Re: afrinic rpki issue

2023-06-14 Thread Alex Band
Hi Carlos, Happy to hear everything is working fine with the latest version of Routinator. At lot of work has been put into making fetching and validating RPKI data more robust since the (over two year old) version of Routinator that you were running. I want to make an important point for

Re: afrinic rpki issue

2023-06-14 Thread Carlos Friaças via NANOG
Greetings, My issue seems to be solved. It seems the Afrinic glitch is incompatible with the version of routinator i was using. So i updated to the last version (0.12.1), and now i can get Afrinic's ROAs again :-) Thanks Alex and Cedrick! Best Regards, Carlos

Re: afrinic rpki issue

2023-06-14 Thread Carlos Friaças via NANOG
On Wed, 14 Jun 2023, Alex Band wrote: Hi Carlos, Hi Alex, All, Because of the issues that AfriNIC is facing, they are forcing all traffic from HTTPS to rsync, so you should check if rsync can properly set up outbound connections from your machine. What?s the output you get when you

Re: afrinic rpki issue

2023-06-14 Thread Alex Band
Hi Carlos, Because of the issues that AfriNIC is facing, they are forcing all traffic from HTTPS to rsync, so you should check if rsync can properly set up outbound connections from your machine. What’s the output you get when you rsync rsync://rpki.afrinic.net/repository/ ? I do an

Re: afrinic rpki issue

2023-06-14 Thread Cedrick Adrien Mbeyet
Hi Carlos, We currently have a degradation on our RPKI services. We had to disable the RRDP service request so it can fall back to RSYNC in the meantime that the team works on ways to optimize the availability of the service. However, this was prior to 1st of June. We will still investigate just

Re: afrinic rpki issue

2023-06-14 Thread Carlos Friaças via NANOG
Hi All, Did this issue resurface some days ago...? I had nearly 6000 ROAs on June 1st. That went to ZERO on June 2nd. I'm using routinator. Should i have changed something in my config to accomodate for some change? Best Regards, Carlos On Sun, 20 Nov 2022, Cedrick Adrien Mbeyet wrote:

Re: afrinic rpki issue

2022-11-20 Thread Cedrick Adrien Mbeyet
Hi Job, Thank you for this good analysis and for sharing your findings. The issue has since been fixed and the team will publish a post-mortem accordingly once we are done with making sure the issue will not reappear. Your recommendation is well noted and I cc my colleague so that they can take

Re: afrinic rpki issue

2022-11-20 Thread Job Snijders via NANOG
Hi all, It appears PacketVis correctly identified an issue. AFRINIC's self-signed root AfriNIC.cer [1] points via its SIA to 'afrinic-ca.cer' [2] which in turn references a RPKI Manifest named 'K1eJenypZMPIt_e92qek2jSpj4A.mft'. The K1eJenypZMPIt_e92qek2jSpj4A Manifest lists 499 Certificate

Re: afrinic rpki issue

2022-11-20 Thread Cedrick Adrien Mbeyet
Hi Randy, Thank you for sharing this information. Our team is investigating the alert. Best regards, == Cedrick Adrien MBEYET Ebene Cybercity, Mauritius +230 5851 7674 +++ Never give up, Keep moving forward +++ On Sun, Nov 20, 2022 at 8:37 AM Randy Bush wrote: >

afrinic rpki issue

2022-11-19 Thread Randy Bush
From: PacketVis Date: Sun, 20 Nov 2022 04:30:44 + Possible TA malfunction or incomplete VRP file: 73.95% of the ROAs disappeared from afrinic See more details about the event: