 
            
            
            
            
                25 Jan
                
                    2011
                
            
            
                25 Jan
                
                '11
                
            
            
            
        
    
                2:42 a.m.
            
        On Jan 24, 2011, at 9:21 PM, Richard Barnes wrote:
The more you have to invent, though, the more this sounds like a bike-shed discussion. s/DNSSEC/X.509/g s/delegating reverse "prefix" zone/signing RPKI delegation certificate/g
The difference is that we don't have an operational RPKI system, we do have an operational DNS one. It's most certainly NOT a bike shed discussion - at least with respect to how I'd configure my routers. I suspect I've sufficiently chummed the waters, I'll kick back and absorb all the reasons this is a whack idea :) -danny