nanog mailing list archives

Re: [arin-announce] ARIN Resource Certification Update


From: sthaug () nethelp no
Date: Sun, 30 Jan 2011 17:28:04 +0100 (CET)

- Hosted solutions offer a low barrier entry to smaller organizations
who simply cannot develop their own PKI infrastructure. This is the
case where they also lack the organizational skills to properly manage
the keys themselves, so, in most cases at least, they are *better off*
with a hosted solution

They also offer an attractive target for miscreants with a huge payoff
if they are ever compromised.
...
For RIPE, their hosted solution is clearly meeting expectations within
their region. Other regionĀ“s mileage may vary. I hope we (LACNIC) can
do just as well.

We'll see how people feel after the first time it gets pwn3d.

I am already trusting RIPE with my data - specifically, RIPE publishes
route objects for my prefixes, and my transit providers generate their
prefix lists based on these route objects. I fail to see how a hosted
RPKI solution would make this situation worse.

Steinar Haug, Nethelp consulting, sthaug () nethelp no


Current thread: