AFRINIC · RIR Watchdog
AFPUB-2019-GEN-006-DRAFT03
Start here for the proposal-by-proposal record: what changed, why it mattered, who argued for what, how positions evolved, what was decided, and where the evidence still has gaps.
Source facts
- Policy ID
- AFPUB-2019-GEN-006-DRAFT03
- RIR
- AFRINIC
- Official status
- Ratified
- Normalized status
- Accepted
- Introduced
- Apr 19, 2021
- Last source update
- Oct 11, 2026
- Coverage
- Partial
Who actually shaped the debate?
Policy evolution
Trust anchor named in the explanation · Draft 2 corrects the explanation of AFRINIC's bogon ROAs to name AFRINIC's TAL instead of APNIC's. This corrects the stated validation context; it does not direct AFRINIC to issue ROAs under APNIC's trust anchor.
Source facts −
When AFRINIC issues a ROA with AS0 for unallocated address space under AFRINIC’s administration, BGP announcements covering this space will be marked as Invalid by networks doing RPKI based BGP Origin Validation using APNIC’s TAL.Source facts ↗
Source facts +
When AFRINIC issues a ROA with AS0 for unallocated address space under AFRINIC’s administration, BGP announcements covering this space will be marked as Invalid by networks doing RPKI based BGP Origin Validation using AFRINIC’s TAL.Source facts ↗
Separate trust anchor option · Draft 2 adds the option of a distinct TAL for AS0 ROAs, allowing opt-in use and separate measurements, particularly during initial deployment. The choice and other operational details remain at AFRINIC's discretion. The requirement to remove AS0 ROAs before allocating covered resources remains unchanged.
Source facts −
Address space can only be allocated once the ROA or ROAs with origin AS0 have been fully removed and are not visible in the repositories.Source facts ↗
Source facts +
The AS0 ROAs could be under a distinct Trust Anchor Locator (TAL), so it becomes an opt-in service and provides separate measurements, at least in the initial deployment phases. This and other operational details are left to the discretion of AFRINIC.Source facts ↗
Staff interpretation of covered resources · The draft-2 snapshot adds a staff interpretation that unallocated and unassigned space includes available and reserved inventory, newly received IANA/PTI prefixes, and returned or reclaimed resources. This elaborates the existing coverage rule in a staff assessment; it is not a separate adopted policy clause.
Source facts −
AFRINIC will create ROAs with origin AS0 for all the unallocated and unassigned address space (IPv4 and IPv6) for which it is the current administrator.Source facts ↗
Source facts +
unallocated and unassigned space here means available and reserved space as per the AFRINIC extended delegated stats file. New prefixes received from IANA/PTI would immediately have AS0 ROA's. Any prefixes returned by or reclaimed from members will also have AS0 ROAsSource facts ↗
Staff assessment of ROA validity · New staff assessment text assumes a ten-year validity period unless proposal authors specify another period. The proposal itself continues to leave validity and revocation procedures to AFRINIC staff, and the assessment also asks for clarification. The ten-year assumption is not presented as a new binding policy duration.
Source facts −
The process for ROA validity periods and release of ROAs before assignment/allocation by AFRINIC is left for AFRINIC staff to define in internal procedures.Source facts ↗
Source facts +
The validity period for these ROAs shall be 10 years (as it currently is for all ROAs) unless a specific validity period is specified by the policy proposal authors.Source facts ↗
Staff deployment recommendation · The added staff assessment recommends a separate trust anchor and estimates implementation within six months of Last Call. These are the staff's historical recommendation and estimate, not evidence that deployment occurred.
Source facts −
The process for ROA validity periods and release of ROAs before assignment/allocation by AFRINIC is left for AFRINIC staff to define in internal procedures.Source facts ↗
Source facts +
Impact on RPKI On the RPKI side, 3 options have been scoped notably, Use the existing AFRINIC RPKI Tree Additional Production certificate (0/0) for unallocated space only New Trust Anchor with a single Production Certificate AFRINIC recommends option C because it then becomes an opt-in service and does not pollute the current RPKI. Legal Assessment No comments 5.0 Implementation Timeline The policy can be implemented as written within 6 months from the Last Call.Source facts ↗
Cross-registry context · The references change from APNIC consensus, a RIPE NCC proposal and intended submissions elsewhere to reported consensus in APNIC and LACNIC. This updates the proposal's historical context and does not establish any other registry's present policy.
Source facts −
4.0 References An equivalent proposal has already reached consensus in APNIC (https:// www.apnic.net/community/policy/proposals/prop-132) )and has been proposed in RIPE NCC (https:// www.ripe.net/participate/policies/proposals/2019-08). )It is also in preparation for submission to the other RIRs.Source facts ↗
Source facts +
4.0 References An equivalent proposal has already reached consensus in APNIC and LACNIC.Source facts ↗
Timing for reclaimed resources · Draft 3 adds an explicit condition that reclaimed resources enter the AS0 ROA coverage only at the end of the reclamation process. Draft 2 required coverage of all unallocated and unassigned resources without this explicit timing qualification. The separate-trust-anchor option and removal of ROAs before allocation remain.
Source facts −
AFRINIC will create ROAs with origin AS0 for all the unallocated and unassigned address space (IPv4 and IPv6) for which it is the current administrator.Source facts ↗
Source facts +
AFRINIC should add reclaimed resources only at the end of the reclamation process.Source facts ↗
Staff choice of deployment architecture · The draft-3 staff implementation section commits to a new separate trust anchor if the proposal reaches consensus and ratification; draft 2 only recommends that option among three alternatives. This is the documented implementation plan, not proof of an operational deployment.
Source facts −
AFRINIC recommends option C because it then becomes an opt-in service and does not pollute the current RPKI.Source facts ↗
Source facts +
5.0 Implementation Should this proposal reaches consensus and is ratified, the implementation will be done on a new (separate) Trust Anchor so that it becomes an opt-in service and does not impact the current RPKI setupSource facts ↗
Historical implementation estimate · The staff estimate changes from six months after Last Call to implementation by Q2 2022, linked in the surrounding text to the planned myafrinic v2 migration. These are historical planning statements; neither establishes the present deployment status or a new current deadline.
Source facts −
5.0 Implementation Timeline The policy can be implemented as written within 6 months from the Last Call.Source facts ↗
Source facts +
We have been advised that the policy can be fully implemented by Q2-2022.Source facts ↗
Staff clarification status · The draft-3 assessment records no clarification requests where draft 2 asks about the AS0 ROA validity period. Both assessments retain the ten-year assumption unless authors specify otherwise, so this change does not itself alter the duration.
Source facts −
3.0 AFRINIC Staff Clarification Requests What will be the validity period of these AS0 ROAs? 10 years?Source facts ↗
Recorded proposal status · The draft-2 snapshot is marked Archived and the draft-3 snapshot Ratified. These are captured page labels, not proof of the date of ratification or implementation; draft 3's implementation table still describes the policy as awaiting implementation.
Source facts −
Date Submitted 2020-08-03 Author(s) Refer to Proposal Tab Status ArchivedSource facts ↗
Source facts +
Date Submitted 19 April 2021 Author(s) Haitham El-Nakhal, Yazid Akanho Version 3 Obsoletes None Status RatifiedSource facts ↗
Debate timeline
Entities
- Discussion messages0First activityUnknownLast activityUnknownFirst explicit stanceUnknownLatest explicit stanceUnknownStance changes0Viewpoint consistencyNo explicit position statedOther policies0
- Discussion messages0First activityUnknownLast activityUnknownFirst explicit stanceUnknownLatest explicit stanceUnknownStance changes0Viewpoint consistencyNo explicit position statedOther policies0
Sources and coverage
Official policy sources
Public discussion archives
- afrinic-rpd
- Earliest captured
- Aug 4, 2004
- Latest captured
- Aug 25, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 13,116
- Known gaps
- 0
- www.afrinic.net
- afrinic-africann
- Earliest captured
- Aug 3, 2026
- Latest captured
- Oct 2, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 2,556
- Known gaps
- 0
- afrinic-afripv6-discuss
- Earliest captured
- Aug 17, 2015
- Latest captured
- Sep 18, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 2,538
- Known gaps
- 0
- afrinic-announce
- Earliest captured
- Aug 18, 2015
- Latest captured
- Sep 18, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 2,497
- Known gaps
- 0
- afrinic-community-discuss
- Earliest captured
- Sep 11, 2015
- Latest captured
- Dec 29, 2019
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 3,127
- Known gaps
- 0
- afrinic-dbwg
- Earliest captured
- Aug 4, 2026
- Latest captured
- Oct 6, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 905
- Known gaps
- 0
- afrinic-dnssec-ops
- Earliest captured
- Aug 18, 2015
- Latest captured
- Dec 1, 2016
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 307
- Known gaps
- 0
- afrinic-icp2-review
- Earliest captured
- Apr 10, 2025
- Latest captured
- Nov 10, 2025
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 0
- Known gaps
- 0
- afrinic-measurement-wg
- Earliest captured
- Feb 1, 2018
- Latest captured
- Nov 22, 2024
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 138
- Known gaps
- 0
- afrinic-mira
- Earliest captured
- Nov 17, 2020
- Latest captured
- Nov 22, 2024
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 0
- Known gaps
- 0
- afrinic-ois-wg
- Earliest captured
- Sep 9, 2021
- Latest captured
- Nov 22, 2024
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 0
- Known gaps
- 0
- afrinic-rpki-discuss
- Earliest captured
- Jan 15, 2016
- Latest captured
- Apr 23, 2026
- Last refresh
- Oct 11, 2026
- Coverage
- Source coverage is incomplete.
- Loading
- 154
- Known gaps
- 0
Coverage
Partial
Earliest captured: Aug 4, 2004
Latest captured: Oct 11, 2026
Freshness
Known gaps
- www.afrinic.net: Source coverage is incomplete. · The source boundary has not yet been reached.
- www.afrinic.net: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-rpd: Source coverage is incomplete. · The source boundary has not yet been reached.
- www.afrinic.net: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-africann: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-afripv6-discuss: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-announce: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-community-discuss: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-dbwg: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-dnssec-ops: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-measurement-wg: Source coverage is incomplete. · The source boundary has not yet been reached.
- afrinic-rpki-discuss: Source coverage is incomplete. · The source boundary has not yet been reached.
