Hi Salvador,
One option would be to extend the ROA to /32 or /128, but I’m not fully comfortable with that since it would also make other more-specifics valid.
Why not? That is the most optimal solution for secure RTBH filtering in my opinion. Increase your maxLength, plus implement RFC9234 to validate the peer role, and ASPA to validate the path. I think this is the path we as an industry should be going down, not ignoring maxLength or relying on IRR derived prefix filters. (because I'm quite lazy, here is a previous post I wrote explaining why I think this is the way forward: https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/Q2GYREV3...) With kind regards, James Bensley (he/him) ________________________________________ From: Salvador Bertenbreiter <salvadorb@gmail.com> Sent: 08 August 2026 20:47 To: routing-wg@ripe.net <routing-wg@ripe.net> Subject: [routing-wg] RTBH and RPKI ⚠️ Caution: This email originated from outside of your organization. Do not click on links or open attachments unless you recognize the sender and know the content is safe. Hi all, A quick question for those using RTBH together with RPKI. How do you handle /32 announcements in IPv4 or /128 in IPv6 when the prefix has a ROA with a maxLength of /24 or /48? One option would be to extend the ROA to /32 or /128, but I’m not fully comfortable with that since it would also make other more-specifics valid. The other option would be to keep the ROA as it is and still announce the host route for RTBH, but in that case it would be RPKI Invalid. Do upstreams normally make an exception for routes marked as blackhole, or are they dropped by RPKI before the RTBH policy is applied? Creating a specific ROA at the time of the attack also doesn’t seem very practical because of propagation times. How are you handling this in production? Regards, Salvador [CompanySignature] Inter..link GmbH | Boxhagener Straße 80, 10245 Berlin, Germany | Managing Directors: Marc Korthaus, Theo Voss | Commercial Register: Amtsgericht Charlottenburg, HRB 138876 | VAT ID: DE281288887 | Email: hello@inter.link<mailto:hello@inter.link> | Web: inter.link<https://inter.link>