home.social

#rpki — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rpki, aggregated by home.social.

fetched live
  1. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  2. bgpipe v0.22 is out! 🚀

    New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.

    Which means every stage you already use just works on them:

    bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'

    That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.

    bgpipe.org

    #BGP #RPKI #networking

  3. #BGP #RPKI

    "With eight Firehol level 1 blocklist matches out of only 79 prefixes, repo.rpki.space stands out immediately. Inspection of BGP Tools DNS records for this server reveals a high density of mailing domains, strongly suggesting that spam mailing infrastructure is hosted across the prefixes in question. "

    An interesting survey of "small" RPKI servers. labs.ripe.net/author/ties-dirk

  4. #BGP #RPKI

    "With eight Firehol level 1 blocklist matches out of only 79 prefixes, repo.rpki.space stands out immediately. Inspection of BGP Tools DNS records for this server reveals a high density of mailing domains, strongly suggesting that spam mailing infrastructure is hosted across the prefixes in question. "

    An interesting survey of "small" RPKI servers. labs.ripe.net/author/ties-dirk

  5. China jumps - in the span of just 3 months - from 4% to a whopping 80% RPKI ROA coverage. Absolutely impressive. #RPKI #RoutingSecurity

  6. China jumps - in the span of just 3 months - from 4% to a whopping 80% RPKI ROA coverage. Absolutely impressive. #RPKI #RoutingSecurity

  7. In today's episode of "Who Cares?", #APNIC serves up an enthralling tale of minuscule #RPKI servers run by who-knows-who 🙄. It's a thrilling saga of navigating #Whois databases and paying bills, guaranteed to put you to sleep faster than you can say "IPv6" 😴.
    blog.apnic.net/2026/07/15/whos #WhoCares #IPv6 #TechHumor #HackerNews #ngated

  8. In today's episode of "Who Cares?", #APNIC serves up an enthralling tale of minuscule #RPKI servers run by who-knows-who 🙄. It's a thrilling saga of navigating #Whois databases and paying bills, guaranteed to put you to sleep faster than you can say "IPv6" 😴.
    blog.apnic.net/2026/07/15/whos #WhoCares #IPv6 #TechHumor #HackerNews #ngated

  9. I keep the ledger at isp6.

    The boring, reliable work: allocations, ROAs, reverse DNS — the records that decide whether the internet believes a prefix is yours. Done right, you never notice any of it.

    I'll write plainly here about IPv6, portability, and why the network identity you run on should be yours — on paper, not on loan.

    No hype. No drama. Just the work, signed.

    — Ada

    #Introduction #IPv6 #BGP #RPKI

  10. I keep the ledger at isp6.

    The boring, reliable work: allocations, ROAs, reverse DNS — the records that decide whether the internet believes a prefix is yours. Done right, you never notice any of it.

    I'll write plainly here about IPv6, portability, and why the network identity you run on should be yours — on paper, not on loan.

    No hype. No drama. Just the work, signed.

    — Ada

    #Introduction #IPv6 #BGP #RPKI

  11. Looks like @mingwei is promoting #RPKI tooling with pop up stores!

  12. Looks like @mingwei is promoting #RPKI tooling with pop up stores!

  13. Please note that we have volunteered to have all of our products and libraries analyzed by LLM tooling, so you can expect security releases for pretty much everything, down to libraries like rpki-rs and projects in maintenance mode like ldns.

    #DNS #RPKI #BGP #OpenSource

  14. Please note that we have volunteered to have all of our products and libraries analyzed by LLM tooling, so you can expect security releases for pretty much everything, down to libraries like rpki-rs and projects in maintenance mode like ldns.

    #DNS #RPKI #BGP #OpenSource

  15. 🚨 Security release! 🚨

    Routinator 0.15.2 ‘Irgendwas ist immer’ is now available, This release fixes a number of vulnerabilities and security issues identified by a security audit performed by @x41sec which was kindly funded by @sovtechfund.

    We advise all users to upgrade at their earliest convenience.

    community.nlnetlabs.nl/t/routi

    #RPKI #CVE #Security #BGP #Routing

  16. 🚨 Security release! 🚨

    Routinator 0.15.2 ‘Irgendwas ist immer’ is now available, This release fixes a number of vulnerabilities and security issues identified by a security audit performed by @x41sec which was kindly funded by @sovtechfund.

    We advise all users to upgrade at their earliest convenience.

    community.nlnetlabs.nl/t/routi

    #RPKI #CVE #Security #BGP #Routing

  17. @bawuenet hat jetzt für alle Adressen #rpki - danke fürs Aktivieren @ixs

  18. @bawuenet hat jetzt für alle Adressen #rpki - danke fürs Aktivieren @ixs

  19. La cybersécuritay, c'est compliquay. Comment la Corée du Nord a coupé sa liaison Internet en voulant la sécuriser. labs.ripe.net/author/romain_fo

    #BGP #RPKI

  20. La cybersécuritay, c'est compliquay. Comment la Corée du Nord a coupé sa liaison Internet en voulant la sécuriser. labs.ripe.net/author/romain_fo

    #BGP #RPKI

  21. 🚨 More new routing insights on Radar!

    - Track #RPKI ROA deployment history at a global/country/ASN level, going back 3+ years for valid prefixes & address space

    radar.cloudflare.com/routing/r

    - Country level announced IP address space graphs now include a "Show top ASes" toggle. Stacked area graphs make it easier to identify the providers behind large address space withdrawals.

    Example: radar.cloudflare.com/routing/i

  22. 🚨 More new routing insights on Radar!

    - Track #RPKI ROA deployment history at a global/country/ASN level, going back 3+ years for valid prefixes & address space

    radar.cloudflare.com/routing/r

    - Country level announced IP address space graphs now include a "Show top ASes" toggle. Stacked area graphs make it easier to identify the providers behind large address space withdrawals.

    Example: radar.cloudflare.com/routing/i

  23. rpki-client 9.8 released

    Routing security matters to all of us (even those of us who seldom give the subject any thought), and the rpki-client project announced the release of a new version of their Resource Public Key Infrastructure (RPKI) client, with a number of improvements.

    The announcement reads

    • List: openbsd-announce
    • Subject: rpki-client 9.8 released
    • From: Sebastian Benoit
    • Date: 2026-04-14 23:20:42

      rpki-client 9.8 has just been released and will be available in the rpki-client directory of any OpenBSD mirror soon.
      It is recommended
      that all users upgrade to this version for improved reliability.

      rpki-client is a FREE, easy-to-use implementation of the Resource
      Public Key Infrastructure (RPKI) for Relying Parties to facilitate
      validation of BGP announcements. The program queries the global RPKI
      repository system and validates untrusted network inputs. The program
      outputs validated ROA payloads, BGPsec Router keys, and ASPA payloads
      in configuration formats suitable for OpenBGPD and BIRD, and supports
      emitting CSV and JSON for consumption by other routing stacks.

      See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
      Origin Validation help secure the global Internet routing system.

      rpki-client was primarily developed by Kristaps Dzonsons, Claudio Jeker,
      Job Snijders, Theo Buehler, Theo de Raadt, and Sebastian Benoit as part
      of the OpenBSD Project.

      This release includes the following changes to the previous release:

      • Various refactoring for improved compatibility with various libcryptoimplementations and in CA/BGPsec certificate handling.
      • Fixed an accounting issue in HTTP gzip compression detection.
      • Added a warning in extra verbose mode (-vv) about standardsnon-compliant Issuer and Subject ASN.1 string encodings.
      • Added a check for canonical encoding of ASPA eContent in alignmentwith draft-ietf-sidrops-aspa-profile-22.
      • Ensure that a repository timeout correctly stops repositoryprocessing. Thanks to Fedor Vompe from Deutsche Telekom for reporting.
      • Fixed a defect in Canonical Cache Representation ROAIPAddressFamilysort order. As a result, rpki-client 9.8 cannot parse rpki-client9.7's .ccr files and vice versa. Thanks to Bart Bakker from RIPE NCCfor reporting.
      • Fixed an issue in the parser for the locally configured constraints.Thanks to Daniel Anderson.
      • A malicious RRDP Publication Server can cause a NULL dereference.Thanks to Daniel Anderson for reporting.
      • A malicious RPKI Publication Server can cause an incorrect error exit.Thanks to Yuheng Zhang, Qi Wang, Jianjun Chen from Tsinghua University,and Teatime Lab for reporting.

    Go read ALL about it here!

    undeadly.org/cgi?action=articl

    #rpki #client #resource #public #key #infrastructure #openBSD #OpenSource #programming #networking

  24. rpki-client 9.8 released

    Routing security matters to all of us (even those of us who seldom give the subject any thought), and the rpki-client project announced the release of a new version of their Resource Public Key Infrastructure (RPKI) client, with a number of improvements.

    The announcement reads

    • List: openbsd-announce
    • Subject: rpki-client 9.8 released
    • From: Sebastian Benoit
    • Date: 2026-04-14 23:20:42

      rpki-client 9.8 has just been released and will be available in the rpki-client directory of any OpenBSD mirror soon.
      It is recommended
      that all users upgrade to this version for improved reliability.

      rpki-client is a FREE, easy-to-use implementation of the Resource
      Public Key Infrastructure (RPKI) for Relying Parties to facilitate
      validation of BGP announcements. The program queries the global RPKI
      repository system and validates untrusted network inputs. The program
      outputs validated ROA payloads, BGPsec Router keys, and ASPA payloads
      in configuration formats suitable for OpenBGPD and BIRD, and supports
      emitting CSV and JSON for consumption by other routing stacks.

      See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
      Origin Validation help secure the global Internet routing system.

      rpki-client was primarily developed by Kristaps Dzonsons, Claudio Jeker,
      Job Snijders, Theo Buehler, Theo de Raadt, and Sebastian Benoit as part
      of the OpenBSD Project.

      This release includes the following changes to the previous release:

      • Various refactoring for improved compatibility with various libcryptoimplementations and in CA/BGPsec certificate handling.
      • Fixed an accounting issue in HTTP gzip compression detection.
      • Added a warning in extra verbose mode (-vv) about standardsnon-compliant Issuer and Subject ASN.1 string encodings.
      • Added a check for canonical encoding of ASPA eContent in alignmentwith draft-ietf-sidrops-aspa-profile-22.
      • Ensure that a repository timeout correctly stops repositoryprocessing. Thanks to Fedor Vompe from Deutsche Telekom for reporting.
      • Fixed a defect in Canonical Cache Representation ROAIPAddressFamilysort order. As a result, rpki-client 9.8 cannot parse rpki-client9.7's .ccr files and vice versa. Thanks to Bart Bakker from RIPE NCCfor reporting.
      • Fixed an issue in the parser for the locally configured constraints.Thanks to Daniel Anderson.
      • A malicious RRDP Publication Server can cause a NULL dereference.Thanks to Daniel Anderson for reporting.
      • A malicious RPKI Publication Server can cause an incorrect error exit.Thanks to Yuheng Zhang, Qi Wang, Jianjun Chen from Tsinghua University,and Teatime Lab for reporting.

    Go read ALL about it here!

    undeadly.org/cgi?action=articl

    #rpki #client #resource #public #key #infrastructure #openBSD #OpenSource #programming #networking

  25. On Tuesday, 7 April, the Global Internet Standards Testing Community (GISTC) held its 3rd online meeting, which was chaired by Alena Muravska from @ripencc.

    The GISTC brings together organisations from all over the world around #InternetStandards the Internet.nl test tool and open-source code.

    Its goal is to enable knowledge exchange, coordination of efforts, and of course to collaboratively improve the adoption of modern internet standards like #IPv6, #DNSSEC, #DANE, #DMARC, and #RPKI.

    1/3

  26. On Tuesday, 7 April, the Global Internet Standards Testing Community (GISTC) held its 3rd online meeting, which was chaired by Alena Muravska from @ripencc.

    The GISTC brings together organisations from all over the world around #InternetStandards the Internet.nl test tool and open-source code.

    Its goal is to enable knowledge exchange, coordination of efforts, and of course to collaboratively improve the adoption of modern internet standards like #IPv6, #DNSSEC, #DANE, #DMARC, and #RPKI.

    1/3

  27. Weekend Reads

    * Email address obfuscation in 2026
    spencermortensen.com/articles/
    * Profile of Kimwolf botnet researcher
    wsj.com/tech/kimwolf-hack-resi
    * Quantifying AI data center heat impacts
    arxiv.org/abs/2603.20897
    * Characterizing invalid routes via Tunnels
    arxiv.org/abs/2603.29207
    * Detecting anomalous topology, routes, and congestion
    arxiv.org/abs/2603.25875

    #EMail #Kimwolf #AI #RPKI #BGP

  28. Weekend Reads

    * Email address obfuscation in 2026
    spencermortensen.com/articles/
    * Profile of Kimwolf botnet researcher
    wsj.com/tech/kimwolf-hack-resi
    * Quantifying AI data center heat impacts
    arxiv.org/abs/2603.20897
    * Characterizing invalid routes via Tunnels
    arxiv.org/abs/2603.29207
    * Detecting anomalous topology, routes, and congestion
    arxiv.org/abs/2603.25875

    #EMail #Kimwolf #AI #RPKI #BGP

  29. 🚀 Ah, the noble quest to secure the Internet's mailman! 🌍 #BGP is still as safe as letting toddlers handle your bank transactions. But fear not, because #ISPs will definitely implement #RPKI and save the day...right after they solve world peace and cure aging. 😂
    isbgpsafeyet.com/ #InternetSecurity #CyberSecurity #Humor #HackerNews #ngated

  30. 🚀 Ah, the noble quest to secure the Internet's mailman! 🌍 #BGP is still as safe as letting toddlers handle your bank transactions. But fear not, because #ISPs will definitely implement #RPKI and save the day...right after they solve world peace and cure aging. 😂
    isbgpsafeyet.com/ #InternetSecurity #CyberSecurity #Humor #HackerNews #ngated

  31. Last week I was in Stockholm for the route servers workshop organised by #Euro-IX. I presented my work on the #Debian packaging of software like #BIRD, #OpenBGPD and the #RPKI validators.

    Slides are available at linux.it/~md/text/ixp-debian-r .

  32. Last week I was in Stockholm for the route servers workshop organised by #Euro-IX. I presented my work on the #Debian packaging of software like #BIRD, #OpenBGPD and the #RPKI validators.

    Slides are available at linux.it/~md/text/ixp-debian-r .

  33. Interesting discussion about distribution / decentralization / de facto concentration of the #RPKI at #IETF125, which reminds me of discussions about the fediverse, Bluesky, etc.

  34. Interesting discussion about distribution / decentralization / de facto concentration of the #RPKI at #IETF125, which reminds me of discussions about the fediverse, Bluesky, etc.

  35. "RPKI has been around for a while... more than a decade..."

    🤔

    🧐

    😱

    "more than a decade"??

    ... I remember when it began... 😃

    #IETF #IETF125 #RPKI #RoutingSecurity #MANRS

  36. "RPKI has been around for a while... more than a decade..."

    🤔

    🧐

    😱

    "more than a decade"??

    ... I remember when it began... 😃

    #IETF #IETF125 #RPKI #RoutingSecurity #MANRS

  37. "ARIN's Director of Customer Technical Services, Brad Gorman, is bringing RPKI expertise to the Toronto Network Operators Group's inaugural full-day conference."

    Learn:
    🔹 What RPKI actually does
    🔹 Why it matters for YOUR network
    🔹 How to deploy it safely
    🔹 Where to start (no theory overload!)

    See ARIN"S original post here: instagram.com/p/DV2VLbfDTN4/

    Join us on April 13th and check out the full agenda here:

    tornog.ca/events/tornog-1/agen

    #TORNOG #RPKI #RoutingSecurity #Toronto #NetworkOperations

  38. The agenda for TORNOG 1 is live! tornog.ca/events/tornog-1/agen

    Join us for the the inaugural TORNOG full day conference on April 13th, at the MaRS Centre in Toronto!

    #Toronto #RPKI #Fiber #IX #Sovereignty #AutonomousResilience #CloudNetwork #NetworkAutomation

  39. Krill 0.16.0 is now available.

    This release of our #RPKI Certification Authority reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API.

    The Krill daemon will now also listen on a Unix socket which allows it to use the name of the local user for authentication, making it unnecessary to specify the authentication token when using krillc locally.

    community.nlnetlabs.nl/t/krill