Creating ROA in RIPE Database
A Route Origin Authorization (ROA) is a cryptographically signed object that authorizes a specific Autonomous System (AS) to originate a particular IP prefix. ROAs are the foundation of RPKI-based route origin validation.
Step 1: Log in to RIPE NCC Portal
- Go to https://my.ripe.net
- Sign in with your RIPE NCC Access credentials
- Navigate to "My Resources" → "Resource Management"
Step 2: Navigate to the RPKI Dashboard
- In the RIPE NCC portal, click on "RPKI" in the left sidebar
- Select "ROAs" to see your current ROA list
- Click "Create ROA" to begin
Step 3: Fill in ROA Parameters
When creating a ROA, you need to specify the following:
| Parameter | Description | Example |
|---|---|---|
| Prefix | The IP prefix you want to authorize | 192.0.2.0/24 |
| Maximum Length | Maximum prefix length for the authorization | 24 |
| Origin AS | The AS number authorized to originate this prefix | AS64496 |
Important notes on Maximum Length
- Setting max length equal to the prefix length (e.g.,
/24for a/24prefix) is the most secure option — it only authorizes the exact prefix. - Setting a larger max length (e.g.,
/32for a/24prefix) allows the AS to announce more specific routes. - Best practice: keep max length equal to the prefix length unless you have a specific reason to allow more specifics.
Setting a max length greater than the prefix length can expose you to sub-prefix hijacking. Only increase it if you actually need to announce more specific prefixes.
Step 4: Create the ROA via the Web Interface
- Enter the prefix (e.g.,
192.0.2.0/24) - Set the maximum prefix length (e.g.,
24) - Enter the Origin AS number (e.g.,
AS64496) - Click "Add"
- Review the ROA details and click "Publish"
Step 5: Create the ROA via the API
You can also create ROAs programmatically using the RIPE NCC API:
curl -X POST "https://my.ripe.net/api/rpki/roas" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{
"added": [
{
"asn": "AS64496",
"prefix": "192.0.2.0/24",
"maximalLength": 24
}
],
"deleted": []
}'
Step 6: Verify the ROA
After creating the ROA, verify it is published correctly:
- Go to RPKI Validator or use the RIPE Stat tool
- Search for your prefix
- The status should show "Valid" for your AS and prefix combination
You can also verify using the command line:
# Check ROA status using RIPE Stat API
curl -s "https://stat.ripe.net/data/rpki-validation/data.json?resource=AS64496&prefix=192.0.2.0/24" | jq '.data.validating_roas'
Creating ROAs for IPv6
The process is identical for IPv6 prefixes. Example:
| Parameter | Value |
|---|---|
| Prefix | 2001:db8::/32 |
| Maximum Length | 48 |
| Origin AS | AS64496 |
For IPv6, a common practice is to set max length to /48 for a /32 allocation, as many operators assign /48 prefixes to customers.
Common Mistakes to Avoid
- Forgetting to create ROAs for all announced prefixes — Any prefix without a ROA will have an RPKI status of "Not Found", and networks enforcing RPKI may eventually filter these.
- Creating ROAs with the wrong AS number — This will cause your routes to be marked as "Invalid" and they will be dropped by RPKI-enforcing networks.
- Not creating ROAs before changing upstream providers — Create the new ROA before decommissioning the old one to avoid route invalidation during the transition.
- Setting max length too broadly — Keep it as restrictive as possible.