diff --git a/draft-ietf-sidrops-rpki-has-no-identity.xml b/draft-ietf-sidrops-rpki-has-no-identity.xml index 3510030..4e878a5 100644 --- a/draft-ietf-sidrops-rpki-has-no-identity.xml +++ b/draft-ietf-sidrops-rpki-has-no-identity.xml @@ -191,6 +191,11 @@ not mention any diligence the CA must, or even might, conduct to assure the INRs are in fact owned by a registrant. + That someone can provide 'proof of possession' of the private key + signing over a particular INR should not be taken to imply that they + are a valid legal representative of the organization in possession + of that INR. They could be just an INR administrative person. + Autonomous System Numbers do not identify real world entities. They are identifiers some network operators 'own' and are only used for loop detection in routing. They have no inherent semantics other