RPKI Validation Reconsidered

The information below is for an old version of the document
Document Type Expired Internet-Draft (sidr WG)
Authors Geoff Huston  , George Michaelson  , Carlos Martínez  , Tim Bruijnzeels  , Andrew Newton  , Alain Aina 
Last updated 2015-07-28 (latest revision 2015-01-24)
Stream Internet Engineering Task Force (IETF)
Expired & archived
pdf htmlized bibtex
Additional Resources
- Mailing list discussion
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document reviews the certificate validation procedure specified in RFC6487 and highlights aspects of operational fragility in the management of certificates in the RPKI in response to the movement of resources across registries, and the associated actions of Certification Authorities to maintain continuity of validation of certification of resources during this movement.


Geoff Huston (gih@apnic.net)
George Michaelson (ggm@apnic.net)
Carlos Martínez (carlos@lacnic.net)
Tim Bruijnzeels (tim@ripe.net)
Andrew Newton (andy@arin.net)
Alain Aina (aalain@afrinic.net)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)