> But the subsequent conversation reads to me like "onboard .. signing
> certificates"

i can not find 'onboard' used as a verb in any rfc.  so anything is a
guess.

> means getting the private keys routers would use for signing into the
> routers.

try draft-ymbk-bgpsec-rtr-rekeying-00.txt, which i thought was asked to
be adopted by the wg.  probably my screw-up.

> Communicating the router's private keys in the RPKI would be a bad
> idea.

only if you don't think a public bath is private :)

> I do not know that anyone plans to use the rpki-rtr protocol to get
> private keys to the router.

this is the ietf.  i am fairly sure someone does.  i just think they
would be extremely ill-advised to do so.

randy
_______________________________________________
sidr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to