Summary
- A lab operator reported that a manual publishing attempt did not change Routinator's rejection after a shutdown of about four days.
- The public exchange ends with questions about logs and machine time, not a diagnosis or a verified fix.
The consequential update came after the first proposed remedy. On September 8, a participant in the NLnet Labs Community said that running krillc bulk publish for parent and child certification authorities had left Routinator showing the same result. Services had already been running for hours. The responder then asked about Krill logs and the machine's clock. The inspected thread contains no confirmed recovery. Community discussion.
This is a laboratory account, not evidence of a production outage. The initial post, dated September 7, describes roughly four days offline. Its pasted September 5 log reports an expired manifest certificate and no valid manifest. Post time and log time are different; neither establishes a universal four-day failure threshold. The operator also reported recent exchanges and green indicators in Krill's parent and repository sections.
The narrow news is that the attempted action did not close the reported problem. There is not enough evidence to decide whether fresh material was issued, which material the validator subsequently saw, or whether clock error mattered. A request to check time is an investigative question, not proof that time was wrong.
The documentation explains why elapsed time belongs in the investigation. A manifest is a signed inventory used by RPKI validators. RFC 9286 requires a new manifest before its scheduled expiry even when the underlying published objects have not changed. Its signing certificate is time-limited too. Restarting a process does not rewrite those signed dates. RFC 9286.
Krill's current 0.16.0 CLI documentation says bulk publishing creates new objects when needed and synchronises them; that function normally runs at startup and every ten minutes. Those are documented expectations, not evidence that a particular lab ran that version or completed that work. Nor does the unsuccessful report establish a scheduler defect. Krill CLI documentation.
For operators, the useful distinction is between a restart test and an expiry-recovery test. A brief interruption may exercise process startup while leaving every credential comfortably valid. A longer pause can test a different dependency: the ability to issue and distribute material that is acceptable now. Whether this lab encountered that precise dependency remains unresolved.
That boundary follows the editorial discipline of Lu Heng's Note 36: describe the operating structure without inventing certainty or assigning villains. Here, the missing ending is part of the story.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
