[135971] in North American Network Operators' Group
Re: Level 3's IRR Database
daemon@ATHENA.MIT.EDU (Randy Bush)
Mon Jan 31 09:17:15 2011
Date: Mon, 31 Jan 2011 23:16:28 +0900
From: Randy Bush <randy@psg.com>
To: Jack Bates <jbates@brightok.net>
In-Reply-To: <m2wrll5g2t.wl%randy@psg.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
> when there is no roa for the arriving prefix, a roa for the covering
> prefix is used. see draft-pmohapat-sidr-pfx-validate-07.txt.
which, btw, is why draft-ietf-sidr-rpki-origin-ops-04.txt warns
Before issuing a ROA for a block, an operator MUST ensure that any
sub-allocations from that block which are announced by others (e.g.
customers) have ROAs in play. Otherwise, issuing a ROA for the
super-block will cause the announcements of sub-allocations with no
ROAs to be Invalid.
randy