Skip to main content

Creating a Maintainer (mntner) Object

A maintainer (mntner) is the authorization mechanism in the RIPE Database. Every object in the database must reference at least one maintainer. The maintainer controls who can create, modify, or delete objects.

Prerequisites​

Step 1: Open the RIPE Database Web Interface​

  1. Go to https://apps.db.ripe.net
  2. Click "Create an Object" in the top menu
  3. Select "mntner" from the object type list

Step 2: Fill in the Maintainer Fields​

Here is an example of a maintainer object:

mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE

Field Descriptions​

FieldRequiredDescription
mntnerYesName of the maintainer. Convention: COMPANY-MNT
descrYesShort description of the maintainer
admin-cYesReference to an admin contact (person/role NIC handle). Use a placeholder initially — you can update it later
upd-toYesEmail address for notifications about unauthorized update attempts
authYesAuthentication method (see below)
mnt-byYesUsually references itself (self-maintaining)
sourceYesAlways RIPE

Authentication Methods​

The auth: field defines how changes are authorized. Available methods:

MethodFormatRecommended
SSOSSO email@example.comYes — links to your RIPE NCC Access account
MD5-PWMD5-PW $1$...Legacy — use SSO instead
PGPKEYPGPKEY-XXXXXXXXFor API/automated workflows
tip

Always use SSO authentication. It links the maintainer to your RIPE NCC Access account, so you authenticate with your login credentials instead of a separate password. You can add multiple SSO lines for team access.

Step 3: Create via the Web Interface​

  1. Fill in all the required fields in the web form
  2. For admin-c, you can create a person or role object first, or use an existing NIC handle
  3. Set auth: to SSO your-email@example.com
  4. Set mnt-by: to the same name as mntner: (self-referencing)
  5. Click "Submit"

Step 4: Create via Syncupdates (API)​

You can also create a maintainer using the RIPE Database Syncupdates API:

curl -X POST "https://syncupdates.db.ripe.net/syncupdates/RIPE" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "DATA=
mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE
" \
--data-urlencode "NEW=yes"
info

When creating a maintainer via Syncupdates, you must authenticate with your RIPE NCC Access session cookie or API key.

Step 5: Verify the Maintainer​

After creation, verify your maintainer exists:

  1. Go to https://apps.db.ripe.net/db-web-ui/query
  2. Search for your maintainer name (e.g., EXAMPLE-MNT)
  3. The object should appear with all your specified fields

Or via the command line:

whois -h whois.ripe.net EXAMPLE-MNT

Naming Conventions​

Follow these conventions for maintainer names:

Use CaseConventionExample
CompanyCOMPANYNAME-MNTDGTL-MNT
LIRAssigned by RIPE NCCorg-XXXX-MNT
PersonalLASTNAME-MNTSMITH-MNT

The name must:

  • End with -MNT
  • Contain only letters, digits, and hyphens
  • Be unique in the RIPE Database

Adding Multiple Administrators​

To allow multiple people to manage objects protected by your maintainer, add multiple auth: lines:

mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO admin1@example.com
auth: SSO admin2@example.com
auth: SSO admin3@example.com
mnt-by: EXAMPLE-MNT
source: RIPE

Common Mistakes​

  1. Forgetting to set mnt-by to itself — If you reference a different maintainer, you won't be able to modify your own maintainer object.
  2. Using MD5-PW instead of SSO — MD5 passwords can be brute-forced. SSO is linked to your RIPE NCC Access account with 2FA.
  3. Not adding upd-to — You won't receive notifications about unauthorized modification attempts.
  4. Using a non-existent admin-c — The referenced person or role object must exist in the database before you can reference it (or create them together).

Next Steps​

  1. Create a Role object for your admin-c contact
  2. Create ROA objects
  3. Set up RPKI synchronization