Creating a Role Object
A role object represents a group or function within an organization (e.g., NOC team, abuse department) rather than an individual person. Role objects are the preferred way to provide contact information in the RIPE Database because they are not tied to a single individual and can be maintained over time as staff changes.
Role vs. Person
| Role | Person | |
|---|---|---|
| Represents | A team or function | An individual |
| NIC Handle | e.g., EXMP1-RIPE | e.g., JS1234-RIPE |
| Recommended for | admin-c, tech-c, abuse-c references | Individual accountability |
| Survives staff changes | Yes | No |
RIPE NCC recommends using role objects for admin-c and tech-c references in all your database objects. This way, you only need to update the role object when staff changes, instead of updating every object that references a person.
Prerequisites
Step 1: Open the RIPE Database Web Interface
- Go to https://apps.db.ripe.net
- Click "Create an Object"
- Select "role" from the object type list
Step 2: Fill in the Role Fields
Here is an example of a role object:
role: Example Company NOC
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
phone: +44 20 1234 5678
e-mail: noc@example.com
abuse-mailbox: abuse@example.com
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE
Field Descriptions
| Field | Required | Description |
|---|---|---|
| role | Yes | Name describing the role/team |
| address | Yes | Postal address (multiple lines allowed) |
| phone | Yes | Phone number in international format |
| Yes | Contact email address | |
| abuse-mailbox | No | Dedicated abuse reporting email (required for abuse-c references) |
| nic-hdl | Yes | NIC handle — use AUTO-1 for auto-assignment |
| mnt-by | Yes | Maintainer that protects this object |
| source | Yes | Always RIPE |
Optional Fields
| Field | Description |
|---|---|
| fax-no | Fax number |
| org | Reference to an organization object |
| admin-c | Admin contact within the role |
| tech-c | Technical contact within the role |
| remarks | Free-text remarks |
Step 3: Create via the Web Interface
- Fill in all required fields
- Set
nic-hdl:toAUTO-1— RIPE will assign a unique handle automatically - Set
mnt-by:to your maintainer (e.g.,EXAMPLE-MNT) - Click "Submit"
- Note the assigned NIC handle (e.g.,
EXMP1-RIPE) — you will need it for other objects
Step 4: Create via Syncupdates (API)
curl -X POST "https://syncupdates.db.ripe.net/syncupdates/RIPE" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "DATA=
role: Example Company NOC
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
phone: +44 20 1234 5678
e-mail: noc@example.com
abuse-mailbox: abuse@example.com
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE
" \
--data-urlencode "NEW=yes"
Step 5: Verify the Role Object
whois -h whois.ripe.net EXMP1-RIPE
Or search in the RIPE Database web interface.
Step 6: Update Your Maintainer
After creating the role object, update your maintainer's admin-c: to reference the new role:
mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: EXMP1-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE
Creating an Abuse Role
If you manage IP address space, you are required to have an abuse-c contact. This must be a role object with an abuse-mailbox: field:
role: Example Company Abuse
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
e-mail: abuse@example.com
abuse-mailbox: abuse@example.com
phone: +44 20 1234 5678
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE
The abuse-mailbox must be a monitored, working email address. RIPE NCC periodically tests abuse contacts and may flag resources with non-functional abuse addresses.
Typical Role Structure for an Organization
Most organizations need at least two role objects:
| Role | Purpose | Used as |
|---|---|---|
| NOC / Technical | Network operations and technical contact | admin-c, tech-c |
| Abuse | Handling abuse reports | abuse-c on organisation object |
Common Mistakes
- Using
nic-hdl: AUTO-1and forgetting to note the assigned handle — Write down the NIC handle returned after creation. You need it for referencing in other objects. - Missing
abuse-mailboxon the abuse role — Without this field, the role cannot be used as anabuse-creference. - Not protecting the role with a maintainer — Always set
mnt-byto prevent unauthorized modifications. - Using a person object instead of a role for
abuse-c— Theabuse-cattribute on an organisation object must reference a role, not a person.
Next Steps
- Create ROA objects to protect your route announcements
- Set up RPKI synchronization