Hello, Since DNS root servers are a critical service, I've been checking if their prefixes could be origin-validated on BGP using RPKI. It would be good if we could secure them.
So I've built this website monitoring the status of DNS root servers prefixes once a day: http://rpki.me/dns.html (So far I'm using LINX route-views monitor and RIR's RPKI repo + CA0 repo) RIPE NCC already told me that they will secure the v4 address of K-root very soon. I also wrote to several other root server operators, but I'm still waiting an answer. Some prefixes are in v4 legacy address space (not administered by ARIN: with RegDate < 22 Dec 1997). I suppose that this might be a problem in order to obtain certificates covering them from ARIN. Regards -- Daniele Iamartino Computer engineering student at Politecnico di Milano, Italy _______________________________________________ sidr mailing list [email protected] https://www.ietf.org/mailman/listinfo/sidr
