#rpki — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rpki, aggregated by home.social.
-
Job Snijders (job@) has imported a new network daemon to #OpenBSD -current, not yet linked to the build.
job@ modified src/usr.sbin/{rtrd,rtrctl}/*: Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation
The rtrd(8) program is intended as a scalable distribution layer to deliver data produced by rpki-client(8) to clients such as bgpd(8) in multi-node/multi-vendor IXP and ISP deployments.
A single rtrd(8) instance can concurrently serve many BGP routers and route servers.Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!
OK deraadt@ claudio@
-
Job Snijders (job@) has imported a new network daemon to #OpenBSD -current, not yet linked to the build.
job@ modified src/usr.sbin/{rtrd,rtrctl}/*: Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation
The rtrd(8) program is intended as a scalable distribution layer to deliver data produced by rpki-client(8) to clients such as bgpd(8) in multi-node/multi-vendor IXP and ISP deployments.
A single rtrd(8) instance can concurrently serve many BGP routers and route servers.Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!
OK deraadt@ claudio@
-
Job Snijders (job@) has imported a new network daemon to #OpenBSD -current, not yet linked to the build.
job@ modified src/usr.sbin/{rtrd,rtrctl}/*: Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation
The rtrd(8) program is intended as a scalable distribution layer to deliver data produced by rpki-client(8) to clients such as bgpd(8) in multi-node/multi-vendor IXP and ISP deployments.
A single rtrd(8) instance can concurrently serve many BGP routers and route servers.Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!
OK deraadt@ claudio@
-
Job Snijders (job@) has imported a new network daemon to #OpenBSD -current, not yet linked to the build.
job@ modified src/usr.sbin/{rtrd,rtrctl}/*: Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation
The rtrd(8) program is intended as a scalable distribution layer to deliver data produced by rpki-client(8) to clients such as bgpd(8) in multi-node/multi-vendor IXP and ISP deployments.
A single rtrd(8) instance can concurrently serve many BGP routers and route servers.Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!
OK deraadt@ claudio@
-
Job Snijders (job@) has imported a new network daemon to #OpenBSD -current, not yet linked to the build.
job@ modified src/usr.sbin/{rtrd,rtrctl}/*: Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation
The rtrd(8) program is intended as a scalable distribution layer to deliver data produced by rpki-client(8) to clients such as bgpd(8) in multi-node/multi-vendor IXP and ISP deployments.
A single rtrd(8) instance can concurrently serve many BGP routers and route servers.Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!
OK deraadt@ claudio@
-
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
-
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
-
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
-
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
-
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
-
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
-
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
-
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
-
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
-
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
-
Weekend Reads
* Internet PMTU measurement analysis
https://pure.mpg.de/rest/items/item_3728539_1/component/file_3728540/content
* Negative DNS answers
https://ispcol.potaroo.net/2026-08/nxd.html
* Telstra July 2026 outage report
https://www.telstra.com.au/content/dam/tcom/dynamic-media-projects/luke-campbell/TAP-Findings-for-Telstra-Outage.pdf
* The IRR landscape RPKI can replace
https://labs.ripe.net/author/mw/the-irr-landscape-what-rpki-can-replace/
* Unexpected IP4 TTL rewrites
https://sebastiankappes.com/papers/kappes2026ttl.pdf -
Weekend Reads
* Internet PMTU measurement analysis
https://pure.mpg.de/rest/items/item_3728539_1/component/file_3728540/content
* Negative DNS answers
https://ispcol.potaroo.net/2026-08/nxd.html
* Telstra July 2026 outage report
https://www.telstra.com.au/content/dam/tcom/dynamic-media-projects/luke-campbell/TAP-Findings-for-Telstra-Outage.pdf
* The IRR landscape RPKI can replace
https://labs.ripe.net/author/mw/the-irr-landscape-what-rpki-can-replace/
* Unexpected IP4 TTL rewrites
https://sebastiankappes.com/papers/kappes2026ttl.pdf -
Weekend Reads
* Internet PMTU measurement analysis
https://pure.mpg.de/rest/items/item_3728539_1/component/file_3728540/content
* Negative DNS answers
https://ispcol.potaroo.net/2026-08/nxd.html
* Telstra July 2026 outage report
https://www.telstra.com.au/content/dam/tcom/dynamic-media-projects/luke-campbell/TAP-Findings-for-Telstra-Outage.pdf
* The IRR landscape RPKI can replace
https://labs.ripe.net/author/mw/the-irr-landscape-what-rpki-can-replace/
* Unexpected IP4 TTL rewrites
https://sebastiankappes.com/papers/kappes2026ttl.pdf -
Weekend Reads
* Internet PMTU measurement analysis
https://pure.mpg.de/rest/items/item_3728539_1/component/file_3728540/content
* Negative DNS answers
https://ispcol.potaroo.net/2026-08/nxd.html
* Telstra July 2026 outage report
https://www.telstra.com.au/content/dam/tcom/dynamic-media-projects/luke-campbell/TAP-Findings-for-Telstra-Outage.pdf
* The IRR landscape RPKI can replace
https://labs.ripe.net/author/mw/the-irr-landscape-what-rpki-can-replace/
* Unexpected IP4 TTL rewrites
https://sebastiankappes.com/papers/kappes2026ttl.pdf -
Weekend Reads
* Internet PMTU measurement analysis
https://pure.mpg.de/rest/items/item_3728539_1/component/file_3728540/content
* Negative DNS answers
https://ispcol.potaroo.net/2026-08/nxd.html
* Telstra July 2026 outage report
https://www.telstra.com.au/content/dam/tcom/dynamic-media-projects/luke-campbell/TAP-Findings-for-Telstra-Outage.pdf
* The IRR landscape RPKI can replace
https://labs.ripe.net/author/mw/the-irr-landscape-what-rpki-can-replace/
* Unexpected IP4 TTL rewrites
https://sebastiankappes.com/papers/kappes2026ttl.pdf -
Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.
A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.
With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.
-
Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.
A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.
With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.
-
Without a ROA, your prefix announced from someone else's network looks exactly like your prefix announced from yours. A router has nothing to check it against.
A ROA names which network is allowed to originate your prefix. Anyone else announcing it is then RPKI invalid, and networks filtering on validation drop them. That is the whole reason to sign.
With isp6 it's a button on the dashboard: type your origin AS, press Add, and we publish the ROA to RIPE.
-
Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.
This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.
https://social.bgp.tools/@newaspa/statuses/01M11SXFGP5536WH52SQ0PEECF
-
Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.
This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.
https://social.bgp.tools/@newaspa/statuses/01M11SXFGP5536WH52SQ0PEECF
-
Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.
This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.
https://social.bgp.tools/@newaspa/statuses/01M11SXFGP5536WH52SQ0PEECF
-
Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.
This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.
https://social.bgp.tools/@newaspa/statuses/01M11SXFGP5536WH52SQ0PEECF
-
Approximately 3.5% of ASNs seen making #BGP announcements have created RPKI #ASPA objects.
This is a decent ramp up before the spec is even out of draft and the big iron from commercial router vendors have production code deployed for validating these (ASPA) paths from the #RPKI.
https://social.bgp.tools/@newaspa/statuses/01M11SXFGP5536WH52SQ0PEECF
-
rpki-client 9.9 has been released:
https://marc.info/?l=openbsd-announce&m=178751317654834&w=2
#rpki #bgp #OpenBSD #rpkiclient #routing #networking -
rpki-client 9.9 has been released:
https://marc.info/?l=openbsd-announce&m=178751317654834&w=2
#rpki #bgp #OpenBSD #rpkiclient #routing #networking -
rpki-client 9.9 has been released:
https://marc.info/?l=openbsd-announce&m=178751317654834&w=2
#rpki #bgp #OpenBSD #rpkiclient #routing #networking -
rpki-client 9.9 has been released:
https://marc.info/?l=openbsd-announce&m=178751317654834&w=2
#rpki #bgp #OpenBSD #rpkiclient #routing #networking -
rpki-client 9.9 has been released:
https://marc.info/?l=openbsd-announce&m=178751317654834&w=2
#rpki #bgp #OpenBSD #rpkiclient #routing #networking -
For future reference:
/usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'
-
For future reference:
/usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'
-
For future reference:
/usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'
-
For future reference:
/usr/bin/sh -c 'awk -v RS="" "/protocol static {\n\s+aspa/,/^}/" < /etc/bird-rpki/bird > /etc/bird-rpki/birdfilt'
-
Can I get ASPA validation (with Debian stable packages?)
fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
stayrtr 0.6.4 apparently doesn't either.
What now? -
Can I get ASPA validation (with Debian stable packages?)
fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
stayrtr 0.6.4 apparently doesn't either.
What now? -
Can I get ASPA validation (with Debian stable packages?)
fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
stayrtr 0.6.4 apparently doesn't either.
What now? -
Can I get ASPA validation (with Debian stable packages?)
fort-validator 1.6.6 does not seem to have it (only 1.7.0-experimental?)
stayrtr 0.6.4 apparently doesn't either.
What now? -
BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.
-
BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.
-
BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.
-
BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.
-
BGP security stack complete for AS201379: ASPA records published for upstream authorization, backed by valid RPKI ROAs and IRR objects.
-
Claudio Jeker (claudio@) has announced the release of OpenBGPD 9.2 -portable.
Release notes: https://cdn.openbsd.org/pub/OpenBSD/OpenBGPD/openbgpd-9.2-relnotes.txt
-
Claudio Jeker (claudio@) has announced the release of OpenBGPD 9.2 -portable.
Release notes: https://cdn.openbsd.org/pub/OpenBSD/OpenBGPD/openbgpd-9.2-relnotes.txt
-
Claudio Jeker (claudio@) has announced the release of OpenBGPD 9.2 -portable.
Release notes: https://cdn.openbsd.org/pub/OpenBSD/OpenBGPD/openbgpd-9.2-relnotes.txt
-
Claudio Jeker (claudio@) has announced the release of OpenBGPD 9.2 -portable.
Release notes: https://cdn.openbsd.org/pub/OpenBSD/OpenBGPD/openbgpd-9.2-relnotes.txt