nanog mailing list archives

Re: ARIN / RIR Pragmatism (WAS: Re: RADB)


From: Sandra Murphy <sandy () tislabs com>
Date: Sat, 25 Oct 2014 08:57:36 -0400

Other RIR based RIRs have the same ability to protect prefixes in their realm of control.  (See RFC 2725 RPSS)(*)  (I 
think that APNIC is doing pretty much as RIPE is.) 

Even RIPE is not secure for prefixes outside their region.  (There's one maintainer that anyone can use to register 
anything for resources outside the region - password publicly available, etc.)

Non-RIR based IRRs do not have the ability to tie the register-er to authority for the resource, so they have no base 
on which to build the RIPE sort of security.

--Sandy

(*) (yes, I'm listed as an author, but Curtis Villamizer was far and away the principal author.)

On Oct 24, 2014, at 7:20 PM, Baldur Norddahl <baldur.norddahl () gmail com> wrote:

The RIPE IRR is secure. Why not just copy that for the other regions?

Baldur

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail


Current thread: