[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [DNA] Route vs Advertise



Jim -

>>A router MAY, however, advertise a
>>   combination of certified and uncertified subnet prefixes.
>>   Uncertified subnet prefixes are treated as unsecured (i.e., processed
>>   in the same way as unsecured router advertisements sent by non-SEND
>>   routers).  The processing of unsecured messages is specified in
>>   Section 8.  Note that SEND nodes that do not attempt to interoperate
>>   with non-SEND nodes MAY simply discard the unsecured information.
>>    
>>
>Note that this does not imply that the router advertisement should be
>considered insecure, just the uncertified prefix. If the advertisement has a
>signature verifiable with the router's certified public key, then the router
>is trustworthy.
>  
>
I understand.

Do you think we need to say 'the prefixes in the DNAO SHOULD NOT be
verified against the prefixes listed in the certificate' in DNAv6?

- Sathya