RPKI and ROAs on 44Net

From 44Net Wiki
Revision as of 17:39, 20 August 2026 by KI5QKX (talk | contribs) (mw push)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)


This page answers a recurring question:

Why can’t 44Net publish ROAs?

The short answer is that 44Net subnets are administered by ARIN under "legacy" status, and ARIN does not provide RPKI or IRR services for legacy resources that not covered by an ARIN service agreement.

The basics

RPKI (Resource Public Key Infrastructure) is the system used to make cryptographically verifiable statements about Internet number resources.

A ROA (Route Origin Authorization) is one of those statements. It says which ASN is authorized to originate a prefix.

On many modern networks, operators expect ROAs to be 'Valid'. If a route is announced without a valid ROA, some providers may treat it as 'Invalid' and filter it out. Others may treat it as 'NotFound' and accept it, but that is not guaranteed.

What that means for 44Net

Operationally, that means some providers support 44Net prefixes without a valid ROA, while others may not. Right now, there is no alternative but to petition the provider to make an exception for the route, or to use a provider that is already familiar with handling 44Net space.

What is ARDC doing about it?

The foundation monitors the situation and available options as part of its responsibility to steward the address space. If and when there is a development worth sharing, ARDC will update the community. In the meantime, ARDC is happy to discuss exceptions with providers and customers on a case-by-case basis.

What about SWIP?

ARDC does not SWIP customer subnets, because the address space is leased to the customer, not transferred. We also cannot currently add customer- or provider-specific text to the parent ARIN Whois or RDAP record.

External references

Related pages