Summary
- RFC 8805 describes self-published, coarse IP-prefix location data and allows consumers to treat it as a hint rather than a verdict.
- RFC 9632 can bind a signed file to authority over the covered address space, but that validation does not establish physical location accuracy.
- A credible correction record joins the signed feed revision to consumer fetch, activation, overlap resolution and an observed service result.
The signature passes while the map stays wrong
An operator moves a prefix from one city to another, updates its geofeed and adds the optional RPKI authenticator. Validation succeeds. Days later, customers still see the old city in a streaming catalogue, fraud check or content-delivery choice.
Nothing in that sequence makes the signature useless. It proves a different fact. RFC 9632 uses the RPKI to authenticate that the signer is authorized for the covered address space and that the canonical file bytes match the signature. HTTPS can protect the retrieval channel, but the RFC explicitly distinguishes WebPKI endpoint authentication from authority over IP resources.
Location is another layer. RFC 8805 defines a simple CSV mapping from a prefix to country, region and city fields. The format is deliberately coarse. It says consumers may treat the feed as a hint, may prefer other sources, should verify publisher authority and should, where practical, verify locality accuracy. A cryptographic check cannot observe where routers, users or services actually sit.
Discovery, authority and consumption are different events
RFC 9632 lets an RPSL inetnum: object point to a geofeed. Its optional signature adds strong resource-authority evidence, but consumers still choose when to fetch, how to resolve the most-specific entry, whether to merge other datasets and when to activate a revision. The document discourages frequent real-time lookups, so cache age is an operating fact, not an implementation accident.
A signed file may therefore be accurate and still absent from a consumer's active database. A consumer may hold newer bytes but prefer another signal. Overlapping prefixes may resolve differently than the publisher expected. An unsigned third-party aggregation can also introduce a separate trust boundary.
The useful investigation traces one prefix across the canonical feed hash, signature and certificate coverage, the discovering inetnum: object, fetch time and cache policy, parser result, overlap decision, consumer dataset version, activated location and external observations. “Signature valid” closes only the authentication step.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

