[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [lisp-interest] Securing the mapping response
On 7/30/08 11:33 AM, Roque Gagliano allegedly wrote:
Hi,
Today the issue was rising about how to certify the "right of use" of an
EID when I get a map-response.
Today SIDR is developing what is called a ROA that matches IP prefixes
to ASN with right of use. Can't we use the certificates and sing (still
using CMS wrapping) instead of the ASN the RLOC or the list of RLOC. Do
you believe this could be useful?
Yes we could if we need it. I'm not sure how useful it would be. ETRs
are already authenticated when they join the ALT and attract
Map-Requests to themselves, and they use a nonce in the Map-Reply. Is
that enough?