the certificates are carried ... in soBGP in a new BGP message.
btw, am i supposed to be cheered by yet another overloading of bgp?
Since S-BGP overloads signatures into the current packet formats, destroys
packing, and destroys peer groups, I'm not certain that you can make the
claim that S-BGP has a "lower impact" on BGP than soBGP does. In fact, to
the contrary, you might have noticed that the transport draft is set up all
on its own, specifically so any other transport could be substituted.
If someone wants to deploy some other transport, and there's community
interest in doing so, then soBGP could be done without touching BGP at all.
:-)
Russ
__________________________________
[EMAIL PROTECTED] CCIE <>< Grace Alone