ietf-mailsig
[Top] [All Lists]

RE: In response to Housley-mass-sec-review

2005-03-04 06:06:00


On Fri, 25 Feb 2005, Hallam-Baker, Phillip wrote:

The OCSP infrastructure being deployed already injects over half a 
million OCSP status values into ATLAS.

I'd be interested to know how well that would scale up by a 
factor of about 1000, to half a billion.

ATLAS already handles the records for 50 million DNS names, it was designed
to scale to at least 10 billion.

And there is absolutely no reason why everyone would have to use the same
server. The OCSP problem has a trivial parallel decomposition. 

Google and VeriSign prove every day that scale is not a barrier. The main
difference between the systems is the priority given to reliability. Google
have a higher volume requirement, ATLAS has a higher reliability and
robustness requirement.


<Prev in Thread] Current Thread [Next in Thread>