Search RPD Archives
Limit search to: Subject & Body Subject Author
Sort by:

[rpd] AFPUB-2019-GEN-006-DRAFT01: "RPKI ROAs for Unallocated and Unassigned AFRINIC Address Space"

Nishal Goburdhan nishal at controlfreak.co.za
Thu Jan 9 13:24:36 UTC 2020


On 9 Jan 2020, at 13:21, Anthony Ubah wrote:


> Quoting my previous comment, " I'm not abreast of staff impact

> assessment

> in the previous presentations, so please offer me some clarity"

> Do we have data on the operational implication/Impact of other RIRs

> that

> have this ion consideration, and/or that which has adopted and

> implemented

> it?


considering that this has just been adopted in the APNIC region, i doubt
that there’s operational data. however, this is not difficult to
figure out. someone has to write a series of hooks into the database
to:
# revoke previous AS0 ROA for parent prefix a/b that covers prefix P
# reissue new AS0 ROA for prefix c/d that does not include P
# confirm that rpki_state=not_found for P

and, in the upcoming myafrinic2.0 there could even be a button that you
can push, that would show you the RPKI state for P. for those that are
too lazy to look it up themselves (which you can do now quite easily
anyway).

none of this is rocket science.



> Also, I'm still curious about the effectiveness of this policy if it

> is

> implemented on RIR to RIR basis. I think it will be of no great

> impact,

> judging by the number of resources within the jurisdiction of AfriNIC.


probably. but you start with fixing something small, in your own
backyard, and going on from there ..



> I honestly think this policy is very operational and should be

> reviewed

> Only a global policy will be reasonable because a none uniform policy

> might

> create additional and unreasonable stress.


you are ignoring that there *is* already global consensus, at least in
the routing world, on what to do with AS0 ROAs. see:
https://tools.ietf.org/html/rfc6483#section-4. so, all that is
necessary is to get the RIR in question to agree to publish the AS0 ROAs
for their blocks. i really don’t understand why people keep beating
this “global policy” issue, because, honestly, that’s really not
relevant. what this *does* do, is protect unassigned afrinic prefixes
from misuse.

—n.



More information about the RPD mailing list