nanog mailing list archives
Re: rpki vs. secure dns?
From: Florian Weimer <fw () deneb enyo de>
Date: Sat, 28 Apr 2012 17:16:55 +0200
* Alex Band:
At RIPE 63, six months ago, the RIPE NCC membership got a chance to vote on RPKI at the general meeting. The result was that the RIPE NCC has the green light to continue offering the Resource Certification service, including all BGP Origin Validation related functionality.
But this was done outside the Policy Development Process, which is supposed to handle such things.
It's correct that concerns were raised in the area of security, resilience and operator autonomy, as you mention. These concerns are continuously being evaluated and addressed.
I don't think so. Ultimately, it does not seem to be possible to get this through the PDP. The whole discussion is a bit odd: Even without RPKI, RIPE NCC already has the power to directly influence global routing because it's unreasonable to expect that the majority of their BGP peers employ strict filtering. So they could inject more specifics as they see fit, and thus blackhole pretty arbitrary chunks of address space. However, so can most folks who of those who control routers in the DFZ, and RPKI (or something similar) would change that at least.
Current thread:
- Re: rpki vs. secure dns?, (continued)
- Re: rpki vs. secure dns? Russ White (Apr 30)
- Re: rpki vs. secure dns? Randy Bush (Apr 30)
- Re: rpki vs. secure dns? Matt Ryanczak (Apr 27)
- Re: rpki vs. secure dns? Randy Bush (Apr 28)
- Re: rpki vs. secure dns? Matthias Waehlisch (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Randy Bush (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Nick Hilliard (Apr 28)
- Re: rpki vs. secure dns? Phil Regnauld (Apr 28)
- Re: rpki vs. secure dns? Nick Hilliard (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Rubens Kuhl (Apr 28)
- Re: rpki vs. secure dns? Phil Regnauld (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 29)
- Re: rpki vs. secure dns? Jennifer Rexford (Apr 29)
- Message not available
- Re: rpki vs. secure dns? Stephane Bortzmeyer (Apr 29)
- Re: rpki vs. secure dns? Matthias Waehlisch (Apr 29)