>>>>> "David" == David Farmer <farmer at umn.edu> writes:
    >> RPKI) I don't see why RPKI certificates would be issued for ULA-C space.
    >> If they were, it would be for completeness, and would specify a
    >> non-existant/reserved/invalid ASN.  This itself would provide an
    >> additional hurdle against leakage.
    >> If RPKI was legitimately issued, it would be issued, in my
    >> opinion, from a different CA. Most likely anyone that needed RPKI
    >> for their ULA-C would be running their own CA.  My opinion (as a
    >> security geek), is that running your own CA exceeds the cost of
    >> getting PI space!!

    David> I don't want to derail things with a discussion of RPKI for
    David> ULA-C, there are many different ways to deal with it I'm not
    David> sure what the right answers are. But just like I think those
    David> that want Authoritative Reverse DNS for ULA-C should be able
    David> to get it, if someone wants an RPKI certificate from ARIN for
    David> their ULA-C assignment, why not?  And it is yet another
    David> reason to have the RIR's do ULA-C assignment.  ULA-C is just
    David> more of the same of what the RIRs do now.

Why not?  Well because a full-validity, primary AA binding of ULA-C to
an ASN makes no operational sense.  

If we agree that the only routing of ULA-C is private small-i internets
(COINs), then those organizations that want to do this need to run their
own RPKI AA's. (AA = Authorization Authority)

