is value in creating a system like this?yes. though, given issues of errors and deliberate falsifications, i am not entirely comfortable with the whois/bgp combo being considered formally authoritative. but we have to do something.Are there any glaring holes that I missedyes. the operator should be able to hold the private key to their certificate(s) or the meaning of 'private key' and the security structure of the [ripe part of the] rpki is a broken. randy
I'll go a step further and say that the resource holder should be the ONLY holder of the private key for their resources. Owen
Current thread:
- Re: [ncc-services-wg] RPKI Resource Certification: building features Randy Bush (Oct 03)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Owen DeLong (Oct 03)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Alex Band (Oct 04)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Owen DeLong (Oct 04)
- Message not available
- Re: [ncc-services-wg] RPKI Resource Certification: building features Owen DeLong (Oct 04)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Alex Band (Oct 04)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Owen DeLong (Oct 03)
- Message not available
- Re: [ncc-services-wg] RPKI Resource Certification: building features Randy Bush (Oct 04)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Alex Band (Oct 05)
- Re: [ncc-services-wg] RPKI Resource Certification: building features Randy Bush (Oct 05)
- <Possible follow-ups>
- Re: [ncc-services-wg] RPKI Resource Certification: building features mkarir (Oct 04)