[Hipsec-rg] Hierarchical HITs
shengjiang at huawei.com (JiangSheng 66104) Mon, 19 January 2009 22:09 UTC
From: "shengjiang at huawei.com"
Date: Tue, 20 Jan 2009 06:09:58 +0800
Subject: [Hipsec-rg] Hierarchical HITs
In-Reply-To: <49717DCD.7050903@googlemail.com>
References: <f832f99e32cca.32ccaf832f99e@huawei.com> <alpine.LFD.2.00.0901152346540.17180@stargazer.pc.infrahip.net> <1CC9CAD8FB744ADA82C9A6F4C2AC8B03@JiangXiong> <49715DE2.9010603@laposte.net> <D8E864423971478CBA743BECAE60EB4E@JiangXiong> <49717246.2060004@laposte.net> <5727D3BB8C774649A5AC98E897EABB1C@JiangXiong> <49717DCD.7050903@googlemail.com>
Message-ID: <f972bd2c3e244.3e244f972bd2c@huawei.com>
Hi, Julien, First of all, I have no objection that DNS names may be used as host identifiers in some scenarios. Then, comparing with DNS, there are at least two major advantages HHIT has, as far as I understand and consider, one, HHIT has embedded security information and easy for verification; two, HHIT is numeric with fixed length. It is much simpler and more effective for a host to process. Cheers, Sheng ----- Original Message ----- From: Julien Laganier <julien.laganier.ietf at googlemail.com> Date: Saturday, January 17, 2009 6:42 am Subject: Re: [Hipsec-rg] Hierarchical HITs To: Sheng Jiang <shengjiang at huawei.com> Cc: hipsec-rg at listserv.cybertrust.com > Sheng, > > Sheng Jiang wrote: > >> This is exactly the point; If a HHIT has the limitation that: > >> > >> - it is bound with one entity in the hierarchy compared to a > plain HIT > >> (like a DNS name is) > >> > >> - is not human readable compared to a DNS name (like a HIT is) > >> > >> Then why should I use a HHIT as a host identifier? I'm getting > all of > >> the disadvantages of HIT (not readable) or DNS name (bound to an > entity>> in the hierarchy) but none of their respective advantages, > i.e., not > >> being bound to an entity, or being readble... > > > > I don't think bound to an entity in the hierarchy is a > disadvantage at all. > > You haven't replied to my previous question which was "My question > was,If my identifier is bound with one entity in the hierarchy, > what would > be the advantage of using HHIT as host identifiers, compared to using > DNS names as host identifiers? " > > Now if this is not a disadvantage, and if it's actually the > functionality that you're searching for, why can't you simply use > domainnames as host identifiers. They have the advantage of being > humanreadable, and I do not see any domain name drawback to HHIT... > > --julien >
- [Hipsec-rg] Hierarchical HITs Xu Xiaohu
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Henderson, Thomas R
- [Hipsec-rg] re: 答复: 答复: Key Revocation Issue Xu Xiaohu
- [Hipsec-rg] 答复: 答复: Key Revocation Issue Andrew McGregor
- [Hipsec-rg] 答复: 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Key Revocation Issue Scott Brim
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Key Revocation Issue Oleg Ponomarev
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Miika Komu
- [Hipsec-rg] Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Hierarchical HITs Zhang Dacheng
- [Hipsec-rg] 答复: Hierarchical HITs Teemu Koponen
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Hierarchical HITs Zhang Dacheng
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Hierarchical HITs Julien Laganier
- [Hipsec-rg] Hierarchical HITs Julien Laganier
- [Hipsec-rg] 答复: Hierarchical HITs Julien Laganier
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] 答复: 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] Hierarchical HITs (Was: reverse DNS l… JiangSheng 66104
- [Hipsec-rg] Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Henderson, Thomas R