Re: [sidr] GOST & SIDR
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [sidr] GOST & SIDR
On Mon, 20 Apr 2009, Randy Bush wrote:
I'm asking "will RPKI partcipants who want to use algorithms
different from the norm and/or their parents be able to do so
without any bad effects"?
no
Using strange algorithms may well mean that most relying parties
can't verify the certificates, but that's to be expected.
i hope you do not think this is acceptable or useful.
Strangely enough, I do think it's useful, or at least not harmful, but
I'm interested in hearing your perspective.
Here's my perspective, informed in part by Dmitry's comments both here
and on DNS-related lists:
There may (or will) be communities that WILL NOT sign with (=issue
certificates signed by) algorithm X (=RSA). They might happily sign
with algorithm Y (=GOST). Some parts of the world (=that same
community plus some) will be able to verify Y certificates and will
gain utility from them, perhaps by authenticating route originations
from within that community. To the parts of the world that can't
verify algorithm Y certificates, hopefully it will be as though such
certs were never issued which, if you assume incremental deployment,
isn't so very bad.
So I do assume a world of partial deployment, and I assume that having
no certificates issued won't cut you off from the rest of the net.
And I assume that having only algorithm Y certificates is no worse
than having none at all.
Where do you think I've gone astray?
-- Sam
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.