On Oct 4, 2012, at 11:19 AM, Tony Finch <d...@dotat.at> wrote:

> Owen DeLong <o...@delong.com> wrote:
>> 
>> Once host identifiers are no longer dependent on or related to topology,
>> there's no reason a reasonable fixed-length cannot suffice.
> 
> Host identities should be cryptographic hashes of public keys, so you have
> to support algorithm agility, which probably implies variable length.
> 

No, they really shouldn't, but I understand why some security zealots think 
that's a good idea.

Owen


Reply via email to