Re: RPKI and offline routes

2016-06-14 Thread Jakob Heitz (jheitz)
ASN 0 is used for this purpose. Look for the word "zero" in https://tools.ietf.org/html/rfc6907 Thanks, Jakob. > Date: Mon, 13 Jun 2016 17:53:45 -0500 (Central Sommerzeit) > From: Matthias Waehlisch > To: Theodore Baschak > Cc: NANOG Operators' Group > Subjec

Re: RPKI and offline routes

2016-06-14 Thread Matthias Waehlisch
Hi, yes. In this context the discussion at IETF92 might be interesting: https://www.ietf.org/proceedings/92/minutes/minutes-92-sidr (search for "Extemporaneous Presentation") Cheers matthias On Tue, 14 Jun 2016, Hugo Slabbert wrote: > > On Mon 2016-Jun-13 17:53:45 -0500, Matthias Wae

Re: RPKI and offline routes

2016-06-14 Thread Hugo Slabbert
On Mon 2016-Jun-13 17:53:45 -0500, Matthias Waehlisch wrote: Hi, the creation of a ROA does not require the announcement of the prefix. Creation of a ROA, prefix announcement, and validation of the prefix are decoupled. If you are the legitimate resource holder you can create a ROA for this

Re: RPKI and offline routes

2016-06-13 Thread Matthias Waehlisch
Hi, the creation of a ROA does not require the announcement of the prefix. Creation of a ROA, prefix announcement, and validation of the prefix are decoupled. If you are the legitimate resource holder you can create a ROA for this prefix (even if you don't advertise the prefix). As soon as t

RPKI and offline routes

2016-06-13 Thread Theodore Baschak
Can RPKI be used with routes that are not being advertised at the moment? As in to sign a route that *could* be there, but is not there presently. There's been several BGP hijacks that I've followed closely that involved hijacking IP space as well as the ASN that would normally originate it. I'm