Hi, On Mon, Aug 24, 2026 at 03:21:57PM +0000, James Bensley wrote:
One option would be to extend the ROA to /32 or /128, but I???m not fully comfortable with that since it would also make other more-specifics valid.
Why not? That is the most optimal solution for secure RTBH filtering in my opinion. Increase your maxLength, plus implement RFC9234 to validate the peer role, and ASPA to validate the path. I think this is the path we as an industry should be going down, not ignoring maxLength or relying on IRR derived prefix filters.
I don't want to announce my prefixes as a /32 all the time, just because I might want to get an upstream to accept the /32 when I need it for RTBH (or "please wash DDoS") purposes. Also, I do not want the /32 to be visible world wide. *Not* announcing the /32 globally when there is a valid ROA opens a huge door for everybody and their dog to spoof that /32. Nah. Gert Doering -- NetMaster -- have you enabled IPv6 on something today...? SpaceNet AG Vorstand: Sebastian v. Bomhard, Karin Schuler, Sebastian Cler Joseph-Dollinger-Bogen 14 Aufsichtsratsvors.: Dr. Frank Thiäner D-80807 Muenchen HRB: 136055 (AG Muenchen) Tel: +49 (0)89/32356-444 USt-IdNr.: DE813185279