This commit is contained in:
Randy Bush 2021-03-16 22:02:11 -07:00
parent b141b93341
commit a6874503c7

View file

@ -104,7 +104,7 @@
<t>The RPKI was designed and specified to sign certificates for use <t>The RPKI was designed and specified to sign certificates for use
within the RPKI itself and to generate Route Origin Authorizations within the RPKI itself and to generate Route Origin Authorizations
(ROAs), <xref target="RFC6480"/>, for use in routing. It's design (ROAs), <xref target="RFC6480"/>, for use in routing. Its design
intentionally precluded use for attesting to real world identity as, intentionally precluded use for attesting to real world identity as,
among other issues, it would expose the Certification Authority (CA) among other issues, it would expose the Certification Authority (CA)
to liability.</t> to liability.</t>
@ -148,7 +148,7 @@
and <xref target="I-D.ietf-sidrops-rpki-rsc"/> must go to great and <xref target="I-D.ietf-sidrops-rpki-rsc"/> must go to great
lengths to extract the supposedly relevant keys from the CA.</t> lengths to extract the supposedly relevant keys from the CA.</t>
<t>For some particular INR, say Bill's Bait and Sushi's Autonompus <t>For some particular INR, say Bill's Bait and Sushi's Autonomous
System (AS) number, someone out on the net probably has the System (AS) number, someone out on the net probably has the
credentials to the CA account in which BB&amp;S's INRs are credentials to the CA account in which BB&amp;S's INRs are
registered. That could be the owner of BB&amp;S, Roberto's Taco registered. That could be the owner of BB&amp;S, Roberto's Taco