rpki-client / rpki-client-portable

Portability shim for OpenBSD's rpki-client

Home Page:https://rpki-client.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Add ARIN TAL to OpenBSD upstream repository?

robert-scheck opened this issue · comments

Today, RIPE NCC Academy made me aware that there recently was a change to management of the Trust Anchor Locator (TAL) for ARIN’s RPKI service:

Users are no longer required to sign the ARIN Relying Party Agreement to redistribute information from ARIN’s Online Resource Certification PKI (“ORCP”) in a machine readable format for network routing purposes. We are making this modification in response to feedback from the Internet community and in the hope that it will accelerate RPKI deployment in the ARIN region. We ask that developers of Relying Party software include the ARIN TAL in future releases. We encourage all participants in the RPKI community to download the ARIN TAL and add it to existing validator deployments where previously it has not been included.

Is there anything that prevents from including ARIN TAL to https://github.com/rpki-client/rpki-client-openbsd/tree/master/src/etc/rpki – or could this just take place before the next release?

The ARIN TAL is still covered by the RPA and there section 9:

9. MACHINE-READABLE FORMAT DISTRIBUTION. Notwithstanding the foregoing, you may make available to any third
party the information made available through the ORCP Services in a machine-readable format for networking routing
purposes subject to the following requirements

(a) the third party receiving such data has entered into a Relying Party Agreement with ARIN; or
(b) You have passed through terms that are at least as protective of ARIN as the terms set forth in Article 5, 6 and 7 and
Sections 8(a), 8(b), 8(c), and 8(f) to the third party receiving such data, via browse-wrap, clickwrap, or other manner
for which such third party is legally obligated to said terms.

We have no way and no willingness to enforce anything for ARIN as required by paragraph 9b.
Therefore we decided to not include the ARIN TAL in rpki-client.