Summary

  • Revision 02 of an individual Internet-Draft turns several fixed operational mandates for delegated RPKI certification authorities into registry-adjustable baselines.
  • The proposed 99.5% availability target and ten-second response time change from mandatory requirements to recommendations, while a 24-hour manifest-gap rule and other numeric details also become more flexible.
  • A single 90-day revocation proposal becomes a 60–90 day range that recognizes different APNIC and RIPE policy choices.
  • The draft is not IETF or SIDROPS policy: Datatracker records an individual draft with no stream, Area Director or formal standing.

The consequential edit is who chooses the number

A service can be required to remain reliable without a standards document fixing the same percentage everywhere. That is the distinction introduced by revision 02 of the delegated-CA operations draft, posted on 14 September.

Revision 01 said that publication points MUST exceed 99.5% availability over a 30-day period. The new text says operators SHOULD maintain high availability, offers 99.5% as an example and calls both the target and its enforcement a registry-operator policy decision. An HTTP response within ten seconds changes from MUST to SHOULD. A prohibition on manifest gaps longer than 24 hours moves from MUST NOT to SHOULD NOT, with registries allowed to choose a stricter maximum.

The official comparison shows the same pattern in audit and timing controls. Operators must still keep certificate-operation logs, but two years is now a recommended retention period subject to longer registry or legal requirements. Time synchronization remains mandatory; stratum-2 accuracy becomes recommended rather than compulsory.

These are not cosmetic substitutions. In the vocabulary of RFC 2119 and RFC 8174, a MUST describes an absolute requirement while a SHOULD permits departure when the implications are understood. Revision 02 therefore moves the selection of several operating thresholds out of the draft and into accountable local policy.

Flexibility does not remove the technical floor

The draft does not make dependable publication optional. It still requires redundant infrastructure with automatic failover, geographically diverse publication endpoints, comprehensive monitoring, validation before publication and atomic updates. Registry operators would have to monitor every delegated CA under their authority, establish clear service-level agreements, make reasonable efforts to contact an operator before revocation and document enforcement decisions.

That division is important. The publication-services BCP work already demands highly available, monitored infrastructure without supplying one universal percentage. Its revision 10 text focuses on consistency, synchronization and observable operation. Revision 02 borrows that architecture: standards can define what must be measurable and safe, while the institution responsible for a delegation chooses the number it can defend.

The draft also treats monitoring as a distributed evidence system. CA operators measure their own publication points; registries oversee all delegated CAs; validator operators can report persistent failures. A separate repository-health draft proposes observable measures such as reachability, freshness, integrity and churn. The public list of non-functional CAs and the CURE research help explain why stale or unstable publication points impose costs beyond their owner.

Metrics are not self-executing, however. Availability depends on vantage points and sampling. “Current” manifests depend on successful discovery and validation. A threshold breach still needs attribution, notice, an exception path and a decision. Automation can surface evidence; it cannot silently supply legitimacy.

Sixty days and ninety days are evidence of local choice

The clearest governance change concerns persistently non-functional CAs. Revision 01 suggested revocation after more than 90 days following contact attempts. Revision 02 proposes a 60–90 day range and cites two regional paths.

APNIC prop-166 uses 60 days without a discoverable and valid current Manifest and CRL. APNIC's public page says the proposal reached consensus at APNIC 60. RIPE proposal 2025-02 is marked accepted and uses three months, implemented as 90 days because calendar months vary. Both require reasonable discovery and notification efforts; both allow an operator to recreate a delegated CA through the normal process after revocation.

Neither number emerges from a universal law of routing security. They are institutional choices about the cost of useless validator work, the tolerance for operational failure and the time an operator should receive to recover. Revision 02 recognizes that divergence instead of disguising one regional settlement as a global technical constant.

The result can be coherent if common evidence travels with local discretion. A registry should publish which endpoints are tested, how often, from where, what counts as a valid Manifest and CRL, when the clock starts, which contacts receive notice, who authorizes escalation and how restoration works. Without that record, “adjustable” risks becoming “unreviewable.”

An individual draft is a proposal, not a mandate

The Datatracker record is explicit: anyone may submit an Internet-Draft, this one is not endorsed by the IETF, and it has no formal standing. The page classifies it as an active individual draft with no RFC stream, responsible Area Director or telechat. Its document header says “Intended status: Best Current Practice,” while Datatracker currently records no intended RFC status. The history page establishes the revision dates, not adoption.

This limitation strengthens rather than weakens the immediate news value. The change exposes a live design question before authority hardens: should a global operational document prescribe one set of numbers, or require transparent institutions to select them? It does not answer how appeals should work, what evidence standard should govern contested measurements or how cross-registry comparability will be audited.

The draft supplies its own cautions. Monitoring may reveal sensitive operational details. False reports can manipulate enforcement. Revocation must not become a denial-of-service mechanism. Public reporting must balance transparency with privacy. Those warnings make clear that threshold setting is governance built on technical evidence, not merely an uptime calculation.

Sources