Latest News for: rpki

Edit

Exploring an idea: Can spreading out repositories speed up RPKI? (APNIC Pty Ltd)

Public Technologies 15 Oct 2021
The current RPKI repository system is spread across RIRs, NIRs and LIRs ... Fetching data in RPKI ... Resource Public Key Infrastructure (RPKI) is a mechanism to access and verify resource certificates issued by the registries ... RPKI interacts with every part of the chain, from the top to the bottom ... RPKI and trust anchors.
Edit

What’s your wish list for the perfect RPKI validator? (APNIC Pty Ltd)

Public Technologies 05 Aug 2021
It wasn't long ago that the sun set on RIPE's RPKI validator ... The role of a relying party (RP) in the RPKI framework is to play the 'verify' part in 'trust but verify' so I am very strongly driven to a validator that can demonstrate it conforms to the standards ... I run Routinator, RPKI-client and Dragon every day, from my own laptop.
Edit

Solo effort to clean up RPKI invalids across a region (APNIC Pty Ltd)

Public Technologies 26 Jul 2021
With the growing adoption of Resource Public Key Infrastructure (RPKI) Route Origin validation (ROV) to make the Internet more secure and resilient, it is becoming increasingly important for IP network operators or IP prefix holders to ensure their Border Gateway Protocol (BGP) advertisements are not seen as RPKI invalid on the Internet.
Edit

RPKI invalids are not going away (APNIC Pty Ltd)

Public Technologies 16 Jul 2021
Over the last couple of years, there has been great progress in terms of RPKI ROA adoption by network operators across the world ... What makes a route RPKI invalid? ... There could be three RPKI invalid route types ... Not dropping RPKI invalids ... Many networks, including some large ISPs, have already adopted RPKI ROV and drop RPKI invalids.
Edit

Does training impact RPKI usage? (APNIC Pty Ltd)

Public Technologies 14 Jul 2021
Participants in APNIC's 2020 RPKI Deployathon. APNIC conducts a lot of Resource Public Key Infrastructure (RPKI) training ... In this post, we'll examine the data to see how training affects RPKI usage ... Over 10 years of RPKI. It is over a decade since the concept of RPKI was proposed ... rpki-lknog 4/10/2019 APNIC 26,267 4,227 178,697 26,862 4,084 182,156.
Edit

RPKI rollout at Hurricane Electric (Boundary Commission for Northern Ireland)

Public Technologies 13 Jul 2021
24 February 2021 marked one year since Hurricane Electric began deploying Resource Public Key Infrastructure Route Origin Validation (RPKI ROV). Since then, significant progress has been made globally in the adoption of RPKI ROV ... Before then, some very large ISPs were validating their peers for RPKI ROV, and filtering for invalids.
Edit

RPKI rollout at Hurricane Electric (APNIC Pty Ltd)

Public Technologies 12 Jul 2021
24 February 2021 marked one year since Hurricane Electric began deploying Resource Public Key Infrastructure Route Origin Validation (RPKI ROV). Since then, significant progress has been made globally in the adoption of RPKI ROV ... Before then, some very large ISPs were validating their peers for RPKI ROV, and filtering for invalids.
Edit

How RRDP was implemented for OpenBSD rpki-client (APNIC Pty Ltd)

Public Technologies 18 May 2021
This blog post discusses the technical challenges encountered when implementing RPKI Repository Delta Protocol (RRDP) in the free, functional, and secure RPKI validator software rpki-client, and how those challenges were addressed. OpenBSD invites RPKI operators to celebrate the release of rpki-client 7.0 and help with testing.
Edit

NIST RPKI Deployment Monitor (APNIC Pty Ltd)

Public Technologies 14 May 2021
The monitor attempts to quantitatively characterize the state of deployment of the emerging RPKI in terms of its completeness, correctness, and robustness ... The monitor also produces summary reports when it detects anomalies in the RPKI-ROV system (for example, unusually large number of RPKI or RPKI-ROV state changes, and so forth).
Edit

Vocus RPKI implementation (APNIC Pty Ltd)

Public Technologies 13 May 2021
Over the course of the year, we at Vocus were rolling out RPKI across our network ... RIPE's RPKI Validator is being phased out, so what are the other options?. After testing a number of options and having discussions with other carriers, we decided to use rpki-client with Cloudflare's GoRTR in front ... Krill - a new RPKI Certificate Authority.
Edit

Cleaning up your RPKI invalid routes (APNIC Pty Ltd)

Public Technologies 28 Apr 2021
As more networks start to implement RPKI Route Origin Validation (ROV), it's good practice to regularly check your Route Origin Authorizations (ROAs), to ensure they are consistent with your Border Gateway Protocol (BGP) announcements ... On 27 April 2021, we saw 3526 RPKI invalid routes for IPv4 addresses delegated to APNIC Members..
Edit

Some security issues with RPKI and how to fix them (APNIC Pty Ltd)

Public Technologies 27 Apr 2021
Resource Public Key Infrastructure (RPKI), as defined in RFC 6810, was proposed to authenticate the relationship between a prefix and its origination ... For example, RPKI validators might not reach a publication point server, there is an infrequent fetch of RPKI data, and some RPKI validators do not follow the technical specifications.
Edit

Common pitfalls in RPKI deployment and how to avoid them (APNIC Pty Ltd)

Public Technologies 08 Apr 2021
While widespread adoption of Resource Public Key Infrastructure (RPKI) - one of the standard ways to improve BGP security - can help, not enough network operators know about it ... Figure 1 shows the main components of the RPKI system from the perspective of a network service provider managing its Route Origin Authorization (ROA) entries from APNIC.
Edit

RPKI services now available to APNIC historical resource holders (APNIC Pty Ltd)

Public Technologies 26 Mar 2021
APNIC Historical Maintenance Non-Member accounts now have full access to RPKI services, following Executive Council (EC) decisions announced during APNIC 51 ... Improving routing security is critical to the health and stability of the Internet globally and APNIC is committed to supporting RPKI adoption in the region.
Edit

RPKI relying party synchronization behaviour (APNIC Pty Ltd)

Public Technologies 22 Mar 2021
On Measuring RPKI Relying Parties. The Resource Public Key Infrastructure (RPKI) is a specialized PKI designed and deployed to improve the security of the Internet BGP routing system. Some of the 'resources' that make up the RPKI include IP address prefixes and Autonomous System numbers (ASNs) ... RPKI objects are stored and made available as files.
×