3 ms·
How would that work? You could sign that you trust your next-to-last hops to deliver traffic to you but transitive delivery isn't guaranteed and not every chai
by bcoates 12y ago
How would that work?
You could sign that you trust your next-to-last hops to deliver traffic to you but transitive delivery isn't guaranteed and not every chain of valid hops is actually workable as a route capacity-wise. A completely signature-valid route with near 100% packet loss isn't much better than an undeliverable leak.
- nknighthb 12y agoThe entirety of all possible AS paths don't need to be signed to make a difference. Even just signing the last 1-2 ASs would stop most of the big screwups.
- noselasd 12y agoThere's an architecture for doing orignation validation in BGP, lot's of info if you want to listen to http://packetpushers.net/show-105-bgp-origin-validation-with-resource-public-key-infrastructure-rpki/ http://packetpushers.net/show-105-bgp-origin-validation-with... However, it pretty much requires everyone to do it.