RFC 8360: Resource Public Key Infrastructure (RPKI) Validation Reconsidered
In plain English — editorial summary, not part of the RFC
This document specifies an alternative to the certificate validation procedure specified in RFC 6487 that reduces aspects of operational fragility in the management of certificates in the Resource Public Key Infrastructure (RPKI), while retaining essential security features. The procedure specified in RFC 6487 requires that Resource Certificates are rejected entirely if they are found to overclaim any resources not contained on the issuing certificate, whereas the validation process defined here allows an issuing Certification Authority (CA) to chose to communicate that such Resource Certificates should be accepted for the intersection of their resources and the issuing certificate. It should be noted that the validation process defined here considers validation under a single trust anchor (TA) only. In particular, concerns regarding overclaims where multiple configured TAs claim overlapping resources are considered out of scope for this document. This choice is signaled by a set of alternative Object Identifiers (OIDs) per "X.509 Extensions for IP Addresses and AS Identifiers" (RFC 3779) and "Certificate Policy (CP) for the Resource Public Key Infrastructure (RPKI)" (RFC 6484). It should be noted that in case these OIDs are not used for any certificate under a trust anchor, the validation procedure defined here has the same outcome as the procedure defined in RFC 6487. Furthermore, this document provides an alternative to Route Origin Authorization (ROA) (RFC 6482) and BGPsec Router Certificate (BGPsec PKI Profiles -- publication requested) validation.
Document record
- Document ID
- RFC8360
- Published
- April 2018
- Authors
- G. Huston; G. Michaelson; C. Martinez; T. Bruijnzeels; A. Newton; D. Shaw
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- rtg
- Pages
- 29
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8361Transparent Interconnection of Lots of Links (TRILL): Centralized Replication for Active-Active Broadcast, Unknown Unicast, and Multicast (BUM) TrafficCurrent
April 2018
- RFC 8359Network-Assigned Upstream LabelCurrent
March 2018
- RFC 8362OSPFv3 Link State Advertisement (LSA) ExtensibilityCurrent
April 2018
- RFC 8363GMPLS OSPF-TE Extensions in Support of Flexi-Grid Dense Wavelength Division Multiplexing (DWDM) NetworksCurrent
May 2018
- RFC 8356Experimental Codepoint Allocation for the Path Computation Element Communication Protocol (PCEP)Current
March 2018
- RFC 8364PIM Flooding Mechanism (PFM) and Source Discovery (SD)Updated
March 2018
- RFC 8355Resiliency Use Cases in Source Packet Routing in Networking (SPRING) NetworksCurrent
March 2018
- RFC 8365A Network Virtualization Overlay Solution Using Ethernet VPN (EVPN)Updated
March 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?