Adverse Actions by a Certification Authority or Repository Manager in the Resource Public Key Infrastructure
RFC 8211, “Adverse Actions by a Certification Authority or Repository Manager in the Resource Public Key Infrastructure”, is an Informational document published in September 2017 by S. Kent, D. Ma. The canonical text is published by the RFC Editor.
Abstract
This document analyzes actions by or against a Certification Authority (CA) or an independent repository manager in the RPKI that can adversely affect the Internet Number Resources (INRs) associated with that CA or its subordinate CAs. The analysis is done from the perspective of an affected INR holder. The analysis is based on examination of the data items in the RPKI repository, as controlled by a CA (or an independent repository manager) and fetched by Relying Parties (RPs). The analysis does not purport to be comprehensive; it does represent an orderly way to analyze a number of ways that errors by or attacks against a CA or repository manager can affect the RPKI and routing decisions based on RPKI data.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 8211 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8210 The Resource Public Key Infrastructure to Router Protocol, Version 1
- RFC 8212 Default External BGP Route Propagation Behavior without Policies
- RFC 8209 A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests
- RFC 8213 Security of Messages Exchanged between Servers and Relay Agents
- RFC 8208 BGPsec Algorithms, Key Formats, and Signature Formats
- RFC 8214 Virtual Private Wire Service Support in Ethernet VPN
- RFC 8207 BGPsec Operational Considerations
- RFC 8215 Local-Use IPv4/IPv6 Translation Prefix