Skip to main content

Tiebreaking Resource Public Key Infrastructure (RPKI) Trust Anchors
draft-ietf-sidrops-rpki-ta-tiebreaker-01

Document Type Expired Internet-Draft (sidrops WG)
Expired & archived
Authors Job Snijders , Theo Buehler , Ties de Kock
Last updated 2025-08-16 (Latest revision 2025-02-12)
Replaces draft-spaghetti-sidrops-rpki-ta-tiebreaker
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Formats
Additional resources Mailing list discussion
Stream WG state WG Document
Document shepherd (None)
IESG IESG state Expired
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

A Trust Anchor (TA) in the RPKI is represented by a self-signed X.509 Certification Authority (CA) certificate. Over time, Relying Parties (RP) may have acquired multiple different issuances of valid TA certificates from the same TA operator. This document proposes a tiebreaking scheme to be used by RPs to select one TA certificate for certification path validation. This document updates RFC 8630.

Authors

Job Snijders
Theo Buehler
Ties de Kock

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)