[16054] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: AS8584 taking over the internet

daemon@ATHENA.MIT.EDU (Scott Huddle)
Thu Apr 9 19:30:44 1998

Date: Thu, 9 Apr 1998 19:25:26 -0400
From: Scott Huddle <huddle@mci.net>
To: huddle@mci.net, randy@psg.com
Cc: nanog@merit.org

I have and remain unconvinced and or confused ;)  The proposal allows
an operator to verify a valid origin AS for a given prefix (i.e. "config"
sorry if I'm being loose with the word) by using the DNS system with
"bgp.in-addr" extensions.  I'm not sure which part of the random 
route announcement problem that dnssec solves in this case?  It can
help with the "are they indeed are who they say they are", but it 
doesn't solve the "are they supposed to be doing what they said that 
they're doing" case.

And you didn't address my paranoia about not trusting the DNS ;)

-scott

> you may wish to read the draft.  it did not suggest using the dns to
> configure.  and you may also want to look into dnssec.
> 
> randy
> 

home help back first fref pref prev next nref lref last post