RPKI

RPKI (Resource Public Key Infrastructure) and route origin validation

RPKI RFCs (65)

Display RFCs as
  • RFC 9981: Resource Public Key Infrastructure (RPKI) Manifest Number Handling

    Proposed Standard
  • RFC 9829: Handling of Resource Public Key Infrastructure (RPKI) Certificate Revocation List (CRL) Number Extensions

    Proposed Standard
  • RFC 9691: A Profile for Resource Public Key Infrastructure (RPKI) Trust Anchor Keys (TAKs)

    Proposed Standard
  • RFC 9697: Detecting RPKI Repository Delta Protocol (RRDP) Session Desynchronization

    Proposed Standard
  • RFC 9674: Same-Origin Policy for the RPKI Repository Delta Protocol (RRDP)

    Proposed Standard
  • RFC 9582: A Profile for Route Origin Authorizations (ROAs)

    Proposed Standard
  • RFC 9589: On the Use of the Cryptographic Message Syntax (CMS) Signing-Time Attribute in Resource Public Key Infrastructure (RPKI) Signed Objects

    Proposed Standard
  • RFC 9455: BCP 238: Avoiding Route Origin Authorizations (ROAs) Containing Multiple IP Prefixes

    Best Current Practice
  • RFC 9324: Policy Based on the Resource Public Key Infrastructure (RPKI) without Route Refresh

    Proposed Standard
  • RFC 9323: A Profile for RPKI Signed Checklists (RSCs)

    Proposed Standard
  • RFC 9319: BCP 185: The Use of maxLength in the Resource Public Key Infrastructure (RPKI)

    Best Current Practice
  • RFC 9286: Manifests for the Resource Public Key Infrastructure (RPKI)

    Proposed Standard
  • RFC 9255: The 'I' in RPKI Does Not Stand for Identity

    Proposed Standard
  • RFC 8893: Resource Public Key Infrastructure (RPKI) Origin Validation for BGP Export

    Proposed Standard
  • RFC 8897: Requirements for Resource Public Key Infrastructure (RPKI) Relying Parties

    Informational
  • RFC 8630: Resource Public Key Infrastructure (RPKI) Trust Anchor Locator

    Proposed Standard
  • RFC 8634: BCP 224: BGPsec Router Certificate Rollover

    Best Current Practice
  • RFC 8635: Router Keying for BGPsec

    Proposed Standard
  • RFC 8608: BGPsec Algorithms, Key Formats, and Signature Formats

    Proposed Standard
  • RFC 8488: RIPE NCC's Implementation of Resource Public Key Infrastructure (RPKI) Certificate Tree Validation

    Informational
  • RFC 8481: Clarifications to BGP Origin Validation Based on Resource Public Key Infrastructure (RPKI)

    Proposed Standard
  • RFC 8416: Simplified Local Internet Number Resource Management with the RPKI (SLURM)

    Proposed Standard
  • RFC 8360: Resource Public Key Infrastructure (RPKI) Validation Reconsidered

    Proposed Standard
  • RFC 8205: BGPsec Protocol Specification

    Proposed Standard
  • RFC 8206: BGPsec Considerations for Autonomous System (AS) Migration

    Proposed Standard
  • RFC 8207: BCP 211: BGPsec Operational Considerations

    Best Current Practice
  • RFC 8208: BGPsec Algorithms, Key Formats, and Signature Formats

    Proposed Standard

    Obsoleted by RFC 8608

  • RFC 8209: A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests

    Proposed Standard
  • RFC 8210: The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1

    Proposed Standard
  • RFC 8211: Adverse Actions by a Certification Authority (CA) or Repository Manager in the Resource Public Key Infrastructure (RPKI)

    Informational
  • RFC 8181: A Publication Protocol for the Resource Public Key Infrastructure (RPKI)

    Proposed Standard
  • RFC 8182: The RPKI Repository Delta Protocol (RRDP)

    Proposed Standard
  • RFC 8183: An Out-of-Band Setup Protocol for Resource Public Key Infrastructure (RPKI) Production Services

    Proposed Standard
  • RFC 8097: BGP Prefix Origin Validation State Extended Community

    Proposed Standard
  • RFC 7935: The Profile for Algorithms and Key Sizes for Use in the Resource Public Key Infrastructure

    Proposed Standard
  • RFC 7909: Securing Routing Policy Specification Language (RPSL) Objects with Resource Public Key Infrastructure (RPKI) Signatures

    Proposed Standard
  • RFC 7730: Resource Public Key Infrastructure (RPKI) Trust Anchor Locator

    Proposed Standard

    Obsoleted by RFC 8630

  • RFC 7382: BCP 173: Template for a Certification Practice Statement (CPS) for the Resource PKI (RPKI)

    Best Current Practice
  • RFC 7353: Security Requirements for BGP Path Validation

    Informational
  • RFC 7318: Policy Qualifiers in Resource Public Key Infrastructure (RPKI) Certificates

    Proposed Standard
  • RFC 7128: Resource Public Key Infrastructure (RPKI) Router Implementation Report

    Informational
  • RFC 7132: Threat Model for BGP Path Security

    Informational
  • RFC 7115: BCP 185: Origin Validation Operation Based on the Resource Public Key Infrastructure (RPKI)

    Best Current Practice
  • RFC 6945: Definitions of Managed Objects for the Resource Public Key Infrastructure (RPKI) to Router Protocol

    Proposed Standard
  • RFC 6916: BCP 182: Algorithm Agility Procedure for the Resource Public Key Infrastructure (RPKI)

    Best Current Practice
  • RFC 6907: Use Cases and Interpretations of Resource Public Key Infrastructure (RPKI) Objects for Issuers and Relying Parties

    Informational
  • RFC 6810: The Resource Public Key Infrastructure (RPKI) to Router Protocol

    Proposed Standard
  • RFC 6811: BGP Prefix Origin Validation

    Proposed Standard
  • RFC 6480: An Infrastructure to Support Secure Internet Routing

    Informational
  • RFC 6481: A Profile for Resource Certificate Repository Structure

    Proposed Standard
  • RFC 6482: A Profile for Route Origin Authorizations (ROAs)

    Proposed Standard

    Obsoleted by RFC 9582

  • RFC 6483: Validation of Route Origination Using the Resource Certificate Public Key Infrastructure (PKI) and Route Origin Authorizations (ROAs)

    Informational
  • RFC 6484: BCP 173: Certificate Policy (CP) for the Resource Public Key Infrastructure (RPKI)

    Best Current Practice
  • RFC 6485: The Profile for Algorithms and Key Sizes for Use in the Resource Public Key Infrastructure (RPKI)

    Proposed Standard

    Obsoleted by RFC 7935

  • RFC 6486: Manifests for the Resource Public Key Infrastructure (RPKI)

    Proposed Standard

    Obsoleted by RFC 9286

  • RFC 6487: A Profile for X.509 PKIX Resource Certificates

    Proposed Standard
  • RFC 6488: Signed Object Template for the Resource Public Key Infrastructure (RPKI)

    Proposed Standard
  • RFC 6489: BCP 174: Certification Authority (CA) Key Rollover in the Resource Public Key Infrastructure (RPKI)

    Best Current Practice
  • RFC 6490: Resource Public Key Infrastructure (RPKI) Trust Anchor Locator

    Proposed Standard

    Obsoleted by RFC 7730

  • RFC 6491: Resource Public Key Infrastructure (RPKI) Objects Issued by IANA

    Proposed Standard
  • RFC 6492: A Protocol for Provisioning Resource Certificates

    Proposed Standard
  • RFC 6493: The Resource Public Key Infrastructure (RPKI) Ghostbusters Record

    Historic
  • RFC 6494: Certificate Profile and Certificate Management for SEcure Neighbor Discovery (SEND)

    Proposed Standard
  • RFC 6472: BCP 172: Recommendation for Not Using AS_SET and AS_CONFED_SET in BGP

    Best Current Practice

    Obsoleted by RFC 9774

  • RFC 6382: BCP 169: Unique Origin Autonomous System Numbers (ASNs) per Node for Globally Anycasted Services

    Best Current Practice

Subscribe to RPKI

Get notified when:

  • RFC changes to status, obsoleted by, updates, updated by, or subseries.
  • New RFC added to this subject or below
  • The subject was merged into another.