[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: The state of IPv6 multihoming development
> > And you need a protocol to pass around the translation
> mappings to the
> > other end so they can undo it. When the other end is a
> foreign network,
> > why should they trust or accept the origin site?
>
> If the level of trust is zero to begin with, there should
> be no problem
> extending this "trust" so a third party.
=> Is this an argument for global PKI? Presumably
this protocol would work between arbitray sites?
>
> However, there may be some unexpected cases. For instance,
> an untrusted
> host tries to bind a trusted address to the connection and
> then inherits
> the higher level of trust. I'm sure we can work all of this out when
> there is something concrete on the table.
=> I don't think this will be a trivial task.
Especially when you're aggregating the updates
to handle large prefixes (instead of updating
each address at a time).
Hesham
>
>