From c517870618717b733c2cfac2c273f18666da62a8 Mon Sep 17 00:00:00 2001 From: Randy Bush Date: Tue, 10 Aug 2021 20:56:40 -0700 Subject: [PATCH] inr signer is not a legal rep of holding org --- draft-ietf-sidrops-rpki-has-no-identity.xml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/draft-ietf-sidrops-rpki-has-no-identity.xml b/draft-ietf-sidrops-rpki-has-no-identity.xml index 3510030..4e878a5 100644 --- a/draft-ietf-sidrops-rpki-has-no-identity.xml +++ b/draft-ietf-sidrops-rpki-has-no-identity.xml @@ -191,6 +191,11 @@ not mention any diligence the CA must, or even might, conduct to assure the INRs are in fact owned by a registrant. + That someone can provide 'proof of possession' of the private key + signing over a particular INR should not be taken to imply that they + are a valid legal representative of the organization in possession + of that INR. They could be just an INR administrative person. + Autonomous System Numbers do not identify real world entities. They are identifiers some network operators 'own' and are only used for loop detection in routing. They have no inherent semantics other