nanog mailing list archives

RPKI chain of trust


From: "Fabiano D'Agostino" <fabiano.dagostino96 () gmail com>
Date: Wed, 26 Aug 2020 10:25:16 +0200

Good morning everyone,
I have a doubt about RPKI chain of trust. The 5 RIRs hold a self-signed
root certificate for all the resources they have in the registry. The root
certificate is used to sign the LIR's certificates that lists LIR's
resources. LIRs use their private key to sign ROAs. LIR's public key is
used to verify ROAs signatures and RIRs public key is used to verify LIR's
signatures.

Is this correct?

Thanks in advance,

Fabiano

Current thread: