Summary
- RIPE NCC records identify Dunnes Stores Unlimited as
ORG-DSU3-RIPE, an Irish LIR associated with IPv4 allocation185.114.160.0/22and IPv6 allocation2a06:7080::/29. - The immediate authority to change a protected RIPE Database object comes from applicable maintainer authentication and
mnt-byrelationships. Management of an LIR organisation object is also divided between RIPE NCC and the member. - Database-editing authority can affect attribution, contact information and operational coordination, but it does not prove ownership, general corporate authority, routing control or physical network operation.
A public registry record can look like a collection of technical fields: an organisation name, a contact role, an address prefix, a date and references to other database objects. The institutional question behind those fields is more consequential. Who is authorised to change the record, which mechanism grants that authority, and where does the authority stop?
Dunnes RIPE Database Admins offers a useful case because the available evidence supports a precise answer rather than a broad claim of control. The relevant power is exercised inside the RIPE Database. Protected objects depend on maintainer authentication and applicable mnt-by references. A member may administer permitted parts of an LIR organisation object through a controlled portal pathway, while RIPE NCC retains responsibility for other parts and for the database system itself.
That architecture creates real authority over a public coordination layer. An accepted update can change contact, attribution or registry information on which operators and other users rely. But the architecture also supplies the limit: authority over a database object is not automatically authority over the company named in it, legal title to the resources it describes, the routers that carry traffic or the people who perform the work.
The organisation and allocation records
The institutional analysis begins with the records themselves. An official RIPE NCC organisation record identifies Dunnes Stores Unlimited as ORG-DSU3-RIPE, gives its country as Ireland, records registration number 317228 and classifies the organisation as a Local Internet Registry, or LIR.
A separate RIPE NCC allocation listing associates Dunnes Stores Unlimited with IPv4 prefix 185.114.160.0/22 and IPv6 prefix 2a06:7080::/29. Both allocations are dated 25 August 2015.
These are significant registry facts. They place the named organisation and number resources within the RIPE NCC registration system and provide a public basis for attribution. They do not, however, answer every question about the resources or the organisation.
An allocation record is not a complete account of later operational use. It does not identify every device using an address within the prefixes, every contractor involved in administration, every network carrying the traffic or every person with access to relevant systems. Nor should an allocation entry be treated as a property deed without separate legal evidence. It records a relationship within a number-resource administration system.
The same caution applies to the Dunnes RIPE Database Admins name and its associated role context, DRD51-RIPE. A role object represents a business or technical contact function. It can allow a function to remain stable as the people performing it change. That makes the object useful for operational accountability, but it does not make the role a natural person or prove that it is a separate legal entity, independent provider or corporate division.
The records therefore answer a bounded attribution question: which organisation, contact role and number resources are associated in the registry? They do not by themselves answer the separate authorization question: which credentials can permit a protected update?
What the RIPE Database contains
The consequences of editing authority depend on the purpose of the system being edited. RIPE NCC describes the RIPE Database as containing address-space records, routing registry information, reverse DNS delegations and related objects. Its documentation also says that network operators enter most of the data, maintainers are primarily responsible for it, and RIPE NCC supports the database while carrying responsibilities as Database Controller.
The database is consequently a public record and coordination surface. It helps users inspect registered relationships, locate contacts, review routing-related information and understand reverse DNS or address-space records. Its usefulness depends on entries being sufficiently accurate, attributable and maintainable.
That does not make the database identical to the network. Three layers must remain distinct.
The first is the record layer: the structured objects and attributes stored in the RIPE Database. An authorised database update directly changes this layer.
The second is the operational layer: routers, servers, DNS infrastructure, network-management systems and the people who operate them. Registry information can support decisions and coordination at this layer, but changing a registry field does not itself reconfigure a router or move traffic.
The third is the legal and organisational layer: contracts, membership arrangements, corporate mandates, employment relationships and rights recognised by competent institutions. A database record can be relevant evidence at this layer without conclusively determining every legal issue.
These distinctions prevent two opposite errors. One is to exaggerate registry editing into ownership or command. The other is to dismiss editing as inconsequential because it does not directly operate equipment. A public record can have substantial coordinating force without being a universal control console.
An obsolete contact can delay an incident response. An inaccurate organisational reference can direct questions to the wrong party. A compromised or inaccessible authorization path can permit an improper change or prevent a necessary correction. Those are practical consequences even though the database does not physically operate the resources it describes.
The mntner and mnt-by authorization mechanism
The immediate instrument of authority is not the visible organisation name or role label. It is the database authorization mechanism.
RIPE NCC documentation describes a mntner object as holding credentials used to authorize the creation, modification or deletion of protected database objects. Protection is established through references to maintainers. An update must satisfy an applicable authorization requirement associated with a referenced maintainer.
This mechanism answers a narrow but important question: can the requested database action be accepted under the protection attached to the object? It does not answer every wider question about the person or organisation submitting the change.
Someone able to satisfy the applicable maintainer authorization may be able to alter a protected object within its defined scope. That ability does not, without further evidence, prove that the person owns the number resource, can sign contracts for the organisation, controls its routers or has general authority over its staff.
A maintainer credential is therefore best understood as a key to a bounded record surface. The protection determines which object or field the key can affect. The credential is not a universal key to every institutional, legal and technical relationship surrounding the record.
This also explains why a role object and a maintainer object should not be confused. A role object supports contact and functional attribution. A maintainer object supports authorization of protected changes. The same organisation may be connected to both, but they perform different jobs.
The role helps answer, “Which function should receive this communication?” The maintainer relationship helps answer, “Which authentication path can authorize this update?” Treating the two questions as interchangeable would obscure both accountability and security.
Multiple maintainers and logical-OR authorization
RIPE NCC documentation says that when more than one maintainer is referenced by applicable mnt-by attributes, those maintainers operate as a logical OR for authorization. Authorization through one applicable maintainer can therefore be sufficient; every referenced maintainer does not necessarily have to approve the same update.
This is an institutional feature, not merely a technical detail. Multiple maintainer references can create more than one valid route for changing a protected object. That can support continuity if one authorization route is unavailable. It can also distribute administrative capability across teams or institutions.
Logical-OR authorization changes the risk analysis. If more than one path can authorize a change, the integrity of the object depends on the governance and security of each applicable path. A weak or poorly managed route can undermine protection supplied by stronger routes.
The public architecture does not reveal the full internal chain behind those credentials. The evidence examined here does not identify the natural persons currently able to authenticate through each relevant maintainer account. It also does not establish whether day-to-day work is performed by employees, contractors or another operator.
That uncertainty must be preserved. Naming a maintainer does not justify naming an individual. Observing an authorization relationship does not prove an employment relationship. Finding a public role does not establish who currently holds the credential that could change a protected object.
Divided management of an LIR organisation object
The Dunnes organisation record adds another boundary. Because ORG-DSU3-RIPE is classified as an LIR, its organisation object falls within a divided management arrangement described by RIPE NCC.
The same RIPE NCC maintainer documentation says an LIR organisation object is partly managed by RIPE NCC and partly by the member. Member-editable attributes are handled through controlled Object Editors in the LIR Portal, while other attributes remain within RIPE NCC’s maintenance surface.
The resulting structure is neither complete member control nor complete RIPE NCC control. RIPE NCC manages specified parts and the system-level pathway. The member can administer permitted fields through a controlled procedure. Authority is allocated by object design and process rather than inferred from whichever name is most prominent in the public record.
This is why the phrase “controls the record” is too broad. Control can differ by field, object type and update route. A member may be able to change contact information through the portal but not freely rewrite institutionally protected attributes. RIPE NCC may manage protected parts of the organisation object without controlling the member company or its physical network.
The arrangement should therefore be described as divided database administration. It is not evidence that RIPE NCC manages Dunnes Stores Unlimited as a corporation. It is not evidence that the member can unilaterally determine every field in the RIPE Database. Each party’s authority remains tied to a specific instrument and control surface.
Responsibility is distributed
RIPE NCC’s account of the database describes a distribution of responsibility. Network operators enter most data, maintainers are primarily responsible for it, and RIPE NCC supports the database while also carrying Database Controller responsibilities.
This allocation resists a simple story in which one institution is the sole author and controller of every statement in the database. Much of the content is entered and maintained by participating operators. RIPE NCC provides and governs the system, controls specified functions and carries its own institutional responsibilities.
For Dunnes-related records, accountability is consequently a chain. The organisation and those administering applicable credentials have responsibilities for information within their permitted maintenance surface. RIPE NCC has responsibilities arising from operation of the database, its controlled procedures and its Database Controller role. Users must still interpret each record according to what its object type and fields can establish.
If a contact becomes obsolete, the responsible maintenance route matters. If a member cannot change a protected field through an ordinary update, the relevant portal or RIPE NCC-controlled procedure matters. If an authorization path is lost, the problem is not solved merely by pointing to the organisation name in the record.
The sources examined here do not document a specific failed update, recovery request, contested change or appeal involving DRD51-RIPE. They therefore do not support a conclusion about the outcome of such a dispute or the remedy available in every scenario. What they establish is the ordinary procedural architecture: protected objects, maintainer authorization, divided management and controlled member pathways.
Role objects, persons and legal entities
Registry terminology can invite over-reading when a stable role name resembles an organisation or service provider. A role object is designed to represent a function performed by one or more people. It allows contact information to remain attached to a function even when staff change.
That persistence is useful. A network-related contact should not necessarily disappear whenever an employee changes jobs. But persistence also means the role name cannot identify the current human actor without additional evidence.
Three identities must be kept separate.
First is the legal organisation recorded as ORG-DSU3-RIPE: Dunnes Stores Unlimited.
Second is the contact function represented by the Dunnes RIPE Database Admins name and associated role context.
Third is the unknown set of natural persons or service arrangements through which the relevant work and authentication may currently be performed.
The public record can support conclusions about the first two. The sources in this investigation do not establish the third. It would be speculative to claim that a named person holds the credentials or that the work is necessarily performed by employees rather than contractors.
The distinction also prevents the role from being misclassified as an independent company, cloud provider or managed network operator. Its significance lies in its function within the registry and the records connected to it, not in an unsupported assumption that the role name describes a separate business.
Why registry editing is not ownership or network control
The ability to edit a protected object and the registered association of an allocation are important evidence, but they do not establish property ownership by themselves.
A maintainer credential demonstrates that an applicable authorization requirement can be satisfied for a defined database action. It does not transform the credential holder into the legal owner of everything described by the object. Otherwise, a database credential would become the equivalent of a deed.
Likewise, the association of Dunnes Stores Unlimited with 185.114.160.0/22 and 2a06:7080::/29 is evidence of what the RIPE NCC allocation listing records. It should not be expanded into an unsupported claim about legal title, every contractual right or every later use of addresses within those ranges.
Number-resource administration involves registry policies, membership and contractual relationships, operational practices and applicable legal frameworks. A registry entry is strongest when used to establish what the registry records. Other conclusions require evidence from the institutions and instruments relevant to those conclusions.
Routing-related information may appear in the RIPE Database, but the database is not the same system as the routers that exchange and select routes. An authorized database user may be able to create or modify a protected routing-related object where the applicable conditions are met. That does not itself prove that the same user can configure a router, originate a route, persuade other networks to accept it or control the operational systems involved.
The two forms of authority may be connected in practice. An organisation might assign related responsibilities to the same team. Institutionally, however, they arise from different instruments: database credentials and object protections on one side, network-system access and operational mandates on the other.
The same separation applies to reverse DNS. A registry record may form part of a delegation and coordination structure, but the ability to edit a related object does not establish physical or administrative control of every server involved.
Precise analysis therefore names the relevant surface. Database-editing authority, routing-system access, DNS operation, corporate authority, legal title and physical access are not interchangeable forms of control.
Controlled update pathways and evidentiary limits
The evidence supports a procedural model rather than a complete map of every present-day actor.
For an ordinary protected object, the applicable maintainer references determine which authentication paths can authorize a change. Where multiple maintainers apply, the logical-OR model can permit more than one route. For an LIR organisation object, responsibility is divided: member-editable attributes pass through controlled LIR Portal Object Editors, while RIPE NCC manages other attributes and the broader database environment.
That structure provides routes for ordinary administration, but the sources do not establish the current protection configuration of every Dunnes-linked object. They do not identify every relevant maintainer or authentication method now in use. They do not reveal which natural persons can currently satisfy each authorization path. They also do not establish whether those people act as employees, contractors or through another arrangement.
No specific disputed update, recovery request, appeal or remedy involving DRD51-RIPE is documented in the source package. It would therefore be unsafe to predict how a concrete conflict would be resolved or to state that a particular party would prevail.
A contested case would require additional evidence: the exact object and attributes at issue, the applicable maintainers at the relevant time, the submitted update, the authentication route used, any rejection or acceptance record, correspondence with RIPE NCC, and the contractual or procedural rules governing escalation. Without that record, the analysis should remain at the level the sources can support.
Bounded institutional consequences
The evidence supports a model of bounded registry authority. Maintainer authentication and mnt-by relationships can govern changes to protected RIPE Database objects. Member procedures can govern specified fields of an LIR organisation object. RIPE NCC retains separate responsibilities for protected attributes, controlled pathways, database operation and its Database Controller role.
Those powers matter because public registry information supports attribution, contact, routing-related coordination, reverse DNS and number-resource administration. An inaccurate or inaccessible record can impose real costs on operators and other users. A valid authorization path can preserve continuity; a weak or compromised path can create risk.
But authority must be traced to its instrument. A database credential proves capacity to satisfy a database authorization requirement within a defined scope. It does not prove ownership, general authority over Dunnes Stores Unlimited, control of routing systems, legal title to number resources or physical operation of network infrastructure.
The durable conclusion is therefore not that one party “controls Dunnes” or even that one party controls every Dunnes-related registry field. It is that the RIPE Database distributes bounded authority across maintainers, member procedures and RIPE NCC-controlled functions. Understanding who can change a record requires identifying the protected object, the applicable authorization path and the particular fields at issue. Understanding what that power means requires refusing to extend it beyond those boundaries.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
