[Hipsec-rg] Re: Native HIP API questions in the hipsec-rg meeting

shep@alum.mit.edu (Tim Shepard) Mon, 16 August 2004 19:11 UTC

From: shep@alum.mit.edu (Tim Shepard)
Date: Mon Aug 16 19:11:00 2004
Subject: [Hipsec-rg] Re: Native HIP API questions in the hipsec-rg meeting
In-Reply-To: Your message of Mon, 16 Aug 2004 13:36:35 -0700. <41211AD3.6080306@netlab.nec.de>
Message-ID: <E1BwrbV-0007LC-00@alva.home>

> >>Tim Shepard:  What if no DNS?  Nervous about building in dependencies on
> >>DNS.
> >>
> >>Julien:  use /etc/hosts.  Can fall back to opportunistic mode too.
> > 
> > The other alternative for DNS is the DHT, but it remains to be seen if we
> > ever get there. In the mean time, we should rely on DNS, as there are no
> > real alternatives currently available.
> > 
> > Maybe the resolver should should support DHT queries too. With a new
> > resolver, this should not be a problem. I'll have to look at this topic
> > when I get my hands on a DHT DNS replacement implementation...
> 
>
> See Tim's email. I agree with him that finding a way to use HIP without 
> a deployed DNS would be very useful. How do you bootstrap communication 
> if someone hands you just a HIT?

You don't.   When I hear that question (and I've heard it many times)
it sounds to me like a question equivalent to:

   How do you bootstrap an ssh connection if someone hands you (only)
   the ssh host key of a machine?

Another equivalent question might be:

   How am I supposed to be able to begin a postal correspondence with
   Alyssa P. Hacker  when the only think you've told me is her name?

A referral requires a name *and* an address.  I don't see anyway
around that.  Directories can be useful, but no directory will ever
have everything or everyone in it.

			-Tim Shepard
			 shep@alum.mit.edu