I'm mainly talking about the IP obtained from LIR PA. As I said before, there is a situation where the end user's IP address is not obtained directly from the LIR, but may be obtained through 10 people. Therefore, it is unlikely that the end user will directly find the LIR to set it, or it is difficult. In addition, the volume of IPv6 is huge. It is unrealistic to let a LIR manage the RPKI settings of hundreds of millions of IPv6 /48. Once there is any change, it will be a huge task. Therefore, many people simply do not set up RPKI. I think people who end up using it should be given a way to manage it themselves.
 
From: "Nick Hilliard (INEX)" <nick@inex.ie>
To: "xiaoyu.net" <yon@xiaoyu.net>
Cc: manrs-community@elists.manrs.org
Date: Wed, 13 Nov 2024 18:00:44 +0000
Subject: Re: [manrs-community] Implementing Decentralized RPKI with Blockchain Technology
 
xiaoyu.net via Manrs-community wrote on 13/11/2024 17:42:
I mean to allow the person who authorizes the use of the IP to submit and manage the ROA and RPKI settings themselves.
 

Are you talking about a LIR assignment from an allocated block of LIR addresses? If that's the case, then it's the LIR that authorises the use of the IP address block, and they can manage them as appropriate. The holder of the addresses doesn't change because it's been assigned to a customer of theirs.

If you're talking about a direct assignment from the RIPE NCC (i.e ASSIGNED PI), then there's a couple of policy items that would be relevant. One would be that assignments can't be sub-assigned, i.e. if you're thinking of sharing this with other people, it's probably not permitted by policy. Another would be that the annual charge for the address space is low because there's a sponsoring LIR who is a RIPE NCC member, who handles the relationship with the RIPE NCC. I.e. you don't have a direct relationship with the RIPE NCC. If you want a direct relationship with the RIPE NCC, you can become a member and handle your own RPKI.

Or if this is a direct assignment you could ask your sponsoring LIR to set you up with hosted RPKI, and run your own service.
 
I think it would be a good idea for manrs to set up an RPKI hosting service.

How would a third party organisation be able to attest legally that someone was the canonical holder of a block of IP addresses? The only organisation in the RIPE NCC service region that can do that is the RIPE NCC - because they're the address registry and have the canonical list of assignments and allocations.

Nick
 

************************************

Our Mail Server Support IPv6 & IPv4

************************************