nanog mailing list archives

Re: RPKI TAs


From: Randy Bush <randy () psg com>
Date: Mon, 03 Aug 2020 09:28:26 -0700

  why is it so hard that all RIRs make their TAL files available under 
the same URL path but different hosts, e.g., https://ripe.net/rpki/tal, 
https://arin.net/rpki/tal ?

no, you are supposed to get TRUST material from alex's secret stash.
sigh.

it should be a dnssec lookup of ripe.net, tls secured lookup, find a TAL
as defind in the RFCs, and fetch it via tls.

randy


Current thread: