[152452] in North American Network Operators' Group
Re: rpki vs. secure dns?
daemon@ATHENA.MIT.EDU (Danny McPherson)
Mon Apr 30 10:53:49 2012
From: Danny McPherson <danny@tcb.net>
In-Reply-To: <F214ED84-0E9C-4C2F-9B0F-6F5721BE1315@ripe.net>
Date: Mon, 30 Apr 2012 10:53:05 -0400
To: Alex Band <alexb@ripe.net>
Cc: "nanog@nanog.org list" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Apr 28, 2012, at 6:34 AM, Alex Band wrote:
> All in all, RPKI has really good traction and with native router =
support in Cisco, Juniper and Quagga, this is only getting better.=20
We should be more careful with statements such as this, they're =
conflating important things that add to the confusion in this area.
None of these implementations support "RPKI" today. What they support =
is a new protocol for onboarding routing policy data (some call this a =
[VRP], essentially prefix,origin bindings) into soft state in a router.
-danny
[VRP] https://ripe64.ripe.net/presentations/74-120417.sidr-origin.pdf