Creating a Maintainer (mntner) Object
A maintainer (mntner) is the authorization mechanism in the RIPE Database. Every object in the database must reference at least one maintainer. The maintainer controls who can create, modify, or delete objects.
Prerequisites
Step 1: Open the RIPE Database Web Interface
- Go to https://apps.db.ripe.net
- Click "Create an Object" in the top menu
- Select "mntner" from the object type list
Step 2: Fill in the Maintainer Fields
Here is an example of a maintainer object:
mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE
Field Descriptions
| Field | Required | Description |
|---|---|---|
| mntner | Yes | Name of the maintainer. Convention: COMPANY-MNT |
| descr | Yes | Short description of the maintainer |
| admin-c | Yes | Reference to an admin contact (person/role NIC handle). Use a placeholder initially — you can update it later |
| upd-to | Yes | Email address for notifications about unauthorized update attempts |
| auth | Yes | Authentication method (see below) |
| mnt-by | Yes | Usually references itself (self-maintaining) |
| source | Yes | Always RIPE |
Authentication Methods
The auth: field defines how changes are authorized. Available methods:
| Method | Format | Recommended |
|---|---|---|
| SSO | SSO email@example.com | Yes — links to your RIPE NCC Access account |
| MD5-PW | MD5-PW $1$... | Legacy — use SSO instead |
| PGPKEY | PGPKEY-XXXXXXXX | For API/automated workflows |
Always use SSO authentication. It links the maintainer to your RIPE NCC Access account, so you authenticate with your login credentials instead of a separate password. You can add multiple SSO lines for team access.
Step 3: Create via the Web Interface
- Fill in all the required fields in the web form
- For
admin-c, you can create a person or role object first, or use an existing NIC handle - Set
auth:toSSO your-email@example.com - Set
mnt-by:to the same name asmntner:(self-referencing) - Click "Submit"
Step 4: Create via Syncupdates (API)
You can also create a maintainer using the RIPE Database Syncupdates API:
curl -X POST "https://syncupdates.db.ripe.net/syncupdates/RIPE" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "DATA=
mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE
" \
--data-urlencode "NEW=yes"
When creating a maintainer via Syncupdates, you must authenticate with your RIPE NCC Access session cookie or API key.
Step 5: Verify the Maintainer
After creation, verify your maintainer exists:
- Go to https://apps.db.ripe.net/db-web-ui/query
- Search for your maintainer name (e.g.,
EXAMPLE-MNT) - The object should appear with all your specified fields
Or via the command line:
whois -h whois.ripe.net EXAMPLE-MNT
Naming Conventions
Follow these conventions for maintainer names:
| Use Case | Convention | Example |
|---|---|---|
| Company | COMPANYNAME-MNT | DGTL-MNT |
| LIR | Assigned by RIPE NCC | org-XXXX-MNT |
| Personal | LASTNAME-MNT | SMITH-MNT |
The name must:
- End with
-MNT - Contain only letters, digits, and hyphens
- Be unique in the RIPE Database
Adding Multiple Administrators
To allow multiple people to manage objects protected by your maintainer, add multiple auth: lines:
mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: JS1234-RIPE
upd-to: noc@example.com
auth: SSO admin1@example.com
auth: SSO admin2@example.com
auth: SSO admin3@example.com
mnt-by: EXAMPLE-MNT
source: RIPE
Common Mistakes
- Forgetting to set
mnt-byto itself — If you reference a different maintainer, you won't be able to modify your own maintainer object. - Using MD5-PW instead of SSO — MD5 passwords can be brute-forced. SSO is linked to your RIPE NCC Access account with 2FA.
- Not adding
upd-to— You won't receive notifications about unauthorized modification attempts. - Using a non-existent
admin-c— The referenced person or role object must exist in the database before you can reference it (or create them together).
Next Steps
- Create a Role object for your
admin-ccontact - Create ROA objects
- Set up RPKI synchronization