Skip to main content

Creating a Role Object

A role object represents a group or function within an organization (e.g., NOC team, abuse department) rather than an individual person. Role objects are the preferred way to provide contact information in the RIPE Database because they are not tied to a single individual and can be maintained over time as staff changes.

Role vs. Person​

RolePerson
RepresentsA team or functionAn individual
NIC Handlee.g., EXMP1-RIPEe.g., JS1234-RIPE
Recommended foradmin-c, tech-c, abuse-c referencesIndividual accountability
Survives staff changesYesNo
tip

RIPE NCC recommends using role objects for admin-c and tech-c references in all your database objects. This way, you only need to update the role object when staff changes, instead of updating every object that references a person.

Prerequisites​

Step 1: Open the RIPE Database Web Interface​

  1. Go to https://apps.db.ripe.net
  2. Click "Create an Object"
  3. Select "role" from the object type list

Step 2: Fill in the Role Fields​

Here is an example of a role object:

role: Example Company NOC
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
phone: +44 20 1234 5678
e-mail: noc@example.com
abuse-mailbox: abuse@example.com
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE

Field Descriptions​

FieldRequiredDescription
roleYesName describing the role/team
addressYesPostal address (multiple lines allowed)
phoneYesPhone number in international format
e-mailYesContact email address
abuse-mailboxNoDedicated abuse reporting email (required for abuse-c references)
nic-hdlYesNIC handle — use AUTO-1 for auto-assignment
mnt-byYesMaintainer that protects this object
sourceYesAlways RIPE

Optional Fields​

FieldDescription
fax-noFax number
orgReference to an organization object
admin-cAdmin contact within the role
tech-cTechnical contact within the role
remarksFree-text remarks

Step 3: Create via the Web Interface​

  1. Fill in all required fields
  2. Set nic-hdl: to AUTO-1 — RIPE will assign a unique handle automatically
  3. Set mnt-by: to your maintainer (e.g., EXAMPLE-MNT)
  4. Click "Submit"
  5. Note the assigned NIC handle (e.g., EXMP1-RIPE) — you will need it for other objects

Step 4: Create via Syncupdates (API)​

curl -X POST "https://syncupdates.db.ripe.net/syncupdates/RIPE" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "DATA=
role: Example Company NOC
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
phone: +44 20 1234 5678
e-mail: noc@example.com
abuse-mailbox: abuse@example.com
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE
" \
--data-urlencode "NEW=yes"

Step 5: Verify the Role Object​

whois -h whois.ripe.net EXMP1-RIPE

Or search in the RIPE Database web interface.

Step 6: Update Your Maintainer​

After creating the role object, update your maintainer's admin-c: to reference the new role:

mntner: EXAMPLE-MNT
descr: Example Company Maintainer
admin-c: EXMP1-RIPE
upd-to: noc@example.com
auth: SSO user@example.com
mnt-by: EXAMPLE-MNT
source: RIPE

Creating an Abuse Role​

If you manage IP address space, you are required to have an abuse-c contact. This must be a role object with an abuse-mailbox: field:

role: Example Company Abuse
address: 71-75 Shelton Street
address: Covent Garden
address: London WC2H 9JQ
address: United Kingdom
e-mail: abuse@example.com
abuse-mailbox: abuse@example.com
phone: +44 20 1234 5678
nic-hdl: AUTO-1
mnt-by: EXAMPLE-MNT
source: RIPE
warning

The abuse-mailbox must be a monitored, working email address. RIPE NCC periodically tests abuse contacts and may flag resources with non-functional abuse addresses.

Typical Role Structure for an Organization​

Most organizations need at least two role objects:

RolePurposeUsed as
NOC / TechnicalNetwork operations and technical contactadmin-c, tech-c
AbuseHandling abuse reportsabuse-c on organisation object

Common Mistakes​

  1. Using nic-hdl: AUTO-1 and forgetting to note the assigned handle — Write down the NIC handle returned after creation. You need it for referencing in other objects.
  2. Missing abuse-mailbox on the abuse role — Without this field, the role cannot be used as an abuse-c reference.
  3. Not protecting the role with a maintainer — Always set mnt-by to prevent unauthorized modifications.
  4. Using a person object instead of a role for abuse-c — The abuse-c attribute on an organisation object must reference a role, not a person.

Next Steps​

  1. Create ROA objects to protect your route announcements
  2. Set up RPKI synchronization