tim bray wanted 6480 pushed harder

This commit is contained in:
Randy Bush 2022-03-10 12:45:11 -08:00
parent 11a782f66b
commit 74d2ca709b

View file

@ -130,11 +130,15 @@
services. They claim to be authoritative, at least for the INRs
which they allocate.</t>
<t>RPKI-based credentials of INRs MUST NOT be used to authenticate
real-world documents or transactions without some formal external
authentication of the INR and the authority for the actually
anonymous INR holder to authenticate the particular document or
transaction.</t>
<t>PKI operations MUST NOT be performed with RPKI certificates other
than exactly as described, and for the purposes described, in <xref
target="RFC6480"/>.</t>
<t>I.e., RPKI-based credentials of INRs MUST NOT be used to
authenticate real-world documents or transactions without some
formal external authentication of the INR and the authority for the
actually anonymous INR holder to authenticate the particular
document or transaction.</t>
<t>Given sufficient external, i.e. non-RPKI, verification of
authority, the use of RPKI-based credentials seems superfluous.</t>
@ -231,13 +235,13 @@
<t>Control of INRs for an entity could be used to falsely authorize
transactions or documents for which the INR manager has no
authority.</t>
<!--
<t>RPKI-based credentials of INRs MUST NOT be used to authenticate
real-world documents or transactions without some formal external
authentication of the INR and the authority for the actually
anonymous INR holder to authenticate the particular document or
transaction.</t>
-->
</section>
<section anchor="iana" title="IANA Considerations">