Hi, On Wed, 26 Aug 2026 at 09:40, Nick Hilliard wrote:
I'm curious why the RPKI makes a good tool for handling ddos. Most ddos incidents are fast flux, and the RPKI is not. Ok, there might be prolonged incidents where an RPKI object of some form could provide distributed benefits, but ultimately it takes a while for RPKI objects to be propagated, and this impacts both insertion and removal.
On Wed, Aug 26, 2026 at 10:55:47AM +0100, Ben Cartwright-Cox wrote:
I think this is for customers/suppliers preparing ahead of time for DDoS events (something I am sure we know is hopeful thinking a lot of the time!) rather than the idea of publishing records in immediate response to a attack
In the envisioned normal course of operations you'd create DOAs when you turn up sessions with a new transit provider. (Basically the same moment you'd update your ASPA record to include that new transit provider.) You'd also update your DOA after having received new IP resources from the RIR. This way, the DOA information will have propagated well in advance of eventual RTBH BGP signaling. Kind regards, Job