Yeah so don't do that. You are going to run a policy like that. Then you should absol utely run your own validator, hardcode the customers that you are expecting into a SLURM file, or ensure that your customers are not allowed to single home with you It is a very bad idea to rely on rpki data always returning valid (vs being okay with not found state). The immediate thing that comes to mind is that if any of your customers are on ARIN signed space, ARIN, for some reason, Will occasionally just turn stuff off to try and see what happens (I am slightly exaggerating. They have a bit of a more scientific reasoning but (in my professional opinion) it's not that much better.) On Thu, Jul 30, 2026, 20:22 Stefan-Gabriel Lungu <hi@lungustefan.com> wrote:
3) A outage on all RTR sessions should ideally not impact you in a meaningful operational way, RPKI "unknown"/"not-founds" should fail open, otherwise you are at the mercy of many other possible problems
From downstream customers, RPKI unknowns are dropped.
Thanks, Stefan.
Sent from Proton Mail for iOS.
-------- Original Message -------- On Thursday, 07/30/26 at 22:15 Ben Cartwright-Cox <ripencc@benjojo.co.uk> wrote: I know that you have specifically said that you do not want your routers to depend on the reachability of infrastructure that you operate yourself, but you really should actually just run a RPKI Validator yourself.
1) You almost certainly do not have any contractual agreement with cloudflare that they are going to operate a service that will stay online and correct (in a way that does not damage your business!)
2) Running such infrastructure is typically quite easy, especially in the case of Routinator or rpki-client + StayRTR (the latter I'm pretty sure being what cloudflare uses anyway), I /personally/ wouldn't recommend FORT
3) A outage on all RTR sessions should ideally not impact you in a meaningful operational way, RPKI "unknown"/"not-founds" should fail open, otherwise you are at the mercy of many other possible problems
I do know that this is not the question you're asking but the existence of this email is provoking further questions about what your infrastructure is configured to do and what your models of reliability risk you are running on
Regards
Ben
On Thu, 30 Jul 2026 at 18:47, Stefan-Gabriel Lungu via routing-wg <routing-wg@ripe.net> wrote:
Hello everyone,
I'm looking for recommendations for reliable public RPKI RTR (RFC 8210)
servers, excluding Cloudflare.
I know the common recommendation is to run my own validator, but in my
particular case I'd prefer to use one or more independently operated public RTR servers instead.
The main reason is that I don't want my routers to depend on the
reachability of infrastructure that I operate myself. I'd rather have RTR connectivity provided by infrastructure that is operationally independent of my own network.
Does anyone know of operators that intentionally provide public RTR
servers suitable for production use?
Thank you, Stefan ----- To unsubscribe from this mailing list or change your subscription
options, please visit: https://mailman.ripe.net/mailman3/lists/routing-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/