[Hipsec-rg] reverse DNS lookups of HITs

shep at alum.mit.edu (Tim Shepard) Mon, 12 January 2009 22:09 UTC

From: "shep at alum.mit.edu"
Date: Mon, 12 Jan 2009 17:09:09 -0500
Subject: [Hipsec-rg] reverse DNS lookups of HITs
In-Reply-To: Your message of Mon, 12 Jan 2009 23:41:38 +0200. <alpine.LFD.2.00.0901122313150.17180@stargazer.pc.infrahip.net>
Message-ID: <E1LMUy5-00069S-00@alva.home>

> > Or, if that turns out to be a bad idea, what are the practical 
> > alternatives that allow someone to write domain-name-based ACLs?
> >
> > I think it would be great to gather more input on these types of
> > deployment questions.
> 
> Actually I wonder how could I use HITs without reverse domains, I don't 
> want to keep random hex sequences in the memory, but it is probably just 
> my feeling.


I view HITs as very similar to SSH host keys.    And just like we have
no need for a network-wide way of looking up an ssh host key to find
out what host it corresponds to, perhaps we can do without any
network-wide way of looking up a HIT (or HI).

I think we (myself included) should all go read the FARA paper again:

  FARA: Reorganizing the Addressing Architecture
 ( the first of 3 papers at http://www.isi.edu/newarch/fara.html )


			-Tim Shepard
			 shep at alum.mit.edu