Summary
- AFRINIC staff reported that tests took about five minutes to revoke AS0 objects, but removal at the publisher was only the beginning of a distributed correction, not proof that repositories, validators, routers and customers recovered within five minutes.
- The only proved change from Draft 1 to Draft 2 was the option to put the registry-generated AS0 objects under a distinct Trust Anchor Locator. That made ingestion voluntary and separate measurement possible, at least initially, while leaving essential operational choices to AFRINIC.
- The proposal’s strongest case was real: a correctly scoped, separately selectable AS0 feed could offer authenticated evidence about inventory not expected to have a normal route origin without forcing any network to use it.
- Its unresolved weakness was error recovery. Scope, validity, emergency challenge, withdrawal evidence, distributed convergence and responsibility needed a public operating contract, while every relying network retained the choice to monitor, de-prefer, reject or ignore the resulting validation state.
The five-minute test and the longer clock
Five minutes is an attractive operational number. It is short enough to remember, concrete enough to repeat and reassuring enough to stand in for a system that appears responsive. At AFRINIC-32, staff reported tests in which AS0 objects took about five minutes to revoke before issuance. Yet the same meeting record contains the reason that number must be handled carefully: publishing or revoking an object is only one step, and other factors affect what observers see. The test described an operation near the source.
It did not establish that every repository, validator, cache, router or affected customer would observe the corrected state within the same interval.
That distinction is the centre of AFPUB-2019-GEN-006-DRAFT02, published on 30 July 2020, even though it is not the largest-looking feature in the text. Draft 2’s proved redline against Draft 1 was labelled “Distinct TAL”. The registry-generated AS0 objects could be placed beneath a separate Trust Anchor Locator, making the special service opt-in and separately measurable, at least during initial deployment. The proposal left that choice, alongside other operational details, to AFRINIC. It did not replace the earlier issuance and withdrawal mechanics with a new system. It put a switch and a measuring boundary around them.
The switch mattered. Without a distinct trust anchor, an operator’s decision to receive ordinary holder-issued RPKI information could be entangled with a decision to receive a special class of objects generated from AFRINIC’s own inventory records. With separation, a network could choose the ordinary trust material without necessarily ingesting this registry-generated AS0 class. Another network could take both. A third could ingest the distinct feed for observation but decline to make routing policy depend on it. Those are materially different positions, and the difference belongs to the operator rather than the registry.
The measuring boundary mattered too. If the AS0 objects could be observed apart from ordinary holder authorisations, researchers and operators could ask specific questions about that class: when was an object issued, what inventory state justified it, when was it withdrawn, and when did different observation points cease to see it? Separate measurement would not guarantee accuracy, but it could make accuracy and withdrawal performance more inspectable. A service that can be isolated is easier to test than one whose effects are mixed into the larger stream of routine authorisations.
The underlying signal is straightforward in concept. An AS0 ROA says that the covered prefix and its more-specifics should not be used in routing. Route-origin validation then produces technical states that a relying network can incorporate into its own decision process. The signed object is evidence generated from registry state. It is not a command to a router, a legal conclusion about a holder, or a confiscation of address space. AFRINIC’s ability to sign for inventory recorded as unallocated inside its service is exclusive technical and administrative control over that registry function.
It is not public authority over a prefix, an operator, a customer or the Internet.
That limit is not semantic decoration. It locates responsibility correctly. AFRINIC can maintain a record, produce signed security metadata, withdraw it and publish evidence about the performance of those acts. It cannot dictate how a network reacts. One operator might use the result only to raise an alert. Another might lower preference for a route. Another might reject a route. Another might take no routing action at all. The same signed object can therefore lead to different operational outcomes, because the last decision remains local.
The proposed issuance surface was nevertheless substantial. Draft 1 had already proposed AFRINIC-created AS0 ROAs for all unallocated and unassigned IPv4 and IPv6 space under its administration. It also allowed a holder to create AS0 objects for resources under that holder’s own account. Before AFRINIC allocated covered space, the registry-generated object had to be revoked and cease to be visible in repositories. Draft 2 preserved that basic construction. It did not newly invent AS0 issuance, the holder option or the pre-allocation withdrawal requirement.
AFRINIC staff’s assessment of Draft 2 made the contemplated inventory flow more concrete. Available and reserved IPv4 and IPv6 space would fall within the automatic registry issuance scope. New prefixes received from IANA or PTI would receive AS0 objects immediately. Returned or reclaimed prefixes would also receive them under the staff interpretation. Already allocated member resources were outside the automatic registry scope, though holders could create their own AS0 objects for resources under their accounts. Before allocation or assignment, covering objects had to be revoked and no longer visible in repositories.
Each step presents a point where correct timing matters. The inventory record must correctly describe the space. Issuance must cover what the service says it covers and exclude what it says it excludes. A newly received block must enter the intended state. A return or reclamation must be represented accurately. A block approaching allocation must leave AS0 coverage before the allocation or assignment proceeds. The repository must stop presenting the withdrawn object. Downstream systems must obtain the new view. The operator must interpret the resulting validation information according to its policy.
The five-minute test touches only part of that chain. It says something useful about AFRINIC’s tested ability to perform publication or revocation. It says nothing universal about how often every repository is consulted, how validators refresh, how caches retain previous material, how routing systems receive updated validation state, or how quickly an operator changes a decision. Even the word “visible” requires a vantage point. Not visible where, checked by whom, at what timestamp and under what refresh conditions? A publisher can complete its own withdrawal while a distant relying party still sees an older state.
The consequence of that gap is not necessarily an outage. The evidence does not establish an affected prefix, a rejected route, a holder loss or any production event. The consequence is instead a risk structure. If a registry record is wrong or a withdrawal is late, a legitimate origin can appear Invalid to a relying network that has chosen the distinct TAL. What happens next depends on that network’s policy. The error might generate a dashboard warning and nothing more. It might cause de-preference. It might lead to rejection. Different networks could make different choices, and their views could update at different times.
For a customer or operator, those differences create costs even before severe harm occurs. Troubleshooting becomes harder when one network sees a corrected state and another retains an older one. Staff may have to compare registry records, repository views, validator outputs and router behaviour. Transit and support teams may need to explain why reachability differs by path or relying party. A customer who does not control AFRINIC’s inventory record or the refresh interval of remote validators can still bear the burden of diagnosing the discrepancy.
LARUS’s focus on infrastructure continuity is useful here: a small error at a coordination layer can become an operational expense elsewhere, precisely because the people paying the cost do not control all the clocks.
The distinct TAL reduces one part of this exposure. A network can decline to ingest the special feed. It can also begin with monitoring rather than a stronger routing response. If problems appear, an operator has a clean conceptual exit: stop relying on that separate trust anchor while continuing to use ordinary holder authorisations. This is a genuine restraint on the service’s reach. It makes replacement or withdrawal of reliance more practical than it would be if the registry-generated class were inseparable from the rest.
But an exit switch is not a correction system. It protects the relying operator’s freedom; it does not establish that AFRINIC’s source record is accurate, that an affected party can challenge it quickly, that the publisher will authenticate the challenge, or that the withdrawn state has propagated. Nor does opt-in adoption answer how losses or customer disruption would be handled. Draft 2 left validity and release procedures to internal staff processes. Its text did not supply a complete public account of the distinct TAL’s default, rollout, measurement definition, emergency contact, correction objective or distributed observation.
This is where NRS’s role becomes relevant without turning NRS into another centre of control. Independent member-side scrutiny can compare the claimed inventory state with the signed objects and the views visible from multiple points. It can press for a correction channel that members can inspect, help operators preserve exit and redundancy, and document discrepancies. NRS is not an allocator, signer, regulator or route authority. Its value lies in making the coordination service contestable and observable from outside the institution that publishes the object.
BTW’s reality-first method sets a parallel discipline. The broad argument over whether AS0 ROAs serve conservation or pre-emptive denial already exists elsewhere and is not the question here. The narrower question is what Draft 2 actually changed and what that change can prove. It proves a possible separate trust anchor, an opt-in design and a basis for separate measurement. It does not prove deployment, adoption, a production object, an incident or a benefit. Keeping those limits visible is not timidity. It is what prevents a useful design option from being inflated into a claim about outcomes that were never demonstrated.
The first reading of Draft 2 should therefore be balanced. The proposal acquired a meaningful brake: networks did not have to accept the registry-generated AS0 class merely because they wanted ordinary RPKI material, and observers gained the possibility of measuring this service separately. Yet the proposal still relied on a withdrawal model whose most memorable number described the publisher’s test, not the distributed system’s recovery. Five minutes may be the beginning of the clock. It is not, on this record, the end.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
