Tuesday, May 25, 2010

Re: [Geopriv] Security considerations for LIS discovery

On 25/05/2010 15:16, "Brian Rosen" <br@brianrosen.net> wrote:

> Sorry, I don't get this.
>
> I certainly understand the customer-of-the-isp issue.
>
> However, at least in my experience, such customers don't want any reference
> to their upstream providers in any service. That means if the customer's
> domain is customer.net, they want the lis to be lis.customer.net, and
> isp.net has to answer to that name. If they didn't care, then the DHCP
> entry would be allowed to point directly to the ISP (and only one DHCP entry
> would need to be changed if the ISP changed)
>
> That is usually pretty straightforward, and ISPs do that. The LIS would
> have multiple credentials and use the appropriate one.

If the protocol is https (which AIUI is expected) then having the ISP LIS
answer as "lis.customer.net" is impractical - it just doesn't scale (see
Martin's message).

Ray


_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv