The Wayback Machine - http://web.archive.org/web/20110114200734/http://www.ripe.net:80/certification/
Image About RIPE NCC | Contact  | Search | Sitemap    
RIPE NCC
 
RIPE Network Coordination Centre
     
Image RIPE NCC Resource Certification
Image Question & Answers
Image Resource Certification Portal
Image Validation Information
Image Certification Practice Statement
Image Terms and Conditions
Next Section

RIPE NCC Resource Certification

Certification of Internet Number Resources

Overview
Benefits
How Certification Works
PKI Principles
Matching the Current Resource Distribution System
Route Origin Authorisation (ROA) Objects
Relationship to the Internet Routing Registries (IRRs)
Certification for RIPE NCC Members
History
1 January 2011
Late 2011
The Business Model
How to enable and use the certification service
Community Development

Overview

The resource certification system is based on Public Key Infrastructure (PKI) principles. A "resource certificate" issued by the RIPE NCC states that a particular Internet number resource (that is, a block of IPv4 or IPv6 addresses, or an Autonomous System (AS) Number) has been registered by the RIPE NCC.

The following information provides an overview of what resource certification is, how it works and why it is important. For more information, there is also a page of Certification Questions and Answers.

Benefits

The resource certification system will benefit every network operator and Internet user in the world by helping to ensure long-term routing stability. The system offers two major features to the Internet community:

  • Resource certification would allow for the prefix holder checking to be automated in a dependable, transparent and standardised way. This is often referred to as automated provisioning, and it has the potential to streamline ISP workflows while still facilitating better routing security.
  • Certification verifies the legitimacy of a resource's allocation or assignment by a Regional Internet Registry. This can be vital when transferring Internet resources between parties, ensuring that the transfer is reliable and secure.

How Certification Works

PKI Principles

The resource certification system is based on Public Key Infrastructure (PKI) principles, a set of hardware, software, people, policies and procedures needed to create, manage, distribute, use, store, and revoke digital certificates. For more information on PKI, see RFC 5280, "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile".

A "resource certificate" is an electronic document proving that its holder has been officially assigned or allocated a particular Internet resource, that is, a block of IPv4 or IPv6 addresses, or an AS Number. It is a standard X.509 certificate with "Extensions for IP Addresses and AS Identifiers" as described in RFC 3779.

Matching the Current Resource Distribution System

Resource certification mirrors the way in which Internet number resources are distributed. That is, resources are initially distributed by the IANA to the RIRs, who in turn distribute them to LIRs, who then distribute the resources to their customers. Registries are responsible for maintaining records of any allocations or assignments that they make, and in the RIPE NCC service region this information is made publicly available in the RIPE Database.

Resource certification is a new, parallel process that augments and runs in tandem with the existing resource distribution process. Resource recipients (in the initial release, restricted to LIRs) have the option of also receiving a digital certificate, which describes the allocation or assignment made to them.

Note: Resource certification is intended to improve technical reliability and does not serve the purpose of verifying a user’s identity. This means that a certificate does not contain any personal information or an organisation name. Whoever can sign objects using the private key in the certificate is regarded as the holder of the resources associated with it. The RIPE Database will remain the source for registration information and related contact details.

Route Origin Authorisation (ROA) Objects

With a certificate over their Provider Aggregatable (PA) address space, an LIR will be able to create a Route Origin Authorisation (ROA) object. This is a standardised document that essentially states that the holder of a certain prefix authorises a particular Autonomous System (AS) to announce that prefix.

The ROA can have a maximum length specified, stating to which point the prefix can be de-aggregated. This means that the authorised AS won't be able to announce a more specific prefix than the LIR who created the ROA. This enforces aggregation and prevents resource hijacking.

Adoption of ROAs will make automated provisioning possible.

Relationship to the Internet Routing Registries (IRRs)

Internet Routing Registries (IRRs) are routing information databases in which network operators can publish their routing policies and their routing announcements. Other network operators can then make use of this data when making decisions about which prefixes to route. The RIPE NCC operates the RIPE Routing Registry for the RIPE community.

ROAs achieve the same outcome as registering routing announcements in an IRR, but make it easier for users to validate this information automatically.

Certification will run alongside the IRR system. IRRs will continue to serve a useful purpose as places to publish routing policies.

Certification for RIPE NCC Members

History

Since 2007, the RIPE NCC has been working on a community-driven system that will issue digital certificates along with the assignment or allocation of Internet number resources. The system uses open standards that were developed in the Secure Inter-Domain Routing (SIDR) Working Group in the IETF.

Development of a resource certification system at the RIPE NCC has been driven by the work of the RIPE Certification Task Force, established at the RIPE 53 Meeting in October 2006.

On 1 January 2011, all five Regional Internet Registries (RIRs) will launch a system to issue digital certificates along with the assignment or allocation of Internet number resources. This system will be expanded over time with additional features, including the up/down protocol.

1 January 2011

Certification: A Hosted Solution

As of 1 January 2011, the RIPE NCC will offer a robust production system with a limited feature set. This will be expanded over time, in a phased deployment.

This means that at the launch date, an LIR will be able to get a certificate for their PA address space. Certification will be offered in a hosted solution through the LIR Portal, where the LIR can manage ROA specifications (see next section). The system will take care of all the crypto operations such as certificate requests and renewals, re-keys and making sure corresponding ROA objects are generated and published. 

Late 2011

The RIPE NCC certification system will evolve in phases over 2011, with additions such as the "up/down protocol".

The Up/Down Protocol

The "up/down protocol" makes it possible for an LIR to create sub-certificates for its End Users. The LIR itself becomes a Certificate Authority (CA), resulting in a chain of trust, starting at, for example, the IANA, and going all the way down to the RIRs and LIRs, each of which serves as a certificate authority. This will allow the users of the system to rely on a single trust anchor, all the way to the top of the hierarchy.

The certification system launched on 1 January 2011 will not include the up/down protocol. However, we plan to incorporate this functionality in a subsequent update, expected later in 2011.

The Business Model

Since certification is simply a different representation of the RIR allocation data, the RIR must follow the processes already in place for making assignments and allocations of resources. The RIPE NCC can only sign and renew certificates and allow access to the certification system if it has a business relationship with a member. Only in this way can the RIPE NCC be sure that it is dealing with the correct people. If the business relationship is discontinued, certificates that do not reflect this will erode the value of the system.

When an organisation wants to become an LIR, the RIPE NCC first diligently checks its identity and company registration papers. This forms the foundation for all services offered to them: Internet resource allocations, billing, LIR Portal access, RIPE Database entries, reverse DNS delegations, etc. Only while the RIPE NCC has a business relationship with the LIR can it make attestations about the LIR’s identity, allocation status or anything else. 

When the registry closes because of bankruptcy, non-payment or any other reason, the business relationship ends. Under such circumstances, the RIPE NCC will reclaim the Internet resources (applying policy measures already in place and approved by the RIPE community), remove the RIPE Database entries and stop the reverse DNS delegation. Reclaimed resources will be reissued to another LIR. An arbitration process exists, should there be any dispute. If there is a dispute, the RIPE NCC will not reclaim resources and will allow the holder to create a new valid certificate until the dispute is resolved.

Resource certification fits exactly into the current business model. A certification service that did not align with the current business process would increase complexity, create confusion as to the business relationship and erode trust in the system.

How to enable and use the certification service

Community Development

RIPE Labs

All certification-related tools will be made available on RIPE Labs to liaise with the community in order to produce the best possible service with the highest amount of value.

Policy Development Process

The RIPE NCC's certification system reflects the RIPE community's registration policy. Any further modification of this policy happens through the RIPE Policy Development Process (PDP).

Mailing Lists

Discussions about Resource Certification policy are held on the RIPE NCC Services Working Group mailing list.
View Mailing List Archives

Image


Image
Image Image
 

Next Section
   About RIPE NCC | Service Announcements | Site Map | LIR Portal | About RIPE | Contact | Legal | Copyright Statement
RIPE NCC Homepage Go to the RIPE NCC LIRPortal Go to the RIPE Community pages