Re: [sidr] sidr-arch-09 refresh cycle time
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sidr] sidr-arch-09 refresh cycle time



Randy Bush wrote:
That is only true if the thing you're propagating has to travel hop by
hop to the bottom of the hierarchy. So the question still stands: what
is this "thing" that you think propagates slowly, and why does it have
to propagate hop by hop?

incorrect or missing cert high in chain which needs delegation fix down
the chain so end site can get a fixed roa out there.  remember, my
routing depends on that roa.  and arin has extreme cases of depth,
though i think we will find itu-rir-<three or four> to be the more
common cases.

it's max time to repair which worries me.

randy

I understand this concern, but how likely is it that there is an "incorrect or missing cert high in chain" which needs fixing within one cycle?

In the case of missing resources, it's very unlikely that someone deep down in the chain suddenly realises "oh, I need more resource from my grand-grand-grandparent NOW!". In the case of overclaiming, it's enough if any one in the chain shrinks their resources, the effect is visible in one cycle.

So I'm not convinced that multi-cycle propagation this is an issue.

Robert


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.