[RPKI] Potential for test/dev trust anchor?

Andrew Gray agray at blargh.com
Sun Feb 24 22:40:53 UTC 2019


Hi all,

At the RPKI round table before NANOG 75 last week, a few people were 
commenting about the inability to test or see what potential ROA entries 
may do, especially inside other providers networks.  This seems to be 
somewhat of a hindrance to adoption under the "well, if I advertise 
nothing, things keep working, but if I screw it up, I break things" issue.

I spoke with a couple other folks at that round table one-on-one, but I 
wanted to toss out an idea to a wider audience: Could a dev/testing 
trust anchor be set up by the community, and have a couple of the tier 1 
providers provide feedback from that through one of the various looking 
glass systems?

This would allow people to use that test trust anchor to verify they 
have advertisements correct, things do what they want, etc., before then 
pulling the advertisement over to whichever RIR is appropriate for 
production work.

Thoughts?

Thanks,
Andrew



More information about the RPKI mailing list