APNIC Home APNIC Home


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sig-policy] prop-072: Reapplication limits whentransferringaddress space



>> 2. Record the transfer with a flag which means prohibited transfer or
>>   activated in the future
>> to me, the rpki cert is the core of transfer.  you either issue it or
>> not.
> I issued as registry role. I'm not clear that the implication of taken
> option-2 is necessary of rpki cert. Would you correct me?

apologies.  i am known for being overly terse.

i am thinking longish term, when the rpki strongly influences, actually
controls, routing.  if you have a validatable chain up from the roa to
the iana root, then your packets move.  if you do not have that chain,
they don't.

any 'swing point' in the transfer [0], e.g. an rir, either certifies the
transfer, in the rpki sense, or not.  so, your 'flag' has no actual
semantic effect.  either the cert has been issued or not.

am i being any clearer?

randy

--

[0] - http://archive.psg.com/071208.transfer.pdf