Re: [sidr] GOST & SIDR
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sidr] GOST & SIDR



On Mon, 20 Apr 2009, Randy Bush wrote:

I'm asking "will RPKI partcipants who want to use algorithms different from the norm and/or their parents be able to do so without any bad effects"?

no

Using strange algorithms may well mean that most relying parties can't verify the certificates, but that's to be expected.

i hope you do not think this is acceptable or useful.

Strangely enough, I do think it's useful, or at least not harmful, but I'm interested in hearing your perspective.

Here's my perspective, informed in part by Dmitry's comments both here and on DNS-related lists:

There may (or will) be communities that WILL NOT sign with (=issue certificates signed by) algorithm X (=RSA). They might happily sign with algorithm Y (=GOST). Some parts of the world (=that same community plus some) will be able to verify Y certificates and will gain utility from them, perhaps by authenticating route originations from within that community. To the parts of the world that can't verify algorithm Y certificates, hopefully it will be as though such certs were never issued which, if you assume incremental deployment, isn't so very bad.

So I do assume a world of partial deployment, and I assume that having no certificates issued won't cut you off from the rest of the net. And I assume that having only algorithm Y certificates is no worse than having none at all.

Where do you think I've gone astray?

-- Sam

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.