tim bray wanted 6480 pushed harder

This commit is contained in:
Randy Bush 2022-03-10 12:45:11 -08:00
parent 11a782f66b
commit 74d2ca709b

View file

@ -130,11 +130,15 @@
services. They claim to be authoritative, at least for the INRs services. They claim to be authoritative, at least for the INRs
which they allocate.</t> which they allocate.</t>
<t>RPKI-based credentials of INRs MUST NOT be used to authenticate <t>PKI operations MUST NOT be performed with RPKI certificates other
real-world documents or transactions without some formal external than exactly as described, and for the purposes described, in <xref
authentication of the INR and the authority for the actually target="RFC6480"/>.</t>
anonymous INR holder to authenticate the particular document or
transaction.</t> <t>I.e., RPKI-based credentials of INRs MUST NOT be used to
authenticate real-world documents or transactions without some
formal external authentication of the INR and the authority for the
actually anonymous INR holder to authenticate the particular
document or transaction.</t>
<t>Given sufficient external, i.e. non-RPKI, verification of <t>Given sufficient external, i.e. non-RPKI, verification of
authority, the use of RPKI-based credentials seems superfluous.</t> authority, the use of RPKI-based credentials seems superfluous.</t>
@ -231,13 +235,13 @@
<t>Control of INRs for an entity could be used to falsely authorize <t>Control of INRs for an entity could be used to falsely authorize
transactions or documents for which the INR manager has no transactions or documents for which the INR manager has no
authority.</t> authority.</t>
<!--
<t>RPKI-based credentials of INRs MUST NOT be used to authenticate <t>RPKI-based credentials of INRs MUST NOT be used to authenticate
real-world documents or transactions without some formal external real-world documents or transactions without some formal external
authentication of the INR and the authority for the actually authentication of the INR and the authority for the actually
anonymous INR holder to authenticate the particular document or anonymous INR holder to authenticate the particular document or
transaction.</t> transaction.</t>
-->
</section> </section>
<section anchor="iana" title="IANA Considerations"> <section anchor="iana" title="IANA Considerations">