Re: [address-policy-wg] 2006-05 New Policy Proposal (PI Assignment Size)
-
To: Max Tulyev president@localhost
-
From: Randy Bush randy@localhost
-
Date: Mon, 25 Sep 2006 06:57:35 -1000
> I just think (if I correct understood that, sorry but this RFC is not easy
> reading) small enhancement of this will give us the large improvement: we
> can do filtering of unauthorized announcements (announcements of right
> prefix originated with right AS but from wrong place)!
will need one more thing to verify origin, what is called a Routing
Origination Authority, which looks a lot like a cert and is stored
in the infrastructure, but which binds a cert of address ownership
to the as number which is authorized to announce it. this would be
verifiably signed by the formal owner of the address space.
randy
|