[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [lisp-interest] Securing the mapping response



On 7/30/08 11:33 AM, Roque Gagliano allegedly wrote:
Hi,

Today the issue was rising about how to certify the "right of use" of an EID when I get a map-response.

Today SIDR is developing what is called a ROA that matches IP prefixes to ASN with right of use. Can't we use the certificates and sing (still using CMS wrapping) instead of the ASN the RLOC or the list of RLOC. Do you believe this could be useful?

Yes we could if we need it. I'm not sure how useful it would be. ETRs are already authenticated when they join the ALT and attract Map-Requests to themselves, and they use a nonce in the Map-Reply. Is that enough?