nanog mailing list archives

Re: where was my white knight....


From: Christopher Morrow <morrowc.lists () gmail com>
Date: Tue, 8 Nov 2011 16:25:54 -0500

On Tue, Nov 8, 2011 at 1:48 PM, Nick Hilliard <nick () foobar org> wrote:
On 08/11/2011 18:14, bmanning () vacation karoshi com wrote:
 the answer seems to be NO, it would not have helped and would have actually
contributed to network instability with large numbers of validation requests
sent to the sidr/ca nodes...

i'm curious about sidr cold bootup, specifically when you are attempting to
validate prefixes from an rpki CA or cache to which you do not necessarily
have network connectivity because your igp is not yet fully up.  The
phrases "layering violation" and "chicken and egg" come to mind.

'lazy validation' - prefer to get at least somewhat converged, then validate.




Current thread: