SlideShare uma empresa Scribd logo
1 de 28
Baixar para ler offline
Nathalie Trenaman | LINX Presents | 26 January 2021
Securing the Internet
One Hop at a Time
RPKI
Nathalie Trenaman | LINX Presents | 26 January 2021
2
Resource Public Key Infrastructure
•Ties IP addresses and ASNs to public keys
•Follows the hierarchy of the registries
•Authorised statements from resource holders
-“ASN X is authorised to announce my Prefix Y”
-Signed, holder of Y
Nathalie Trenaman | LINX Presents | 26 January 2021
3
Two Elements of RPKI
Signing
Create your ROAs
Validating
Verifying others
Nathalie Trenaman | LINX Presents | 26 January 2021
4
RPKI Certificate Structure
ARIN APNIC RIPE LACNIC AFRINIC
Member
Member
Member
ROA ROA ROA
Certificate hierarchy follows allocation hierarchy
Nathalie Trenaman | LINX Presents | 26 January 2021
5
Hosted or Delegated RPKI
RIPE
ROA ROA
ROA ROA
ROA
Member Member Member
ROA
Member-X CA Member-Y CA
RIPE NCC Hosted System
RPKI Challenges
Nathalie Trenaman | LINX Presents | 26 January 2021
7
2020: The Year of RPKI
• Serious uptake in Route Origin Validation at transits and IXPs
• Resulting in decrease of Invalid RPKI BGP announcements
• High uptake in signing objects at other Regional Internet
Registries
• All major routing vendors are now on board
• Increase in delegated RPKI
• Also some outages at different Trust Anchors
Nathalie Trenaman | LINX Presents | 26 January 2021
8
What Happened?
• 22 February 2020: Certificate Revocation List (CRL) expired
- Full disk resulted in an expired CRL – went unnoticed on our side
- Some Validators didn’t notice this
- Sparked a discussion in the IETF about unified stricter behaviour of validation
software
- We improved our monitoring
• 3 April 2020: 2,669 ROAs got deleted
- Update of the registry software resulted in a mismatch of resources in RPKI
- RIPE NCC decided to restore all deleted ROAs
- Added checks between the different software
Nathalie Trenaman | LINX Presents | 26 January 2021
9
And There Was More…..
• 6 April 2020: rsync repository was unavailable for 7 hours
- Servers reached maximum capacity pool size
- A malfunctioning client was hanging and established many new connections
- We enhanced the maximum capacity pool size
- We’re (also) moving rsync to the cloud
• 12 August 2020: Manifest encoding issue at ARIN
- Went unnoticed for some Validator software
- ARIN expanded their test environment with additional Validator software
Nathalie Trenaman | LINX Presents | 26 January 2021
10
What Can You Do?
• Set up alerts in the LIR Portal
Nathalie Trenaman | LINX Presents | 26 January 2021
11
What Else Can You Do?
• Make sure your MaxLength matches your intent
Nathalie Trenaman | LINX Presents | 26 January 2021
12
What Else Can You Do?
• Make sure your AS Number matches your intent
13
So, How Bad Are Things?
Nathalie Trenaman | LINX Presents | 26 January 2021
14
Key Takeaways
• Creating a ROA helps – a lot!
• Most large transit providers and IXPs perform Route Origin
Validation (ROV)
• Many ISPs that have BGP customers don’t. This is problematic.
• Just ROV is not the holy grail for all BGP mishaps.
- We really need Path Validation
Plans for the Future
of RPKI
At the RIPE NCC
Nathalie Trenaman | LINX Presents | 26 January 2021
16
Focus on Resiliency
• Significant improvements in metrics/monitoring finalised
- Usage of Prometheus with Grafana for visualisations
- Hooking up with SMS alerting for engineers on 24/7 duty
• Deployment of rsync/RRDP into AWS in progress
- Multiple regions/availability zones with aim of very high availability
- RRDP is already in AWS but with simpler architecture – the goal is to also move rsync
to similar architecture
- Redundant fully functional infrastructure in our current data centres to provide very
high resiliency being evaluated by the teams
Nathalie Trenaman | LINX Presents | 26 January 2021
17
Focus on Security
• Performed an RFC compliance audit
• Building an RPKI specific audit framework in SOC 2 type II
• For 2021:
- Publish a report from the RFC compliance audit
- Performing SOC 2 type II audit, publish a SOC 3 report
- Performing penetration test
- Performing Red Team test
Nathalie Trenaman | LINX Presents | 26 January 2021
18
Upcoming Work from the IETF
• Autonomous System Provider Authorisation (ASPA)
- https://tools.ietf.org/html/draft-ietf-sidrops-aspa-profile-04
• Validation Reconsidered
- https://tools.ietf.org/html/rfc8360
• Resource Tagged Attestations (RTA)
- https://tools.ietf.org/html/draft-michaelson-rpki-rta-02
Deprecating the
RIPE NCC Validator
Nathalie Trenaman | LINX Presents | 26 January 2021
20
Timeline
STOP
Phase 1 Phase 2 Phase 3
28 Oct 2020 1 Jan 2021 1 March 2021 1 July 2021
Nathalie Trenaman | LINX Presents | 26 January 2021
21
Phase 1
• 28 October 2020 - 31 December 2021
• Work continues as normal:
- Features
- RFC implementations
- Policy implementations (AS0 in other regions)
- Bug fixes
- Security fixes
• Community will be informed of future timeline
Nathalie Trenaman | LINX Presents | 26 January 2021
22
Phase 2
• 1 January 2021 - 28 February 2021
• No new features will be implemented
• Continued work on:
- RFC implementations
- Policy implementations (AS0 in other regions)
- Bug fixes
- Security fixes
• Training material and website will be updated
Nathalie Trenaman | LINX Presents | 26 January 2021
23
Phase 3
• 1 March 2021 - 30 June 2021
• No more work on RFC and policy implementations
• Continued work on:
- Bug fixes
- Security fixes
• On 1 July 2021, we will archive the RIPE NCC RPKI Validator
Nathalie Trenaman | LINX Presents | 26 January 2021
24
Alternatives
• All are open source:
- Routinator - https://github.com/NLnetLabs/routinator/
- FORT - https://github.com/NICMx/FORT-validator/
- OctoRPKI - https://github.com/cloudflare/cfrpki
- RPKI-client - https://rpki-client.org/
- Prover - https://github.com/lolepezy/rpki-prover
- Rpstir2 - https://github.com/bgpsecurity/rpstir2
Insiders Tips
Nathalie Trenaman | LINX Presents | 26 January 2021
26
Insiders Tips & Tricks
• It might take a few hours from the moment you create your ROA
to making them appear in all Validators and BGP
• If you run your own CA, be aware that your repository is critical
infrastructure
• Maintaining route objects and maintaining filters in BGP are still
very important
Nathalie Trenaman | LINX Presents | 26 January 2021
27
How Do I Get Started?
• Read up! This is a great starting point:
- https://rpki.readthedocs.io/en/latest/
• Create your ROAs:
- https://my.ripe.net/#/rpki (login required)
• Download a Validator
- Not from RIPE NCC :)
• Share your experience or ask for advice
- https://www.ripe.net/mailman/listinfo/routing-wg/
?
Questions
nathalie@ripe.net
rpki@ripe.net

Mais conteúdo relacionado

Mais procurados

IANA Update September 2015
IANA Update September 2015IANA Update September 2015
IANA Update September 2015APNIC
 
Detecting BGP Instability Using RQA
Detecting BGP Instability Using RQADetecting BGP Instability Using RQA
Detecting BGP Instability Using RQAUniversity of Kufa
 
Route Origin Authorization (ROA) using RPKI
Route Origin Authorization (ROA) using RPKIRoute Origin Authorization (ROA) using RPKI
Route Origin Authorization (ROA) using RPKIAPNIC
 
IPv6 for IXPs workshop - Manama - January 2016
IPv6 for IXPs workshop - Manama - January 2016IPv6 for IXPs workshop - Manama - January 2016
IPv6 for IXPs workshop - Manama - January 2016Kjell Leknes
 
APNIC Update: PITA 19
APNIC Update: PITA 19APNIC Update: PITA 19
APNIC Update: PITA 19APNIC
 
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221Lynn Woodruff
 
ARIN Update
ARIN UpdateARIN Update
ARIN UpdateAPNIC
 
RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)Fakrul Alam
 
APNIC Services by Anna Mulingbayan
APNIC Services by Anna MulingbayanAPNIC Services by Anna Mulingbayan
APNIC Services by Anna MulingbayanMyNOG
 
Introduction to RPKI
Introduction to RPKIIntroduction to RPKI
Introduction to RPKIAPNIC
 
IDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaIDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaAPNIC
 
Fintech week london 2014
Fintech week london 2014Fintech week london 2014
Fintech week london 2014Mauro Rappa
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation
 
20210506 meeting2
20210506 meeting220210506 meeting2
20210506 meeting2NickHuang49
 
IPv6 at 6connect, PTC17
IPv6 at 6connect, PTC17IPv6 at 6connect, PTC17
IPv6 at 6connect, PTC17APNIC
 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTAPNIC
 
SGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesSGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesAPNIC
 
RPKI Trust Anchor
RPKI Trust AnchorRPKI Trust Anchor
RPKI Trust AnchorAPNIC
 

Mais procurados (20)

IANA Update September 2015
IANA Update September 2015IANA Update September 2015
IANA Update September 2015
 
Near rt ric tc
Near rt ric tcNear rt ric tc
Near rt ric tc
 
Detecting BGP Instability Using RQA
Detecting BGP Instability Using RQADetecting BGP Instability Using RQA
Detecting BGP Instability Using RQA
 
Lacnic measurements
Lacnic measurementsLacnic measurements
Lacnic measurements
 
Route Origin Authorization (ROA) using RPKI
Route Origin Authorization (ROA) using RPKIRoute Origin Authorization (ROA) using RPKI
Route Origin Authorization (ROA) using RPKI
 
IPv6 for IXPs workshop - Manama - January 2016
IPv6 for IXPs workshop - Manama - January 2016IPv6 for IXPs workshop - Manama - January 2016
IPv6 for IXPs workshop - Manama - January 2016
 
APNIC Update: PITA 19
APNIC Update: PITA 19APNIC Update: PITA 19
APNIC Update: PITA 19
 
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221
Sprint Spark-Capable, Tri-Band LTE Router - NetGear 6100 - Datasheet 140221
 
ARIN Update
ARIN UpdateARIN Update
ARIN Update
 
RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)RPKI (Resource Public Key Infrastructure)
RPKI (Resource Public Key Infrastructure)
 
APNIC Services by Anna Mulingbayan
APNIC Services by Anna MulingbayanAPNIC Services by Anna Mulingbayan
APNIC Services by Anna Mulingbayan
 
Introduction to RPKI
Introduction to RPKIIntroduction to RPKI
Introduction to RPKI
 
IDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaIDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesia
 
Fintech week london 2014
Fintech week london 2014Fintech week london 2014
Fintech week london 2014
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCA
 
20210506 meeting2
20210506 meeting220210506 meeting2
20210506 meeting2
 
IPv6 at 6connect, PTC17
IPv6 at 6connect, PTC17IPv6 at 6connect, PTC17
IPv6 at 6connect, PTC17
 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRT
 
SGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesSGNOG2 - APNIC Updates
SGNOG2 - APNIC Updates
 
RPKI Trust Anchor
RPKI Trust AnchorRPKI Trust Anchor
RPKI Trust Anchor
 

Semelhante a RPKI - Securing the Internet One Hop at a Time

VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools APNIC
 
Recent Developments in RPKI
Recent Developments in RPKIRecent Developments in RPKI
Recent Developments in RPKIRIPE NCC
 
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?PROIDEA
 
Openstack Overview
Openstack OverviewOpenstack Overview
Openstack Overviewrajdeep
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISRIPE NCC
 
Collaborating with OpenDaylight for a Network-Enabled Cloud
Collaborating with OpenDaylight for a Network-Enabled CloudCollaborating with OpenDaylight for a Network-Enabled Cloud
Collaborating with OpenDaylight for a Network-Enabled CloudTesora
 
ARIN Engineering Department Report
ARIN Engineering Department ReportARIN Engineering Department Report
ARIN Engineering Department ReportARIN
 
Myanmar Member Gathering
Myanmar Member GatheringMyanmar Member Gathering
Myanmar Member GatheringAPNIC
 
34th TWNIC OPM: APNIC Policy Implementation Update
34th TWNIC OPM: APNIC Policy Implementation Update34th TWNIC OPM: APNIC Policy Implementation Update
34th TWNIC OPM: APNIC Policy Implementation UpdateAPNIC
 
IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?apnic_slides
 
APNIC services and Policy Development Process | IDNOG 5
APNIC services and Policy Development Process | IDNOG 5APNIC services and Policy Development Process | IDNOG 5
APNIC services and Policy Development Process | IDNOG 5APNIC
 
RINA research results - NGP forum - SDN World Congress 2017
RINA research results - NGP forum - SDN World Congress 2017RINA research results - NGP forum - SDN World Congress 2017
RINA research results - NGP forum - SDN World Congress 2017ARCFIRE ICT
 
Building Modern Digital Services on Scalable Private Government Infrastructur...
Building Modern Digital Services on Scalable Private Government Infrastructur...Building Modern Digital Services on Scalable Private Government Infrastructur...
Building Modern Digital Services on Scalable Private Government Infrastructur...Andrés Colón Pérez
 
RIPE NCC Operations and Analysis Tools
RIPE NCC Operations and Analysis ToolsRIPE NCC Operations and Analysis Tools
RIPE NCC Operations and Analysis ToolsRIPE NCC
 
Training Update and Technical Assistance Service Demo
Training Update and Technical Assistance Service DemoTraining Update and Technical Assistance Service Demo
Training Update and Technical Assistance Service DemoAPNIC
 
IPv6 deployment status - APEC TEL47
IPv6 deployment status - APEC TEL47IPv6 deployment status - APEC TEL47
IPv6 deployment status - APEC TEL47APNIC
 
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasRIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasAPNIC
 
RIPE NCC Update
RIPE NCC UpdateRIPE NCC Update
RIPE NCC UpdateAPNIC
 
RIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC
 
Automation, Agility and NFV
Automation, Agility and NFVAutomation, Agility and NFV
Automation, Agility and NFVJames Crawshaw
 

Semelhante a RPKI - Securing the Internet One Hop at a Time (20)

VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools
 
Recent Developments in RPKI
Recent Developments in RPKIRecent Developments in RPKI
Recent Developments in RPKI
 
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?
PLNOG 7: Ferenc Csorba - What’s new at the RIPE NCC?
 
Openstack Overview
Openstack OverviewOpenstack Overview
Openstack Overview
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
 
Collaborating with OpenDaylight for a Network-Enabled Cloud
Collaborating with OpenDaylight for a Network-Enabled CloudCollaborating with OpenDaylight for a Network-Enabled Cloud
Collaborating with OpenDaylight for a Network-Enabled Cloud
 
ARIN Engineering Department Report
ARIN Engineering Department ReportARIN Engineering Department Report
ARIN Engineering Department Report
 
Myanmar Member Gathering
Myanmar Member GatheringMyanmar Member Gathering
Myanmar Member Gathering
 
34th TWNIC OPM: APNIC Policy Implementation Update
34th TWNIC OPM: APNIC Policy Implementation Update34th TWNIC OPM: APNIC Policy Implementation Update
34th TWNIC OPM: APNIC Policy Implementation Update
 
IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?
 
APNIC services and Policy Development Process | IDNOG 5
APNIC services and Policy Development Process | IDNOG 5APNIC services and Policy Development Process | IDNOG 5
APNIC services and Policy Development Process | IDNOG 5
 
RINA research results - NGP forum - SDN World Congress 2017
RINA research results - NGP forum - SDN World Congress 2017RINA research results - NGP forum - SDN World Congress 2017
RINA research results - NGP forum - SDN World Congress 2017
 
Building Modern Digital Services on Scalable Private Government Infrastructur...
Building Modern Digital Services on Scalable Private Government Infrastructur...Building Modern Digital Services on Scalable Private Government Infrastructur...
Building Modern Digital Services on Scalable Private Government Infrastructur...
 
RIPE NCC Operations and Analysis Tools
RIPE NCC Operations and Analysis ToolsRIPE NCC Operations and Analysis Tools
RIPE NCC Operations and Analysis Tools
 
Training Update and Technical Assistance Service Demo
Training Update and Technical Assistance Service DemoTraining Update and Technical Assistance Service Demo
Training Update and Technical Assistance Service Demo
 
IPv6 deployment status - APEC TEL47
IPv6 deployment status - APEC TEL47IPv6 deployment status - APEC TEL47
IPv6 deployment status - APEC TEL47
 
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasRIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
 
RIPE NCC Update
RIPE NCC UpdateRIPE NCC Update
RIPE NCC Update
 
RIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An Update
 
Automation, Agility and NFV
Automation, Agility and NFVAutomation, Agility and NFV
Automation, Agility and NFV
 

Mais de RIPE NCC

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryRIPE NCC
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionRIPE NCC
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in TechRIPE NCC
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfRIPE NCC
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopRIPE NCC
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfRIPE NCC
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfRIPE NCC
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsRIPE NCC
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing SecurityRIPE NCC
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfRIPE NCC
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasRIPE NCC
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasRIPE NCC
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet InfrastructureRIPE NCC
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenRIPE NCC
 
IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)RIPE NCC
 

Mais de RIPE NCC (20)

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet Registry
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate Action
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in Tech
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement Tools
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the Baltics
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing Security
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE Atlas
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement Services
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in Sweden
 
IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)
 

Último

Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfhans926745
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 

Último (20)

Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 

RPKI - Securing the Internet One Hop at a Time

  • 1. Nathalie Trenaman | LINX Presents | 26 January 2021 Securing the Internet One Hop at a Time RPKI
  • 2. Nathalie Trenaman | LINX Presents | 26 January 2021 2 Resource Public Key Infrastructure •Ties IP addresses and ASNs to public keys •Follows the hierarchy of the registries •Authorised statements from resource holders -“ASN X is authorised to announce my Prefix Y” -Signed, holder of Y
  • 3. Nathalie Trenaman | LINX Presents | 26 January 2021 3 Two Elements of RPKI Signing Create your ROAs Validating Verifying others
  • 4. Nathalie Trenaman | LINX Presents | 26 January 2021 4 RPKI Certificate Structure ARIN APNIC RIPE LACNIC AFRINIC Member Member Member ROA ROA ROA Certificate hierarchy follows allocation hierarchy
  • 5. Nathalie Trenaman | LINX Presents | 26 January 2021 5 Hosted or Delegated RPKI RIPE ROA ROA ROA ROA ROA Member Member Member ROA Member-X CA Member-Y CA RIPE NCC Hosted System
  • 7. Nathalie Trenaman | LINX Presents | 26 January 2021 7 2020: The Year of RPKI • Serious uptake in Route Origin Validation at transits and IXPs • Resulting in decrease of Invalid RPKI BGP announcements • High uptake in signing objects at other Regional Internet Registries • All major routing vendors are now on board • Increase in delegated RPKI • Also some outages at different Trust Anchors
  • 8. Nathalie Trenaman | LINX Presents | 26 January 2021 8 What Happened? • 22 February 2020: Certificate Revocation List (CRL) expired - Full disk resulted in an expired CRL – went unnoticed on our side - Some Validators didn’t notice this - Sparked a discussion in the IETF about unified stricter behaviour of validation software - We improved our monitoring • 3 April 2020: 2,669 ROAs got deleted - Update of the registry software resulted in a mismatch of resources in RPKI - RIPE NCC decided to restore all deleted ROAs - Added checks between the different software
  • 9. Nathalie Trenaman | LINX Presents | 26 January 2021 9 And There Was More….. • 6 April 2020: rsync repository was unavailable for 7 hours - Servers reached maximum capacity pool size - A malfunctioning client was hanging and established many new connections - We enhanced the maximum capacity pool size - We’re (also) moving rsync to the cloud • 12 August 2020: Manifest encoding issue at ARIN - Went unnoticed for some Validator software - ARIN expanded their test environment with additional Validator software
  • 10. Nathalie Trenaman | LINX Presents | 26 January 2021 10 What Can You Do? • Set up alerts in the LIR Portal
  • 11. Nathalie Trenaman | LINX Presents | 26 January 2021 11 What Else Can You Do? • Make sure your MaxLength matches your intent
  • 12. Nathalie Trenaman | LINX Presents | 26 January 2021 12 What Else Can You Do? • Make sure your AS Number matches your intent
  • 13. 13 So, How Bad Are Things?
  • 14. Nathalie Trenaman | LINX Presents | 26 January 2021 14 Key Takeaways • Creating a ROA helps – a lot! • Most large transit providers and IXPs perform Route Origin Validation (ROV) • Many ISPs that have BGP customers don’t. This is problematic. • Just ROV is not the holy grail for all BGP mishaps. - We really need Path Validation
  • 15. Plans for the Future of RPKI At the RIPE NCC
  • 16. Nathalie Trenaman | LINX Presents | 26 January 2021 16 Focus on Resiliency • Significant improvements in metrics/monitoring finalised - Usage of Prometheus with Grafana for visualisations - Hooking up with SMS alerting for engineers on 24/7 duty • Deployment of rsync/RRDP into AWS in progress - Multiple regions/availability zones with aim of very high availability - RRDP is already in AWS but with simpler architecture – the goal is to also move rsync to similar architecture - Redundant fully functional infrastructure in our current data centres to provide very high resiliency being evaluated by the teams
  • 17. Nathalie Trenaman | LINX Presents | 26 January 2021 17 Focus on Security • Performed an RFC compliance audit • Building an RPKI specific audit framework in SOC 2 type II • For 2021: - Publish a report from the RFC compliance audit - Performing SOC 2 type II audit, publish a SOC 3 report - Performing penetration test - Performing Red Team test
  • 18. Nathalie Trenaman | LINX Presents | 26 January 2021 18 Upcoming Work from the IETF • Autonomous System Provider Authorisation (ASPA) - https://tools.ietf.org/html/draft-ietf-sidrops-aspa-profile-04 • Validation Reconsidered - https://tools.ietf.org/html/rfc8360 • Resource Tagged Attestations (RTA) - https://tools.ietf.org/html/draft-michaelson-rpki-rta-02
  • 20. Nathalie Trenaman | LINX Presents | 26 January 2021 20 Timeline STOP Phase 1 Phase 2 Phase 3 28 Oct 2020 1 Jan 2021 1 March 2021 1 July 2021
  • 21. Nathalie Trenaman | LINX Presents | 26 January 2021 21 Phase 1 • 28 October 2020 - 31 December 2021 • Work continues as normal: - Features - RFC implementations - Policy implementations (AS0 in other regions) - Bug fixes - Security fixes • Community will be informed of future timeline
  • 22. Nathalie Trenaman | LINX Presents | 26 January 2021 22 Phase 2 • 1 January 2021 - 28 February 2021 • No new features will be implemented • Continued work on: - RFC implementations - Policy implementations (AS0 in other regions) - Bug fixes - Security fixes • Training material and website will be updated
  • 23. Nathalie Trenaman | LINX Presents | 26 January 2021 23 Phase 3 • 1 March 2021 - 30 June 2021 • No more work on RFC and policy implementations • Continued work on: - Bug fixes - Security fixes • On 1 July 2021, we will archive the RIPE NCC RPKI Validator
  • 24. Nathalie Trenaman | LINX Presents | 26 January 2021 24 Alternatives • All are open source: - Routinator - https://github.com/NLnetLabs/routinator/ - FORT - https://github.com/NICMx/FORT-validator/ - OctoRPKI - https://github.com/cloudflare/cfrpki - RPKI-client - https://rpki-client.org/ - Prover - https://github.com/lolepezy/rpki-prover - Rpstir2 - https://github.com/bgpsecurity/rpstir2
  • 26. Nathalie Trenaman | LINX Presents | 26 January 2021 26 Insiders Tips & Tricks • It might take a few hours from the moment you create your ROA to making them appear in all Validators and BGP • If you run your own CA, be aware that your repository is critical infrastructure • Maintaining route objects and maintaining filters in BGP are still very important
  • 27. Nathalie Trenaman | LINX Presents | 26 January 2021 27 How Do I Get Started? • Read up! This is a great starting point: - https://rpki.readthedocs.io/en/latest/ • Create your ROAs: - https://my.ripe.net/#/rpki (login required) • Download a Validator - Not from RIPE NCC :) • Share your experience or ask for advice - https://www.ripe.net/mailman/listinfo/routing-wg/