Hi all, To clarify:
On 26 Aug 2026, at 14:52, Havard Eidnes via routing-wg <routing-wg@ripe.net> wrote:
I'll have to admit that I've not looked too closely under the covers, but to my mind, if I originate 192.168.0.0/16 into the routing system, and do not want to authorize any longer routes in this address space than this /16, do I not then use the maxLength attribute to say "16"? That's certainly what it looks like to me through the RIPE NCC RPKI ROA issuance assistant..
The RIPE NCC RPKI Dashboard expects and explicit max length that defaults to the actual prefix length. This is essentially done this way to keep the UI simple. It forces the user to make an explicit choice (go with the default or change it). On the encoded ROA object the max length is omitted if it matches the prefix length. Kind regards, Tim Bruijnzeels Principal Engineer RPKI RIPE NCC