Skip to main content

RPKI Certificate Tree Validation by the RIPE NCC RPKI Validator

Document Type Replaced Internet-Draft (sidrops WG)
Authors Oleg Muravskiy , Tim Bruijnzeels
Last updated 2016-12-01 (Latest revision 2016-10-31)
Replaces draft-tbruijnzeels-sidr-validation-local-cache
Replaced by RFC 8488
Stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Expired & archived
plain text xml htmlized pdfized bibtex
Stream WG state WG Document
Document shepherd (None)
IESG IESG state Replaced by draft-ietf-sidrops-rpki-tree-validation
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD Joel Jaeggli
Send notices to (None)
This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at:


This document describes the approach to validate the content of the RPKI certificate tree, as used by the RIPE NCC RPKI Validator. This approach is independent of a particular object retrieval mechanism. This allows it to be used with repositories available over the rsync protocol, the RPKI Repository Delta Protocol, and repositories that use a mix of both.


Oleg Muravskiy
Tim Bruijnzeels

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)