NLnet Labs · @nlnetlabs
1800 followers · 660 posts · Server fosstodon.org

The first Release Candidate of Routinator 0.13.0 is now available. The most notable change support for Autonomous System Provider Authorisations (), allowing verification of the AS_PATH attribute of routes advertised in the . As this functionality is still subject to change in the , the feature has to be explicitly enabled when compiling to avoid unintended side effects. github.com/NLnetLabs/routinato

#aspa #bgp #ietf #rpki #openstandards #routingsecurity

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1736 followers · 640 posts · Server fosstodon.org

In case you were holding your breath for the Routinator release with support, please exhale now. 😮‍💨 The people discussing this topic in the have reached consensus to make ASPA AFI-agnostic instead. We'll change our implementation accordingly.

#aspa #routingsecurity #ietf

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1710 followers · 615 posts · Server fosstodon.org

Perfectly timed for all the discussions at , we’re proud to launch Krill 0.13. This release introduces production grade support in addition to . It also adds a full Trust Anchor support, enabling RIRs to run Krill as their root CA solution. github.com/NLnetLabs/krill/rel

#routingsecurity #ripe86 #aspa #bgpsec #rpki

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1673 followers · 591 posts · Server fosstodon.org

Thank you all for all the testing with the latest Krill 0.13 Release Candidates. There is a massive amount of changes and with all your feedback we're able to iron out all the little wrinkles that slipped through our rigorous QA process. github.com/NLnetLabs/krill/rel

#rpki #routingsecurity

Last updated 1 year ago

Jim Cowie · @jimcowie
161 followers · 470 posts · Server social.secret-wg.org

Putting the *measurement* into making a measurable difference in the ecosystem: update on community engagement OKRs from Hisham Ibrahim @ripencc

labs.ripe.net/author/hisham_ib

#internet #routingsecurity #ipv6 #datastorytelling

Last updated 1 year ago

Alex Band · @alexband
480 followers · 185 posts · Server hachyderm.io

I'm actually quite stunned that there are now 94 objects out in the wild. krill.docs.nlnetlabs.nl/en/lat

#aspa #rpki #routingsecurity

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1655 followers · 571 posts · Server fosstodon.org

We're super proud that one of the five Regional Internet Registries will be deploying Krill as the Certification Authority solution for their members. To make this possible, Trust Anchor support is now available in Krill 0.13 Release Candidate 1. This pre-release also contains a new User Interface, as well as production support for ASPA objects. github.com/NLnetLabs/krill/rel

#rpki #routingsecurity #opensource #rustlang #memorysafety

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1645 followers · 560 posts · Server fosstodon.org

With support for running as an Trust Anchor (as an RIR), the ability to import CAs, production grade ASPA support and a brand new User Interface, the Krill 0.13 release will be massive. github.com/NLnetLabs/krill/pul

#rpki #routingsecurity #opensource #rustlang

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1639 followers · 556 posts · Server fosstodon.org

Another thing that @tweedegolf inspired us with is fuzzing of projects. We’ve now used this to fuzz delta construction and merging when developing ASPA support in Routinator.
github.com/NLnetLabs/routinato

#rust #rpki #opensource #rustlang #fuzzing #security #routingsecurity

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1635 followers · 555 posts · Server fosstodon.org

There are currently 39 ASPAs out in the wild, almost all generated by our Certificate Authority software Krill. It’s currently an experimental feature, but will be made a first class citizen in Krill 0.13. krill.docs.nlnetlabs.nl/en/sta

#rpki #opensource #routingsecurity

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1635 followers · 554 posts · Server fosstodon.org

An Autonomous System Provider Attestation (ASPA) object in is similar to a ROA: it’s an authority to propagate a route learned from an AS, issued by that authorising AS. Support for ASPAs in Routinator is now ready for review, coming soon to a release near you. github.com/NLnetLabs/routinato

#rpki #routingsecurity #bgp

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1616 followers · 546 posts · Server fosstodon.org

For the -to-Router protocol, the semantics of ROAs and ASPAs differ. This means quite a bit of refactoring was done to accommodate ASPAs in Routinator. Getting there though! github.com/NLnetLabs/rpki-rs/p

#rpki #routingsecurity

Last updated 1 year ago

Internet Society · @internetsociety
721 followers · 81 posts · Server techpolicy.social
Internet Society · @internetsociety
721 followers · 80 posts · Server techpolicy.social
Internet Society · @internetsociety
721 followers · 79 posts · Server techpolicy.social
Alex Band · @alexband
467 followers · 165 posts · Server hachyderm.io

Meanwhile on the sidrops list: “But after X.509 validation of ASPA, we have VAPs and then the SPAS derived from the VAPs, which can be called VAP-SPAS.”

Once again, it's going to be quite the adventure to pour this into an implementation that is understandable and usable for network operators…

#ietf #openstandards #rpki #routingsecurity #bgp

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1582 followers · 520 posts · Server fosstodon.org

The first step towards support for Autonomous System Provider Authorisation (ASPA) in Routinator. github.com/NLnetLabs/rpki-rs/p

#rpki #bgp #routingsecurity #opensource #rustlang

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1582 followers · 520 posts · Server fosstodon.org

The first step towards support for Autonomous System Provider Authorisation (ASPA )in Routinator. github.com/NLnetLabs/rpki-rs/p

#rpki #bgp #routingsecurity #opensource #rustlang

Last updated 1 year ago

NLnet Labs · @nlnetlabs
1576 followers · 515 posts · Server fosstodon.org

ASPA is in working group last call, so support in Routinator coming soon. Krill already had support. Remember to ask to your router vendor to implement support too. github.com/NLnetLabs/routinato

#bgp #opensource #rpki #routingsecurity

Last updated 1 year ago

Internet Society · @internetsociety
673 followers · 62 posts · Server techpolicy.social