RPKI

Route origin validation, without the machinery.

Most networks that should sign their routes do not, because the software wants a server, a repository and a maintenance plan. We run those. You keep the certificate authority and the decisions; the parts nobody wants to operate are ours.

01

What you get

A CA under your RIR

Delegated, not shared.

  • Your own certificate authority
  • Delegated from RIPE or another RIR
  • ROAs you create and revoke yourself

A published repository

RRDP and rsync, kept up.

  • Published continuously
  • Mirrored to the anycast network
  • Nothing for you to keep online

RTR for your routers

One endpoint, every VRP.

  • RTR over the anycast address
  • Validated set from the global repositories
  • Works with the routers you already have
02

Questions

Do I need my own address space?

For a CA, yes — a ROA says which AS may originate a prefix, so the prefix has to be yours. The RTR endpoint is useful to anyone with routers, whether or not they hold address space.

Can I leave later?

Yes. The CA is delegated to you from your RIR; moving it elsewhere, or taking it in-house, is a change at the RIR and does not need our cooperation.