Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Pinned post

rpki-client 9.4 has been released! This release imposes restrictions on Trust Anchor certificate validity periods, includes ASPA support for BIRD2, protection against AS0 TALs, and various reliability improvements. Read the release notes here: cdn.openbsd.org/pub/OpenBSD/rp

The key words "MUST", "MUST NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED BUT REPULSIVE", "WRONG BUT WROMANTIC", "FREQUENTLY MISUNDERSTOOD", "NOBODY BOTHERS WITH THIS BIT", "SHOULDN'T REALLY BUT WE WON'T JUDGE", "REQUIRED IN ORDER TO WORK AROUND EVERYONE ELSE'S BUGS", "YOU DO YOU", and "OBVIOUSLY ABSURD BUT VERY COMMON FOR SOME REASON" in this document are to be interpreted as described in RFC 2119.

New (short) RFC: Detecting RPKI Repository Delta Protocol (RRDP) Session Desynchronization rfc-editor.org/rfc/rfc9697.htm Rpki-client was the first to implement Ties’s clever concept

Juicht, allen, juicht! Dankzij de hemelmechanica gaat de zon *vanaf morgen* al iets later onder. Geniet ervan! 😎
(De nachten worden korter vanaf 21/12; 's ochtends is het nog wachten tot 31/12 eer de zon weer vroeger opkomt.)

RFC 9674: Same-Origin Policy for the RPKI Repository Delta Protocol (RRDP), J. Snijders, rfc-editor.org/info/rfc9674 #RFC This document describes a Same-Origin Policy (SOP) requirement for Resource Public Key Infrastructure (RPKI) Repository Delta Protocol (RRDP) servers and clients. Application of a SOP in RRDP client/server communication isolates resources such as Delta and 1/2

RFC 9687: Border Gateway Protocol 4 (BGP-4) Send Hold Timer, J. Snijders, et al., rfc-editor.org/info/rfc9687 #RFC This document defines the SendHoldTimer, along with the SendHoldTimer_Expires event, for the Border Gateway Protocol (BGP) Finite State Machine (FSM). Implementation of the SendHoldTimer helps overcome situations where a BGP connection is not terminated after the 1/2

Our favorite Internet routing protocol - BGP - just got an update!

The mechanism in this RFC should help a bit against zombie routes and other problems rfc-editor.org/rfc/rfc9687.htm

hat tip to @benjojo and Yingzhen Qu for sticking it out with me

rpki-client 9.2 has just now been released! \o/ This is a bugfix release, it is recommended that all users upgrade to this version for improved reliability. Release notes are here marc.info/?l=openbsd-announce&

OpenBSD rpki-client 9.1 has been released. This release contains novel replay attack & DoS countermeasures, bug fixes, and more. Read the full announcement here: marc.info/?l=openbsd-announce&

Proudly made without AI 🙂

The year is 2030.

Computers boot directly into the browser. IDEs are just a web app now, running in the GPU. No one knows why. Or how.

All programs run in 4 nested containers on top of a hypervisor abstracting over the 5 major computational clouds. The last time a branch was predicted correctly, in any CPU anywhere, was 4 years ago.

Cloud costs are withdrawn directly from your retirement fund.

Ext7 just came out, it's written in Javascript and uses AI to guess what the file may contain.

Expiration of ROAs - what is it and how does it work? What to monitor for @dougmadory
and I teamed up to analyze and visualize what's happening under the hood of the RPKI. fastly.com/blog/times-up-how-r

Vreselijk nieuws, Erik Bais is eerder vandaag overleden plotseling. Beeld van een presentatie uit 2019 waar hij ons techneuten op NLNOG leerde hoe te werken onder moeilijke omstandigheden, op vervelende werkvloeren: youtube.com/watch?v=7areInUXby

My dear friend Erik Bais unexpectedly passed away this morning. This is an incredible loss

New RFC published, a thorough revision of the RPKI ROA specification: rfc-editor.org/rfc/rfc9582.htm this update removes a number of ambiguities, while exploring the edges of what’s possible in ASN.1

rpkiviews.dataplane.org
is archiving #RPKI AS0 TAL repository data. Brought to you in partnership with @job and rpkiviews.org.

In today's blog post for @kentikinc, I team up with @jobsnijders of Fastly to review the latest RPKI ROV adoption metrics in light of a major milestone:

For the first time in the history of RPKI, the majority of IPv4 routes in the global routing table are now covered by ROAs. #BGP

kentik.com/blog/rpki-rov-deplo

Show older
BSD Network

bsd.network is a *BSD-adjacent Mastodon Instance. We have a code of conduct.