ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
IP & ASN

What Are ROA and RPKI? How to Create a ROA for Your IP Block (RIPE/APNIC/ARIN/AFRINIC) and Verify It

5 steps 11 min read 5 views 0
On this page

RPKI (Resource Public Key Infrastructure) uses certificates to prove which ASN may announce which IP prefix, and a ROA (Route Origin Authorization) is the signed object that states that permission. More and more networks drop RPKI-invalid routes, so a prefix without a correct ROA may be unreachable from parts of the internet. This guide explains what ROA and RPKI are, how to create a ROA for your IP block in the RIPE, APNIC, ARIN and AFRINIC portals, how to choose the max prefix length, and how to verify with rpki.cloudflare.com and Routinator on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.

Step 1: Understand RPKI validation states and check your current ROA

Routers compare received routes with ROAs and get one of three results: Valid (origin ASN and length match), Invalid (wrong ASN, or more specific than the max length; dropped by many networks) or NotFound (no ROA covers the prefix). Check the current status via the RIPEstat API:

curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64500&prefix=198.51.100.0/24" | grep -o '"status":"[^"]*"'

Step 2: List prefixes, origin ASN and max prefix length for the ROA

Collect every prefix you actually announce and its origin ASN. The max length controls which more-specific sub-prefixes the ROA also allows. Set it equal to the announced length and create separate ROAs only for more-specifics you really announce. A loose max length lets an attacker forge your ASN and hijack sub-prefixes.

curl -s "https://stat.ripe.net/data/announced-prefixes/data.json?resource=AS64500" | grep -o '"prefix":"[^"]*"'
birdc show route export upstream1          # BIRD 2
vtysh -c "show bgp ipv4 unicast neighbors 203.0.113.1 advertised-routes"   # FRR
Prefix              Origin ASN   Max Length
198.51.100.0/24     AS64500      24
198.51.100.0/23     AS64500      23     # only if you also announce the /23
2001:db8:100::/48   AS64500      48

Step 3: Create the ROA in your RIR portal

Only the resource holder (or a member account it authorizes) can create ROAs. The entry points are roughly as follows; follow each RIR's current interface:

  • RIPE NCC: LIR Portal → RPKI Dashboard; enable hosted RPKI and create a ROA.
  • APNIC: MyAPNIC → resource / route management; create the ROA (a route object can be generated at the same time).
  • ARIN: ARIN Online → enable Hosted RPKI for the resource, then submit a ROA request.
  • AFRINIC: MyAFRINIC → RPKI menu → create ROA.

Enter prefix, origin ASN and max length and save; publication usually takes minutes to an hour. If the IPs are leased from IMIDC, IMIDC is the resource holder: open a ticket with the prefix, your ASN and the max length and we will create the ROA, and the IRR route object if needed.

Prefix:      198.51.100.0/24
Origin ASN:  AS64500
Max Length:  24
IRR route object: yes
If the prefix is still announced by an old ASN or another provider, plan the migration before creating the new ROA, or the old route may turn Invalid immediately and cause an outage. For unused blocks, an AS0 ROA helps prevent hijacking.

Step 4: Verify the ROA online at rpki.cloudflare.com

Open the validator view on rpki.cloudflare.com, enter ASN and prefix and you will see Valid or Invalid plus every ROA covering the prefix. RIPEstat and bgp.tools also show RPKI status. You can also repeat the command from Step 1 until it reports valid.

curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64500&prefix=198.51.100.0/24" | grep -o '"status":"[^"]*"'

Step 5: Validate RPKI locally with Routinator

Routinator is NLnet Labs' open-source RPKI validator. It can validate independently on your server or feed routers over RTR. The commands below install it via the Rust toolchain (NLnet Labs also provides package repositories for Debian/Ubuntu and RHEL-based systems). The first run syncs the whole RPKI repository and may take several minutes.

# Debian / Ubuntu
apt install -y curl build-essential
# CentOS / Rocky / AlmaLinux
dnf install -y curl gcc
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
source "$HOME/.cargo/env"
cargo install --locked routinator
routinator validate --asn AS64500 --prefix 198.51.100.0/24
routinator vrps --select-asn AS64500

FAQ

Do I still need an IRR route object if I have a ROA?

Yes. Many upstreams still build prefix filters from IRR data, so keep ROAs and route/route6 objects in place and consistent.

How long until a ROA takes effect?

RIRs usually publish within an hour, and validators refresh on their own schedule, so expect tens of minutes to a few hours.

Can one prefix be authorized for several ASNs?

Yes. Create one ROA per ASN, which is useful for multi-origin setups or during a migration.

Still stuck? Open a ticket with IMIDC 24/7 technical support.

Was this answer helpful?

Related Tutorials