<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">Le 16/07/2026 à 23:09, Hytham El-Nakhal
a écrit :<br>
</div>
<blockquote type="cite" cite="mid:1784239787450.20999@tra.gov.eg">
<pre wrap="" class="moz-quote-pre">Dear PDWG,
The Policy Development Working Group (PDWG) Chairs have initiated a Last Call for this proposal, following rough consensus at the AFRINIC-37 Public Policy Meeting held in hybrid format in Nairobi, Kenya on 24 June 2026.
* Proposal Name: Hierarchical Names for New AS-SETs
* Proposal ID: AFPUB-2026-ASN-001-DRAFT02
* Proposal URL: <a class="moz-txt-link-freetext"
href="https://www.afrinic.net/afpub-2026-asn-001-draft02.html">https://www.afrinic.net/afpub-2026-asn-001-draft02.html</a>
Last Call closes on: July 31, 2026, at 23:59 UTC.
</pre>
</blockquote>
<br>
Dear PDWG Co-chairs,<br>
<br>
Many thanks for your much appreciated work!<br>
<br>
<tl;dr><br>
This long email contains four things:<br>
* the reason why i support this DPP;<br>
* A presentation from Tashi Phuntsho, during <br>
iWeek2026 regarding: <br>
<a
href="https://iweek.org.za/sessions/securing-internet-routing-puzzle-pieces">Securing
Internet Routing - The Puzzle Pieces | iWeek</a><br>
<a href="https://www.youtube.com/watch?v=6LJU2IWNAHw">Why Internet
Routing Is Broken — And How We're Fixing It | BGP Security
Explained - YouTube</a> <br>
<br>
* Actual AS-SET syntax;<br>
* Actual AS-SET detailed syntax <br>
{as that is where the proposed (by this DPP) <br>
change of behavior would firstly appear...}<br>
</tl;dr><br>
<br>
...i would like to thanks the author of this DPP; <br>
as he wisely ended the References section with <br>
the following words:<br>
<br>
"AFRINIC is the only major RIR which has not currently implemented
this feature, or is not currently working towards implementing it.
If/when AFRINIC implements it, AS-SET squatting in the 5 major RIRs
will no longer be possible and AS-SETs will be have become more
secure globally."<br>
<br>
...which is the exact reason why i want this DPP <br>
to be (i) adopted; (ii) ratified; and (iii) implemented <br>
the soonest.<br>
<br>
<blockquote type="cite" cite="mid:1784239787450.20999@tra.gov.eg">
<pre wrap="" class="moz-quote-pre">Please note the staff observation regarding implementation constraints: due to the current prioritization of the MyAFRINIC v2 deployment, physical database implementation of this policy will be scheduled once the MyAFRINIC v2 deployment is concluded.
</pre>
</blockquote>
<br>
...this is ok to me! i have also noted the following <br>
from the Staff IAr (Impact Assessment report) <br>
of this DPP (AFPUB-2026-ASN-001-DRAFT02): <br>
<br>
"<strong>6. Staff Observations</strong>
<p>We note the exception highlighted in 7.8.6 that could allow
restoration of deleted objects. However, we feel that such recalls
may introduce operational loopholes, and it may also reduce the
effective objective for the policy in general. In the instance
that an unintended deletion happens, the affected members may take
the opportunity to create aligned AS-SETs."</p>
<br>
<blockquote type="cite" cite="mid:1784239787450.20999@tra.gov.eg">
<pre wrap="" class="moz-quote-pre">As always, we kindly request that all participants adhere to the AFRINIC Code of Conduct<a
class="moz-txt-link-rfc2396E" href="https://www.afrinic.net/code"><https://www.afrinic.net/code></a> to maintain a respectful and professional environment on the mailing list.
</pre>
</blockquote>
<br>
Thanks for recalling it; as the risk is always there!<br>
<br>
By the way, having noted that there seems to <br>
be some recurring misbeliefs regarding what <br>
an AS-SET class of IRR/Whois objects is; please <br>
allow me to share three things, which could be <br>
helpful to see where the proposed change is <br>
intended to start to be seen:<br>
<br>
(i) A presentation from Tashi Phuntsho, during <br>
iWeek2026 regarding: <br>
<a
href="https://iweek.org.za/sessions/securing-internet-routing-puzzle-pieces">Securing
Internet Routing - The Puzzle Pieces | iWeek</a><br>
<a href="https://www.youtube.com/watch?v=6LJU2IWNAHw">Why Internet
Routing Is Broken — And How We're Fixing It | BGP Security
Explained - YouTube</a><br>
<br>
(ii) Actual AS-SET syntax;<br>
<br>
<i>cacty@<a class="moz-txt-link-freetext" href="shalom:~$">shalom:~$</a> TZ='UTC' date --rfc-3339='seconds' &&
whois -h whois.afrinic.net -t AS-SET # from AS15964 at Bhome<br>
2026-07-19 14:43:17+00:00<br>
% This is the AfriNIC Whois server.<br>
% The AFRINIC whois database is subject to the following terms of
Use. See <a class="moz-txt-link-freetext" href="https://afrinic.net/whois/terms">https://afrinic.net/whois/terms</a><br>
<br>
as-set: [mandatory] [single] [primary/lookup key]<br>
descr: [mandatory] [multiple] [ ]<br>
members: [optional] [multiple] [ ]<br>
mbrs-by-ref: [optional] [multiple] [inverse key]<br>
remarks: [optional] [multiple] [ ]<br>
org: [optional] [multiple] [inverse key]<br>
tech-c: [mandatory] [multiple] [inverse key]<br>
admin-c: [mandatory] [multiple] [inverse key]<br>
notify: [optional] [multiple] [inverse key]<br>
mnt-by: [mandatory] [multiple] [inverse key]<br>
mnt-lower: [optional] [multiple] [inverse key]<br>
changed: [mandatory] [multiple] [ ]<br>
source: [mandatory] [single] [ ]<font size="2"><br>
<br>
cacty@<a class="moz-txt-link-freetext" href="shalom:~$">shalom:~$</a> </font></i><br>
<img src="cid:part1.BdjO66AV.LegVzfhR@cmnog.cm" alt="" width="539"
height="403"><br>
<br>
(iii) Actual AS-SET detailed syntax;<br>
<br>
<i>cacty@<a class="moz-txt-link-freetext" href="shalom:~$">shalom:~$</a> TZ='UTC' date --rfc-3339='seconds' &&
whois -h whois.afrinic.net -v AS-SET # from AS15964 at Bhome<br>
2026-07-19 14:53:36+00:00<br>
% This is the AfriNIC Whois server.<br>
% The AFRINIC whois database is subject to the following terms of
Use. See <a class="moz-txt-link-freetext" href="https://afrinic.net/whois/terms">https://afrinic.net/whois/terms</a><br>
<br>
The as-set class:<br>
<br>
An as-set object defines a set of aut-num objects. The<br>
attributes of the as-set class are shown in Figure 1.2.2.
The<br>
"as-set:" attribute defines the name of the set. It is an
RPSL<br>
name that starts with "as-". The "members:" attribute lists
the<br>
members of the set. The "members:" attribute is a list of
AS<br>
numbers, or other as-set names.<br>
<br>
as-set: [mandatory] [single] [primary/lookup key]<br>
descr: [mandatory] [multiple] [ ]<br>
members: [optional] [multiple] [ ]<br>
mbrs-by-ref: [optional] [multiple] [inverse key]<br>
remarks: [optional] [multiple] [ ]<br>
org: [optional] [multiple] [inverse key]<br>
tech-c: [mandatory] [multiple] [inverse key]<br>
admin-c: [mandatory] [multiple] [inverse key]<br>
notify: [optional] [multiple] [inverse key]<br>
mnt-by: [mandatory] [multiple] [inverse key]<br>
mnt-lower: [optional] [multiple] [inverse key]<br>
changed: [mandatory] [multiple] [ ]<br>
source: [mandatory] [single] [ ]<br>
<br>
The content of the attributes of the as-set class are defined
below:<br>
<br>
as-set<br>
<br>
Defines the name of the set.<br>
<br>
An as-set name is made up of letters, digits, the<br>
character underscore "_", and the character hyphen "-"; it<br>
must start with "as-", and the last character of a name must<br>
be a letter or a digit.<br>
<br>
An as-set name can also be hierarchical. A hierarchical set<br>
name is a sequence of set names and AS numbers separated by<br>
colons ":". At least one component of such a name must be<br>
an actual set name (i.e. start with "as-"). All the set<br>
name components of a hierarchical as-name have to be as-set<br>
names.<br>
<br>
descr<br>
<br>
A short decription related to the object.<br>
<br>
A sequence of ASCII characters.<br>
<br>
members<br>
<br>
Lists the members of the set.<br>
<br>
<as-number> or<br>
<as-set-name><br>
<br>
mbrs-by-ref<br>
<br>
This attribute can be used in all "set" objects; it allows
indirect<br>
population of a set. If this attribute is used, the set also
includes<br>
objects of the corresponding type (aut-num objects for as-set,
for<br>
example) that are protected by one of these maintainers and
whose<br>
"member-of:" attributes refer to the name of the set. If the
value of<br>
a "mbrs-by-ref:" attribute is ANY, any object of the
corresponding<br>
type referring to the set is a member of the set. If the<br>
"mbrs-by-ref:" attribute is missing, the set is defined
explicitly by<br>
the "members:" attribute.<br>
<br>
<mntner-name> | ANY<br>
<br>
remarks<br>
<br>
Contains remarks.<br>
<br>
A sequence of ASCII characters.<br>
<br>
org<br>
<br>
Points to an existing organisation object representing the
entity that<br>
holds the resource.<br>
<br>
The 'ORG-' string followed by 2 to 4 characters, followed by
up to 5 digits<br>
followed by a source specification. The first digit must not
be "0".<br>
Source specification starts with "-" followed by source name
up to<br>
9-character length.<br>
<br>
tech-c<br>
<br>
References a technical contact.<br>
<br>
From 2 to 4 characters optionally followed by up to 5 digits<br>
optionally followed by a source specification. The first
digit<br>
must not be "0". Source specification starts with "-"
followed<br>
by source name up to 9-character length.<br>
<br>
admin-c<br>
<br>
References an on-site administrative contact.<br>
<br>
From 2 to 4 characters optionally followed by up to 5 digits<br>
optionally followed by a source specification. The first
digit<br>
must not be "0". Source specification starts with "-"
followed<br>
by source name up to 9-character length.<br>
<br>
notify<br>
<br>
Specifies the e-mail address to which notifications of changes
to an<br>
object should be sent.<br>
This attribute is filtered from the default whois output.<br>
<br>
An e-mail address as defined in RFC 2822.<br>
<br>
mnt-by<br>
<br>
Specifies the identifier of a registered mntner object used for<br>
authorisation of operations performed with the object that
contains<br>
this attribute.<br>
<br>
Made up of letters, digits, the character underscore "_",<br>
and the character hyphen "-"; the first character of a name<br>
must be a letter, and the last character of a name must be a<br>
letter or a digit. The following words are reserved by<br>
RPSL, and they can not be used as names:<br>
<br>
any as-any rs-any peeras and or not atomic from to at<br>
action accept announce except refine networks into inbound<br>
outbound<br>
<br>
Names starting with certain prefixes are reserved for<br>
certain object types. Names starting with "as-" are<br>
reserved for as set names. Names starting with "rs-" are<br>
reserved for route set names. Names starting with "rtrs-"<br>
are reserved for router set names. Names starting with<br>
"fltr-" are reserved for filter set names. Names starting<br>
with "prng-" are reserved for peering set names. Names<br>
starting with "irt-" are reserved for irt names.<br>
<br>
mnt-lower<br>
<br>
Specifies the identifier of a registered mntner object used for<br>
hierarchical authorisation. Protects creation of objects
directly (one<br>
level) below in the hierarchy of an object type. The
authentication<br>
method of this maintainer object will then be used upon
creation of<br>
any object directly below the object that contains the
"mnt-lower:"<br>
attribute.<br>
<br>
Made up of letters, digits, the character underscore "_",<br>
and the character hyphen "-"; the first character of a name<br>
must be a letter, and the last character of a name must be a<br>
letter or a digit. The following words are reserved by<br>
RPSL, and they can not be used as names:<br>
<br>
any as-any rs-any peeras and or not atomic from to at<br>
action accept announce except refine networks into inbound<br>
outbound<br>
<br>
Names starting with certain prefixes are reserved for<br>
certain object types. Names starting with "as-" are<br>
reserved for as set names. Names starting with "rs-" are<br>
reserved for route set names. Names starting with "rtrs-"<br>
are reserved for router set names. Names starting with<br>
"fltr-" are reserved for filter set names. Names starting<br>
with "prng-" are reserved for peering set names. Names<br>
starting with "irt-" are reserved for irt names.<br>
<br>
changed<br>
<br>
Specifies who submitted the update, and when the object was
updated.<br>
This attribute is filtered from the default whois output.<br>
<br>
An e-mail address as defined in RFC 2822, followed by a date<br>
in the format YYYYMMDD.<br>
<br>
source<br>
<br>
Specifies the registry where the object is registered. Should
be<br>
"AFRINIC" for the AFRINIC Database.<br>
<br>
Made up of letters, digits, the character underscore "_",<br>
and the character hyphen "-"; the first character of a<br>
registry name must be a letter, and the last character of a<br>
registry name must be a letter or a digit.<br>
<br>
cacty@<a class="moz-txt-link-freetext" href="shalom:~$">shalom:~$</a> </i><br>
<br>
<br>
Have a blessed sunday; y'all!<br>
<br>
Shalom,<br>
--sb.<br>
<br>
<br>
<blockquote type="cite" cite="mid:1784239787450.20999@tra.gov.eg">
<pre wrap="" class="moz-quote-pre">Kind regards,
Haitham el Nakhal
AFRINIC PDWG Co-Chair
_______________________________________________
RPD mailing list
<a class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:RPD@afrinic.net">RPD@afrinic.net</a>
<a class="moz-txt-link-freetext"
href="https://lists.afrinic.net/mailman/listinfo/rpd">https://lists.afrinic.net/mailman/listinfo/rpd</a>
</pre>
</blockquote>
<br>
<div class="moz-signature">-- <font size="2"><br>
<br>
Best Regards !<br>
</font> <font size="2"><br>
baya.sylvain [AT cmNOG DOT cm] | <br>
<a href="https://www.cmnog.cm/dokuwiki/Structure">cmNOG's
Structure</a> | <a href="https://www.camix.cm/">CAMIX's
Website</a> | <a href="https://tools.std.douala-ix.net/lg">Douala-IX's
Looking Glass</a> | <br>
<a href="https://survey2.cmnog.cm/">cmNOG's Surveys</a> |
Subscribe to <a
href="https://lists.cmnog.cm/mailman/listinfo/cmnog">cmNOG's
Mailing List</a> | <br>
__ <br>
#LASAINTEBIBLE|#Ephé<a class="moz-txt-link-freetext"
href="siens5:18,15-21«">siens5:18,15-21«</a>[...] 18 Et <b><u>ne
vous enivrez</u></b> pas <b><u>de vin</u></b>, en quoi <b><u>il
y a de la dissolution</u></b>; mais <b><u>soyez remplis de
l'Esprit</u></b>, [...]» <br>
#LASAINTEBIBLE|#Hé<a class="moz-txt-link-freetext"
href="breux13:9,5-15«">breux13:9,5-15«</a>[...] 9 <u><b>Ne
soyez pas seduits par</b></u> des <u><b>doctrines diverses</b></u>
et <u><b>etrangeres</b></u>, car il est bon <u><b>que le coeur
soit affermi par la grace</b></u>, non par les viandes,
lesquels n'ont pas profite à ceux qui y ont marche. [...]» <br>
#AMEN,#Maranatha,#MerciJÉSUS! #MaPrière est que tu naisses de
nouveau.#Chrétiennement</font><br>
</div>
<br>
</body>
</html>