Skip to main content

Creating ROA in RIPE Database

A Route Origin Authorization (ROA) is a cryptographically signed object that authorizes a specific Autonomous System (AS) to originate a particular IP prefix. ROAs are the foundation of RPKI-based route origin validation.

Step 1: Log in to RIPE NCC Portal​

  1. Go to https://my.ripe.net
  2. Sign in with your RIPE NCC Access credentials
  3. Navigate to "My Resources" → "Resource Management"

Step 2: Navigate to the RPKI Dashboard​

  1. In the RIPE NCC portal, click on "RPKI" in the left sidebar
  2. Select "ROAs" to see your current ROA list
  3. Click "Create ROA" to begin

Step 3: Fill in ROA Parameters​

When creating a ROA, you need to specify the following:

ParameterDescriptionExample
PrefixThe IP prefix you want to authorize192.0.2.0/24
Maximum LengthMaximum prefix length for the authorization24
Origin ASThe AS number authorized to originate this prefixAS64496

Important notes on Maximum Length​

  • Setting max length equal to the prefix length (e.g., /24 for a /24 prefix) is the most secure option — it only authorizes the exact prefix.
  • Setting a larger max length (e.g., /32 for a /24 prefix) allows the AS to announce more specific routes.
  • Best practice: keep max length equal to the prefix length unless you have a specific reason to allow more specifics.
warning

Setting a max length greater than the prefix length can expose you to sub-prefix hijacking. Only increase it if you actually need to announce more specific prefixes.

Step 4: Create the ROA via the Web Interface​

  1. Enter the prefix (e.g., 192.0.2.0/24)
  2. Set the maximum prefix length (e.g., 24)
  3. Enter the Origin AS number (e.g., AS64496)
  4. Click "Add"
  5. Review the ROA details and click "Publish"

Step 5: Create the ROA via the API​

You can also create ROAs programmatically using the RIPE NCC API:

curl -X POST "https://my.ripe.net/api/rpki/roas" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{
"added": [
{
"asn": "AS64496",
"prefix": "192.0.2.0/24",
"maximalLength": 24
}
],
"deleted": []
}'

Step 6: Verify the ROA​

After creating the ROA, verify it is published correctly:

  1. Go to RPKI Validator or use the RIPE Stat tool
  2. Search for your prefix
  3. The status should show "Valid" for your AS and prefix combination

You can also verify using the command line:

# Check ROA status using RIPE Stat API
curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64496&prefix=192.0.2.0/24" | jq '.data.validating_roas'

Creating ROAs for IPv6​

The process is identical for IPv6 prefixes. Example:

ParameterValue
Prefix2001:db8::/32
Maximum Length48
Origin ASAS64496
tip

For IPv6, a common practice is to set max length to /48 for a /32 allocation, as many operators assign /48 prefixes to customers.

Common Mistakes to Avoid​

  1. Forgetting to create ROAs for all announced prefixes — Any prefix without a ROA will have an RPKI status of "Not Found", and networks enforcing RPKI may eventually filter these.
  2. Creating ROAs with the wrong AS number — This will cause your routes to be marked as "Invalid" and they will be dropped by RPKI-enforcing networks.
  3. Not creating ROAs before changing upstream providers — Create the new ROA before decommissioning the old one to avoid route invalidation during the transition.
  4. Setting max length too broadly — Keep it as restrictive as possible.