[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [DNA] Route vs Advertise
Jim -
>>A router MAY, however, advertise a
>> combination of certified and uncertified subnet prefixes.
>> Uncertified subnet prefixes are treated as unsecured (i.e., processed
>> in the same way as unsecured router advertisements sent by non-SEND
>> routers). The processing of unsecured messages is specified in
>> Section 8. Note that SEND nodes that do not attempt to interoperate
>> with non-SEND nodes MAY simply discard the unsecured information.
>>
>>
>Note that this does not imply that the router advertisement should be
>considered insecure, just the uncertified prefix. If the advertisement has a
>signature verifiable with the router's certified public key, then the router
>is trustworthy.
>
>
I understand.
Do you think we need to say 'the prefixes in the DNAO SHOULD NOT be
verified against the prefixes listed in the certificate' in DNAv6?
- Sathya