Summary
- ARIN opened Consultation 2026.1 on 14 August, proposing RDAP as its sole standardized directory service after independently retiring Whois-RWS, RWhois and Whois on Port 43. Comments remain open until 14 September; no retirement has been finally approved.
- The three paths are deliberately unequal: 180 days of outreach for the Whois-RWS API, a conversion-tool release followed by 365 days for RWhois, and two years for high-volume Port 43 use.
- RDAP is a complete Internet Standard with uniform HTTP queries, JSON responses and authoritative-service discovery. The unresolved issue is deployment evidence: what must ARIN observe about clients, local databases, investigation workflows and rollback before each switch is turned off.
One destination does not make one migration
The mirrored consultation notice names four current directory paths: Whois-RWS, RWhois, Whois on Port 43 and RDAP. ARIN's proposed end state is simple. RDAP becomes the one supported standardized directory service; future features such as geolocation would be added there, and duplicate software and infrastructure would no longer need maintenance.
The proposal does not pretend that the route to that end state is simple. Whois-RWS, RWhois and Port 43 are three different migration objects. They have different callers, replacement work and earliest dates. ARIN says each retirement will be completed independently even if some work overlaps.
That distinction is the strongest part of the road map. Protocol retirement is often described as a contest between an old format and a better standard. In practice it is an inventory of dependencies. A structured replacement can be technically superior and still fail a user whose installed client, parser, security workflow or reassignment database has no tested path to it.
RDAP's technical case is real. STD 95 combines standard HTTP transport, security services, uniform query syntax, JSON response structures and discovery of the authoritative server. These are material improvements over free-form text parsing.
But a standard describes how a compatible implementation should work. It does not enumerate every script that still invokes whois, every analyst who expects its terse output or every organization serving reassignment data through RWhois. ARIN therefore needs three completion tests, not one declaration that RDAP is ready.
Whois-RWS can expose its own callers
The Whois-RWS API has the shortest proposed path. ARIN considers its function equivalent to RDAP and proposes a 180-day customer-outreach programme. Responses would carry a retirement notice, while announcements and direct communication would tell users to migrate. The proposed retirement is on or after 1 July 2027.
This channel has an advantage: the service can speak to active callers. A payload notice reaches the path that must change, and request telemetry can show whether old traffic declines. That makes the transition measurable without identifying individual users publicly. ARIN could report aggregate query volume, distinct authenticated customers where applicable, error patterns and the share of calls that continue after successive notices.
The web interface is a different product even though it shares a name. ARIN proposes keeping it until RDAP provides equivalent query capabilities, then changing the implementation behind the familiar URL and giving at least 30 days' notice. For an occasional human user, preserving the interface may make the protocol change invisible.
The readiness question is therefore narrower than “does RDAP work?” The API needs evidence that active callers have moved or received a documented exception. The web service needs a public parity checklist covering the searches people actually perform. A calendar can start outreach; it cannot prove either condition by itself.
RWhois cannot retire before its replacement exists
RWhois reverses the sequence. Some organizations use local servers to publish reassignment information. ARIN proposes recommending an open-source RDAP server and providing a conversion tool that can populate it from existing RWhois data. Only when that tool is available would the 365-day sunset begin. Retirement would be no earlier than 1 January 2028.
This dependency is explicit and useful. It prevents the notice period from being consumed while affected organizations are still waiting for the migration mechanism. It also creates a testable object: the tool can be released, versioned, exercised against representative data and corrected before any server is considered ready to disappear.
Tool availability is only the first gate. Conversion must preserve the meaning and discoverability of reassignment records, not merely copy strings into another format. Operators need to know how referrals change, how failures are detected, how updates are synchronized during transition and whether they can roll back without losing newer data.
The public evidence could be modest: number of known RWhois operators contacted, number that tested conversion, classes of rejected record, unresolved parity defects and a dated stable release. Confidential customer data need not be exposed. The objective is to distinguish “a tool was published” from “the affected directory function survived migration.”
Port 43 contains the hidden tail
Port 43 receives the longest proposal: two years, with retirement on or after 1 January 2029. ARIN says the service still carries high query volume and is used by cybersecurity professionals, researchers, law enforcement and others beyond the immediate registry community.
Those users are difficult to count because low-friction access is part of the service's value. A person can issue an occasional command without an account. A vendor can embed a lookup inside a product. An old investigation script can run for years without telling ARIN who maintains it. Query volume measures activity but not the number or criticality of distinct dependencies.
The NANOG discussion exposes both sides. One operator set out a six-link adoption chain: notify client developers, obtain releases, get those releases into operating-system distributions, reach users, deliver equivalent tools and allow them to become ubiquitous. Another participant described the opposite experience: RDAP scripts are simpler because they use HTTPS, JSON and IANA bootstrap files rather than ad hoc text parsing.
Neither message measures the whole installed base. Together they define the right test. ARIN should not assume unreadiness because Whois is old, or readiness because RDAP is well designed. It should instrument the transition: place machine-readable notices in results, publish a maintained client guide, test common operating systems and security tools, observe residual traffic and open a documented exception path for dependencies that cannot move on schedule.
Retirement needs a proof standard and a return path
The proposed dates are all qualified. “On or after” leaves room for evidence to decide. ARIN should use that room explicitly by publishing a short readiness record for each service: replacement capability, outreach completed, adoption trend, unresolved blockers, decision authority, notice date, rollback window and the evidence that permits closure.
Lu Heng's Bill of Rights of Uniqueness Coordination makes operational continuity a boundary on registry administration. Applied here, the point is not that an old protocol must live forever. It is that access to the shared record should not become hostage to an institutional timetable when a measurable migration is available.
His Multi-Stakeholder Mirage proposes an order for transitions: visibility first, continuity next, coordinated protection next, then a thinner architecture. Consultation supplies participation, but participation alone does not prove that dependent systems are ready. Observable state does.
At the research cutoff, the consultation was open. No final dates, RWhois tool release, complete client inventory, parity score or rollback rule had been published. The destination is nevertheless clearer than the gate. RDAP can be the one protocol without requiring one unmeasured leap. The quality of ARIN's plan will be decided by whether each of the three exits closes on evidence rather than elapsed time.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
