<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-sidrops-rpkimaxlen" target="https://datatracker.ietf.org/doc/html/draft-ietf-sidrops-rpkimaxlen-12">
   <front>
      <title>The Use of maxLength in the RPKI</title>
      <author initials="Y." surname="Gilad" fullname="Yossi Gilad">
         <organization>Hebrew University of Jerusalem</organization>
      </author>
      <author initials="S." surname="Goldberg" fullname="Sharon Goldberg">
         <organization>Boston University</organization>
      </author>
      <author initials="K." surname="Sriram" fullname="Kotikalapudi Sriram">
         <organization>USA National Institute of Standards and Technology</organization>
      </author>
      <author initials="J." surname="Snijders" fullname="Job Snijders">
         <organization>Fastly</organization>
      </author>
      <author initials="B." surname="Maddison" fullname="Ben Maddison">
         <organization>Workonline Communications</organization>
      </author>
      <date month="July" day="29" year="2022" />
      <abstract>
	 <t>   This document recommends ways to reduce the forged-origin hijack
   attack surface by prudently limiting the set of IP prefixes that are
   included in a Route Origin Authorization (ROA).  One recommendation
   is to avoid using the maxLength attribute in ROAs except in some
   specific cases.  The recommendations complement and extend those in
   RFC 7115.  The document also discusses the creation of ROAs for
   facilitating the use of Distributed Denial of Service (DDoS)
   mitigation services.  Considerations related to ROAs and origin
   validation in the context of destination-based Remotely Triggered
   Discard Route (RTDR) (elsewhere referred to as &quot;Remotely Triggered
   Black Hole&quot;) filtering are also highlighted.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-sidrops-rpkimaxlen-12" />
   
</reference>
