Skip to main content

Topic

RPKI and Route Security

Within the Topic facet, RPKI and Route Security topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

IETF

BGP Roles Turn a Peering Relationship into a Route-Leak Boundary

Before two networks exchange a single route, each can state what kind of neighbour it believes it has. RFC 9234 turns that bilateral statement into a control: incompatible roles can stop the session, while the Only-to-Customer attribute can stop a marked route from crossing the…

Sep 3, 2026
An evidence ledger connects npNOG workshop records to completed, partial and unresolved operational-outcome cards in a network operations room.

NPNOG

A decade of meetings, but where is the outcome ledger? Auditing npNOG’s institutional value

npNOG can document that it kept opening the room. Its public chronology runs from the first numbered meeting in 2016 to npNOG-11 in 2025, with a virtual programme in 2020. The archive shows workshops, conferences, fellows, committees and technical subjects. That is not trivial…

Sep 2, 2026
Two separated abstract routing-evidence structures: cobalt prefix-origin paths and an amber customer-cone relationship tree.

Story

RIPE’s IRR Study Says RPKI Can Replace a Route Object, Not a Customer Cone

A new RIPE Labs study makes a useful distinction that is easy to lose in general talk about replacing the IRR. A prefix–origin record and the policy information used to discover a customer cone are not the same operational entity, so they cannot share one retirement decision.

Sep 1, 2026
Fibre-connected network racks behind glass at blue hour, representing visible exchange infrastructure rather than an outcome measurement.

Story

AFRINIC Says Douala-IX Strengthens Local Exchange. Its Public Snapshot Does Not Yet Measure It.

AFRINIC’s March community bulletin frames its support for Douala-IX as a way to strengthen local interconnection in Cameroon. The public evidence now available is useful, but it is an inventory of exchange attributes—not a measurement of the claimed operational result.

Sep 1, 2026
A translucent identity disc connects through an amber gate around a small resource cluster to two cyan ROA state layers, while dim blocks remain outside the gate.

Story

RIPE’s RPKI Key Plan Is Not Yet a ROA Scope Receipt

RIPE NCC’s plan to move RPKI API keys toward OpenID Connect is a statement about a future access mechanism. It is not yet a public way to reconstruct which resource authority and which state-changing action stood behind an individual ROA change.

Aug 31, 2026
Three separate cyan, amber, and magenta-green evidence channels cross a dark-blue relief surface toward three neutral gates.

Story

LACNIC’s Bogon Guide Has Three Different Data Clocks.

A BGP filter can reject a route without saying why that route was rejected. Treating every rejected route as one security statistic may be convenient for capacity reporting, but it is too coarse to explain what the underlying evidence meant at the moment of the decision.

Aug 31, 2026
Four small gold record cards cross a dark-blue circular ledger toward a blank upright receipt panel, joined by cyan paths.

Story

APNIC Reissued Four Expired ASPAs. Its Repair Needs a State Receipt.

APNIC has reported a bounded correction: automatic renewal did not run, four ASPA entities expired, and the entities were reissued and published at 11:03. That is useful operational disclosure. It is not yet a measurement of what every repository, validator, router or customer…

Aug 31, 2026
A luminous reader path remains open beside a separate amber queue for authoritative updates and a reconciliation return path.

Story

ARIN Kept Five Services Running Without Updates. Its Service-Level Report Has No Freshness Column

A registry can answer a question and still have nothing new to say. ARIN's planned July maintenance made that distinction visible: five reader-facing services remained operational while updates were not being published. The public service-level report measures availability well…

Aug 31, 2026
An archive passes an empty glass verification cradle into a compiler while its detached signature foil and public-key ring remain beside the release platform.

Story

LACNIC’s FORT Guide Skips the Signature Published Beside Its Tarball

The guide checks the validator after installation. It never checks the archive before extraction, even though the release already offered a digest, a detached signature and a public keyring.

Aug 31, 2026
Two glass inspection frames examine one registry process: policy tickets on one side and layered system controls on the other, beneath an unfinished control layer.

Story

ARIN's Two Audit Findings Sound Opposite. They Test Different Controls

One ARIN Board record says no audited ticket was out of policy; another says inconsistencies appeared in every area examined. The difference is not a proven reversal in performance. It is a warning that audit findings become misleading when the test, standard and denominator are…

Aug 31, 2026
An editorial workbench contrasts one individually slotted route-authorization tile with a removable tray holding an entire interconnected set, against a subtle map of Latin America and the Caribbean.

Story

LACNIC Calls Postman Its Current API. The Website Still Says ROAs Change by Serial Number

LACNIC gives an API operator two public descriptions of the same control surface. Its Registration API page says Postman holds the most current v3 documentation, while the route table beside that instruction describes modifying or removing one ROA by `serialNumber`. Follow the…

Aug 31, 2026
An authoritative repository core feeds a smaller mirror connected to five amber expiry chambers and three cyan performance gauges.

Story

APNIC Called RPKI Mirroring Marginal. Its NNIX Pilot Tests a Different Benefit

In October 2025, APNIC assessed a repository mirror as a short-lived aid during a long outage and called the benefit very marginal. Seven months later, its agreement with NNIX proposed a Hangzhou mirror pilot around latency, validation speed and data availability. The…

Aug 30, 2026
An open policy binder places a cyan Africa and Indian Ocean overlay beside an amber Asia-Pacific overlay, with a red correction line pointing to clause V.8.

Story

AFRINIC's Current RPKI CPS Says It Manages Asia-Pacific

The Certification Practice Statement linked from AFRINIC's current resource-certification page is version 3.0 from May 2020. In its CA-termination clause, the registry assigns itself the Asia-Pacific region. AFRINIC and IANA assign that region to APNIC and place AFRINIC in Africa…

Aug 30, 2026
Ordered address-object tiles send geofeed connections through an amber side channel beside an empty schema socket.

Story

AFRINIC Has 3,573 Address Entities Pointing to Geofeeds. Its Schema Still Has No Geofeed Field

AFRINIC’s public database already carries geofeed pointers at material scale, but it carries them as prose. The fallback is valid and useful. The missing question is whether a convention used by thousands of address records should remain a string that the schema cannot identify…

Aug 30, 2026
One routing-security operation branches into two linked record trails, with a complete event sequence on one rail and a sparse history on the other.

Story

ARIN Links ROAs to IRR Objects. Only the ROA Side Has a Visible Action Log

ARIN has made it possible for one routing-security action to leave two related records. That convenience is real. The evidentiary problem begins when the records later separate: the documented public history can explain the ROA, but not yet the whole operation that created…

Aug 30, 2026
Editorial illustration of the SeaTelecom wordmark beside fibre-routing equipment, with route visibility and authorization accountability shown as separate layers.

Europe and Middle East Regional ISP Trends

SeaExpress’s AS31444 makes route visibility easier than route-authorisation accountability

SeaExpress’s AS31444 makes route visibility easier than route-authorisation accountability intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure…

Aug 30, 2026
Versioned ROA authorization flows through independent validators to route activation, with an orange withdrawal path returning to the prior state

Number Resource Society

A ROA Change Needs an Authorization-and-Withdrawal Ledger

A route can be Valid while the organization behind it has already forgotten who approved the authorization, what changed, or how to reverse it. ROA governance needs evidence that joins intent, publication, observation and withdrawal—not another screenshot of a green status.

Aug 30, 2026
Editorial infrastructure model with one eight-segment clock above a switching device and six distinct operation paths ending at independent state checkpoints.

Story

APNIC's Firewall Reboot Put Registry Writes and Repository Reads Under One Clock

APNIC says a network firewall detected a hardware fault and rebooted on 28 August, interrupting six named service surfaces for an incident window of eight minutes. The short duration is reassuring. The single clock is not a complete recovery statement, because the list stretches…

Aug 30, 2026
Editorial illustration of signed RPKI materials passing through a protected publication engine into synchronized repository mirrors, with a separate row of recovery and evidence checkpoints.

IETF

RPKI’s Publication BCP Can Say MUST. Operators Still Need to Show What They Do

The IETF is reviewing a Best Current Practice for the machinery that carries signed routing intentions from certificate authorities to the repositories used by relying parties. Its capitalized rules are deliberately strong. Its own text also says they are not formal…

Aug 29, 2026
Multiple routing-authority change tokens converge through one atomic transaction into a single durable signal reaching an independent network observer.

Story

ARIN’s ROA Alerts Follow Deletion, Not the Change in Routing Authority

ARIN can commit several routing authorizations in one transaction, yet its documented alert boundary still follows a single verb: delete. Two public suggestions expose the resulting choice between inbox noise and silence. A safer design would report the net change once.

Aug 29, 2026