RTBH + RPKI is quite the hot topic in recent days! 

This is a problem without a go-to, standard solution. I wanted to say I’ll be talking about some long-invalid prefixes in October at NANOG 98 ( 
https://nanog.org/events/nanog-98/content/5843/ ) where one of my focuses is RTBH hijacks and filtering. A recording will be made available afterward.

Salvador (or others), if you’re interested in a router feature knob that could selectively ignore maxLength of ROAs while (only) performing RTBH route validation, I can share at least the Juniper and Cisco feature requests I’ve submitted. Let me know. 

Thanks, 



--
Bryton Herdes
Principal Network Engineer
AS13335 - Cloudflare

On Sat, Aug 8, 2026 at 1:47 PM Salvador Bertenbreiter <salvadorb@gmail.com> wrote:
Hi all,
A quick question for those using RTBH together with RPKI.

How do you handle /32 announcements in IPv4 or /128 in IPv6 when the prefix has a ROA with a maxLength of /24 or /48?

One option would be to extend the ROA to /32 or /128, but I’m not fully comfortable with that since it would also make other more-specifics valid.

The other option would be to keep the ROA as it is and still announce the host route for RTBH, but in that case it would be RPKI Invalid. Do upstreams normally make an exception for routes marked as blackhole, or are they dropped by RPKI before the RTBH policy is applied?

Creating a specific ROA at the time of the attack also doesn’t seem very practical because of propagation times.

How are you handling this in production?

Regards,

Salvador
-----
To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/routing-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/