You are here: Home > Manage IPs and ASNs > Documentation for Resource Management > Resource Certification (RPKI) > RIPE NCC RPKI Trust Anchor Structure

RIPE NCC RPKI Trust Anchor Structure

On 28 September 2017, the RIPE NCC RPKI Trust Anchor configuration was updated following an agreement with the RIRs and announced by the NRO.

In this configuration, each RIR publishes an “all resources” Trust Anchor, under which its own regional resources (IP addresses and ASNs) will be certified.

In this structure, the RIPE NCC Offline Trust Anchor and the RIPE NCC Online Operational Certificate will each hold “all resources”. Using “all resources” on these certificates is in-line with operations by other RIRs. This allows the RIPE NCC to issue a more constrained “RIPE NCC Managed Resources” certificate dynamically, and reflects the actual set of resources registered by the RIPE NCC. As a result, resources transferred into the RIPE NCC service region can be certified immediately. Conversely, resources transferred out of the RIPE NCC service region can removed immediately. Using this certificate, the RIPE NCC can then issue a single resource certificate to each of its members, reflecting all the resources registered to them by RIPE NCC.

Please contact us if you need more information.

Stay up to date!

Follow the #RPKI hashtag on Twitter.