Skip to main content

Topic

RPKI and Route Security

Within the Topic facet, RPKI and Route Security topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A clean cyan route crosses a transparent observation plane while an amber route appears at a separate downstream junction.

Story

The Route Was Absent. The Traffic Still Found It: APNIC 62’s BGP Neighbor Problem

A route-origin filter can leave an operator’s table clean while a downstream neighbor forwards toward the rejected destination. An APNIC 62 presentation made that uncomfortable distinction concrete. The useful response is to preserve separate evidence of received routes, local…

Sep 22, 2026
A glass test rig with four coloured status lenses ends in a gap before blank receipt tokens, while a blue production rack remains separate behind it.

Story

RIPE NCC Closed the Test API Incident. The Recovery Join Is Missing

Four status updates show a pilot service moving from investigation to resolution in 37 minutes. They do not show the small set of facts that would let a user connect that green status to a particular test operation, a checked isolation boundary and a completed reconciliation.

Sep 20, 2026
A glass projection plane shows two origin nodes above four underlying authorization paths, while one observed route reaches only one node.

Story

LACNIC’s WHOIS Shows the Origin ASNs but Not Their Authorization Boundary

LACNIC’s WHOIS Shows the Origin ASNs but Not Their Authorization Boundary intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 19, 2026
Six distinct cryptographic checkpoints cross a network map of Africa, ending in a separately observed routing signal.

Story

AFRINIC's Resource Certificate Can Be Valid Without Naming the Member

A resource certificate with a generated, apparently meaningless Common Name can be doing its job perfectly. AFRINIC’s own practice statement shows why: the public certificate proves a bounded resource authorization, while a different chain connects the request key to a…

Sep 19, 2026
Editorial illustration showing AS210837 at the center of separated evidence layers for registry identity, declared routing intent, observed BGP paths, RPKI origin validation and service continuity.

Global Regional ISP

ROYA’s AS210837: What Would Prove Operational Control and Durable Repair?

ROYA’s AS210837: What Would Prove Operational Control and Durable Repair? intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 19, 2026
Four abstract selector cells feed a path-existence gate; two continue through illuminated test chambers while two terminate at empty outlined slots.

Story

Rapport Counts Outcomes Only After a Requested Test Path Exists

LACNIC’s revised Rapport runner can expand several category and test selectors into a matrix. Yet a requested cell with no matching directory leaves no row in the result: it returns before a test identity is printed or any outcome counter moves.

Sep 15, 2026
Translucent certificate wafers move along a copper rail through a warm-lit molding press and a circular optical inspector toward an empty output tray on a dark indigo laboratory bench.

Story

Rapport’s Forbidden-AKI Test Starts at Barry, Not at the Validator

A conformance test cannot prove that a validator rejected a forbidden certificate field until it proves that the field reached the certificate. A September correction to one LACNIC Rapport fixture makes that dependency unusually visible. The change replaces a scalar value that…

Sep 14, 2026
Thirty-two linked RRDP transitions cross a retention gate above a separate snapshot fallback plate.

Story

AFRINIC's RRDP Lists 32 Deltas. That Is Not a Recovery Window.

AFRINIC's live RPKI notification showed a neat chain of 32 incremental updates. The number is useful, but it does not tell a network operator how long a validator may be offline before recovery changes from a small replay to a full snapshot.

Sep 14, 2026
Two matching ordered sets of colored provider tiles approaching a capacity gate before a consolidation stage, over a Latin American map relief.

Story

FORT’s Provider Cap Checks the Sum Before the Union

FORT’s fixed release checks the combined lengths of two provider lists before removing duplicates. The distinction is visible in code; no affected customer or router withdrawal was observed.

Sep 14, 2026
A route token meets a closed selection gate while a separate transparent diagnostic tray preserves its amber imprint.

Story

APNIC 62’s OTC Warning Is Also a Looking-Glass Problem

BIRD can stop a leaked route before ordinary filters have an entity to retain. The September warning asks for more than softer rejection: an explanation that survives without giving the route permission to travel.

Sep 14, 2026
Two abstract repository frames beside a shared translucent cache, with separate guarded download and rebuild paths over a subtle Latin American and Caribbean map.

Story

FORT’s Snapshot Patch Changes the Rebuild, Not the Meaning of a Good Hash

The published 1.6.8 fix constrains snapshot references and moves a download ahead of workspace deletion. Its cache still remembers an attempt result—a distinction that matters when signed routing evidence vanishes from a local view.

Sep 14, 2026
A segmented glass timeline passes between a signed object, an observation lens and a separate router.

Story

APNIC Will Put VRP History in REx. A Timeline Still Needs a Vantage Point

APNIC plans to show current and historical RPKI VRP information for an individual Internet number resource in REx. That could turn a specialist dataset into useful public memory. But a dated line is not self-explanatory: unless it names the observation, derivation and scope…

Sep 13, 2026
Cyan BGP paths converge on a crystalline authorization capsule while amber provider candidates remain on separate evidence planes over Europe.

Story

RIPE NCC Lets Operators Sign ASPAs Without Showing the Providers It Sees

RIPE NCC has made ASPA signing possible and tells operators to list every real upstream. Its public guide also says the Dashboard offers no BGP-derived hint about who those upstreams might be. The missing interface is not an automatic answer but an evidence receipt that helps a…

Sep 13, 2026
Blue active route fibers cross a glass inspection frame while a separate amber standby provider waits in its own chamber, joined by a small provenance token.

Story

APNIC's ASPA Interface Checks Observed Paths. A Standby Provider Leaves No Path to Check.

APNIC has built a sensible safety rail into its new ASPA interface: suggest providers from visible routing data, then show how an edit would affect paths that BGP observers can see. The awkward provider is the one hired precisely not to be visible yet. A standby link turns the…

Sep 12, 2026
A sealed software-update capsule follows a blue route beside an amber diversion while a terminal prints one blank local receipt.

Story

LACNIC’s BGP Case Counts 368 Route Peers. The Vendor Could Not Produce a Definitive Installation List.

LACNIC’s latest routing-security case is unusually rich in network evidence and unusually poor in application evidence. The route, certificate and attack window can be reconstructed in detail; the vendor still cannot say which installations accepted the malicious update. That gap…

Sep 12, 2026
Cyan route paths enter a glass selection instrument, cross into a violet validation chamber and emerge beside an ivory provenance token linked to two separate gauges.

Story

AFRINIC's Prefix Checker Can Supply the ASN From BGP. The Verdict Keeps Only the RPKI Time.

AFRINIC's Prefix Checker Can Supply the ASN From BGP. The Verdict Keeps Only the RPKI Time. intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure…

Sep 12, 2026
Four distinct record lanes—an archival holding, branching route policy, sealed authorization and live network pulse—enter a transparent decision matrix with a preserved rollback path.

Story

APNIC Will Automate Route-Record Alignment. The Roadmap Does Not Name the Conflict Winner

“Alignment” sounds like database housekeeping. In APNIC’s Q3 2026 roadmap, it means something harder: deciding how resource holdings, a route-management template, Whois route objects and RPKI authorizations should change when they disagree—and preserving enough evidence to show…

Sep 11, 2026
Layered map of Internet infrastructure authority showing separate organizational, software, root-service, registry, routing-observation and RPKI authorization surfaces with bounded remedy paths.

Global Institutional

ISC-AGP1 and the Authority Chain Behind Internet Systems Consortium’s Network Identity

ISC-AGP1 and the Authority Chain Behind Internet Systems Consortium’s Network Identity intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences…

Sep 11, 2026
Abstract global routing map showing layered network paths, registry evidence nodes, route-authorization marks and unresolved operational-footprint gaps.

Global Institutional

DFINFRA and AS210860: What Would Prove an Operating Network?

DFINFRA and AS210860: What Would Prove an Operating Network? intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Global…

Sep 11, 2026
Layered illustration of software stewardship, downstream operations, registry authorization and routing observation as distinct internet infrastructure control surfaces.

Global Institutional

Where ISC’s Control Ends—and the Evidence of Recovery Begins

Where ISC’s Control Ends—and the Evidence of Recovery Begins intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Global…

Sep 11, 2026