@techreport{nro-sidrops-ta-constraints-00, number = {draft-nro-sidrops-ta-constraints-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-nro-sidrops-ta-constraints/00/}, author = {Tom Harrison and Tim Bruijnzeels and Carlos Martinez-Cagnazzo and Mark Kosters and Yogesh Chadee}, title = {{RPKI Trust Anchor Constraints}}, pagetotal = 29, year = 2025, month = oct, day = 20, abstract = {Resource Public Key Infrastructure (RPKI) Relying Parties (RPs) are commonly configured with five Trust Anchors (TAs), one for each of the Regional Internet Registries (RIRs). Each TA operator is able to make arbitrary RPKI statements about resources independently of the other TA operators: for example, one TA could issue a Route Origin Authorization (ROA) for resources that have actually been assigned to another TA. This document specifies a protocol that allows a set of TAs to make signed statements that assert their consensus as to the resources for which each TA is authoritative.}, }