design draft issue: section 5.5 nits
Jari Arkko <[email protected]> Wed, 21 Dec 2005 12:53:15 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
> If the addresses are part of the certificate then it is > not necessary to execute the weaker return routability check. The > return routability check is a form of authorization check, although > it provides weaker guarantees than the inclusion of the IP address as > a part of a certificate. If multiple addresses are communicated to > the remote peer then some of these addresses may be already verified > even if the primary address is still operational. s/the weaker/the/ (the strength is explained in next sentence) Also, it seems like there is some text missing here that we had in the protocol draft about the need to have some authority involved in the certs... surely the pure inclusion of data in a self-signed certificate, for instance, does not make the data reliable. I do not understand the last sentence. I guess you are trying to say that verification can take place in parallel with ongoing use of another, current address pair? > Another option is to use the [I-D.dupont-mipv6-3bombing] approach > which suggests to perform a return routability check only when an > address update needs to be sent from some address other than the > indicated preferred address. I would delete this paragraph. There are a zillion variations of the return routability procedure, and there is no need to point to one of the variants here, particularly if that variant has not been in use in other contexts. --Jari