SlideShare ist ein Scribd-Unternehmen logo
1 von 31
Downloaden Sie, um offline zu lesen
1
(More than an)
APNIC Policy
implementation
update
George Kuo
34th TWNIC OPM
8 October 2020
2
Congratulations!
33
Overview
• A brief introduction to the Policy Development Process
(PDP)
• Policy implementation status from APNIC 50
– prop – 132: RPKI ROAs for unallocated and unassigned APNIC
address space
– prop – 125 Validation of “abuse-mailbox” and other IRT emails
44
Policies, proposals and the PDP
• APNIC policies determine the way Internet number
resources (IP addresses and ASNs) are distributed,
registered and managed in the Asia Pacific
• A policy proposal is a formal, written submission that
outlines an idea for a new policy; if a policy proposal is
successful it will become a policy
• Policy Development Process (PDP) is the procedure for
discussing and deciding proposed changes to APNIC
policies
55
Important values of the PDP
Open Transparent Bottom-up
Anyone can
participate in
submitting proposals,
discussing policies
and making
decisions
PDP is driven by
people from the
community
Policy documents,
policy mailing list,
and Policy SIG are
accessible to all
開放參與 資訊公開透明 由社群主導
6
From policy proposals to implementation
Start here
APNIC Secretariat
facilitates policy
discussion and stays
neutral in the debate
7
prop-132
RPKI ROAs for unallocated and unassigned APNIC address space
88
prop-132 v3
https://www.apnic.net/community/policy/proposals/prop-132
99
Proposal history
Proposal
v1, v2
submitted
Aug 2019
Proposal v3
submitted
Sep 2019
Consensus
reached
APNIC 48
Sep 2019
Proposal
endorsed
by EC
Dec 2019
Implemented
Sep 2020
https://www.apnic.net/community/policy/proposals/prop-132
1010
Resource Public Key Infrastructure (RPKI)
• RPKI uses hierarchical Public Key Infrastructure that binds
Internet number resources to a public key via certificates
(x.509 certificate standards)
– The hierarchy of resource certificates are aligned to the Internet
number resource allocation structure
• Via the resource certification service, resource holders can
encrypt and sign BGP routing advertisements digitally by
creating ‘ROAs’ (Route Origin Authorizations)
1111
RFC 6483
• AS0 is reserved by IANA so that it may be used to identify
non-routed networks
• A ROA with a subject of AS0 (AS0 ROA) is an attestation by
the holder of a prefix that the prefix described in the ROA,
and any more specific prefix, should not be used in a
routing context
1212
prop-132 implementation
• APNIC’s RPKI system now publishes and maintains an AS0
ROA for all undelegated resources recorded in APNIC’s
registry
• It is a fully deployed service with systems monitoring 24/7
integrated into our operations platforms
• Undelegated resources are the IPv4 and IPv6 addresses
listed as ‘available’ or ‘reserved’ in the daily published
delegated statistics files
• http://ftp.apnic.net/stats/apnic/
1313
prop-132 implementation
• Deploy an initial testbed operated on the ‘Krill’ system from
NLNet Labs
– A temporary, soft-keyed Trust Anchor (TA) in a Trust Anchor Locator
(TAL) file created based on the daily delegated files
– The ‘repository’ published inside APNIC’s VM on the test network
• Introduce a delay to prevent accidental exclusions (if
delegated stats files are out of synchronization with the
registry)
– Approx. around five mins, after live updates to the registry
(delegations or returns) occur, apply updates to both main RPKI and
AS0 RPKI state
1414
Similar AS0 ROA policies in other region?
RIR Status
APNIC Implemented
AFRINIC Under discussion
ARIN No proposal
LACNIC Consensus reached, awaiting implementation
RIPE NCC Proposal withdrawn
1515
What’s next?
• Be sure to keep your ROAs updated!
• Try Route Origin Validation (ROV) and share your
experience
– Invalid advertisements (advertisements that contradict ROA
information) may be discarded or de-preferenced
16
prop-125
Validation of “abuse-mailbox” and other IRT emails
1717
Incident Response Team (IRT) object
1717
18
prop- 125 v1
https://www.apnic.net/community/policy/proposals/prop-125
1919
Proposal history
Proposal
submitted
Aug 2018
Consensus
reached
APNIC 46
Sep 2018
Proposal
endorsed by EC
Sep 2018
Implementation
Phase 1
completed
Jun 2019
Implementation
Phase 2
completed
Dec 2019
Implementation
Phase 3 ongoing
https://www.apnic.net/community/policy/proposals/prop-125
2020
prop-125 implementation
• Phase one – completed
– Validations for all IRTs associated with portable
delegations
– Created new escalation mailbox (excalation-
abuse@apnic.net)
• Phase two – completed
– Validations for all IRTs associated with non-portable
customer assignments
• Phase three – ongoing
– Improved UI/UX and resolved software issues
reported from Members
– Added ‘abuse-c’ attribute to whois records
– MyAPNIC restriction to be reinstated soon
APNIC
Members
End user
Parent,
portable
delegations
Child,
non portable
customer
assignments
2121
Validation process
• Frequency
– Every six months
• Failure to validate
– IRT objects marked invalid after 15 days
– Restricted Member access to MyAPNIC
after 30 days
• Requirement
– Abuse-mailbox responsive to legitimate
reports
– Validation requests responded to by human
2222
Some stats on validation
22
In the last six months:
• 5,779 Members requested to validate emails
• 6,845 email validation requests issued
• 6,003 email validation requests confirmed
• 87.7% validation rate
As of Sep 2020
2323
Feedback from APNIC Members
23
Software vendor:
“I am concerned about clicking links sent to verify my IRT. Hopefully, there is a better way.”
Internet Service Provider:
“Is this email for validate IRT contact? Any evidence that your email is from APNIC? As I
receive many spam mail and hacker mail, so it is hard for me to trust and click on any links
without knowing it is real or fake account."
2424
Feedback from APNIC Members
24
Banking/Financial
“These emails are pretty problematic – they have a link to click on and it asks to validate an
email address. These are very suspect in an email. I had to look at the email header to verify
it did indeed come from APNIC.
University/CERT
“This type of automated testing is an abuse of our abuse address, is mindless robotic
punishment of client organizations without regard to the impact upon those organizations
and without any consideration of the realities of email deliverability or the pressures on
abuse or other addresses of an organization from spam and other email threats.
I would suggest you cease this automated testing.”
2525
APNIC Secretariat recommendations
25
• Investigate using other methods of validation, instead of
unique links in emails
• Change validation cycle from every six months to once
annually
• Consider deprecating the ‘email’ attribute in IRT objects and
validating only ‘abuse-mailbox’. Members will then only be
required to validate one email address
Have your say and let us know if you have any
suggestions!
2626
Similar IRT policy in other region?
RIR Status
APNIC Validation of “abuse-mailbox”
and other IRT emails
Implemented
AFRINIC “Abuse Contact Policy
Update (Draft 6)”
Under discussion
ARIN ARIN-prop-264: Validation of
Abuse-mailbox
Abandoned
LACNIC LAC-2018-5: Registration
and validation of abuse
contact
Consensus reached, awaiting
implementation
RIPE NCC Validation of abuse-mailbox Proposal withdrawn
2727
What’s next?
• Continue working with the community to amend the policy
to address current concerns
– Negative feedback about the overall process
– Many raising security concerns about clicking on email links
• Simplifying the process and reducing the frequency of
validation should help alleviate some of the pain points
• Find the balance between ease of validation and achieving
the policy goal — to ensure accurate and contactable
network abuse contacts
28
FUTURE CONFERENCES
Your participation benefits all
2929
You are invited to attend
• APRICOT 2021 and APNIC 51
– Online only (https://www.2021.apricot.net/)
– 22 February to 4 March 2021
• APNIC 52
– Hopefully in person and online
– Sapporo, Japan
– 8 to 16 September 2021
3030
By participating you can...
Make new friends
Polish tech skills Share your experience
Hear from experts
Promote your organization
Help develop policies
3131
References
• https://tools.ietf.org/html/rfc6483
• https://www.apnic.net/community/participate/mailinglists/
• https://www.apnic.net/community/policy/proposals/
• https://www.apnic.net/community/policy/process/
• https://conference.apnic.net/50/assets/files/APCS790/prop-125-
implementation-updateV2.pdf
• https://conference.apnic.net/50/assets/files/APCS790/prop-132-
Implementation.pdf
• https://www.apnic.net/events/conferences/
• https://academy.apnic.net/en/course/policy-development-process-course/
• https://training.apnic.net/

Weitere ähnliche Inhalte

Was ist angesagt?

Connecting your bank to the Internet
Connecting your bank to the InternetConnecting your bank to the Internet
Connecting your bank to the InternetAPNIC
 
IANA: Who, What, Why?
IANA: Who, What, Why?IANA: Who, What, Why?
IANA: Who, What, Why?APNIC
 
JPNIC Update
JPNIC UpdateJPNIC Update
JPNIC UpdateAPNIC
 
IDNOG 2: IPv4 Transfers
IDNOG 2: IPv4 TransfersIDNOG 2: IPv4 Transfers
IDNOG 2: IPv4 TransfersAPNIC
 
IPv4 transfer presentation, SGNOG4
IPv4 transfer presentation, SGNOG4IPv4 transfer presentation, SGNOG4
IPv4 transfer presentation, SGNOG4APNIC
 
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasRIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasAPNIC
 
IANA Transition Update, August 2016
IANA Transition Update, August 2016IANA Transition Update, August 2016
IANA Transition Update, August 2016APNIC
 
The IANA Stewardship Transition Overview & Background
The IANA Stewardship Transition Overview & Background The IANA Stewardship Transition Overview & Background
The IANA Stewardship Transition Overview & Background APNIC
 
IANA Activities Update by Elise Gerich [APRICOT 2015]
IANA Activities Update by Elise Gerich [APRICOT 2015]IANA Activities Update by Elise Gerich [APRICOT 2015]
IANA Activities Update by Elise Gerich [APRICOT 2015]APNIC
 
Internet measurement-ARM3/bdNOG1
Internet measurement-ARM3/bdNOG1Internet measurement-ARM3/bdNOG1
Internet measurement-ARM3/bdNOG1APNIC
 
Measuring the end user
Measuring the end userMeasuring the end user
Measuring the end userAPNIC
 
An Update on Mobility in Today's Internet
An Update on Mobility in Today's InternetAn Update on Mobility in Today's Internet
An Update on Mobility in Today's InternetAPNIC
 
IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27APNIC
 
APNIC Update: PITA 19
APNIC Update: PITA 19APNIC Update: PITA 19
APNIC Update: PITA 19APNIC
 
BdNOG 3: A closer look at IPv4 transfers
BdNOG 3: A closer look at IPv4 transfersBdNOG 3: A closer look at IPv4 transfers
BdNOG 3: A closer look at IPv4 transfersAPNIC
 
36th TWNIC OPM: APNIC 52 Policy Update
36th TWNIC OPM: APNIC 52 Policy Update36th TWNIC OPM: APNIC 52 Policy Update
36th TWNIC OPM: APNIC 52 Policy UpdateAPNIC
 
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]APNIC
 
LACNIC 25 - APNIC Update
LACNIC 25 - APNIC UpdateLACNIC 25 - APNIC Update
LACNIC 25 - APNIC UpdateAPNIC
 
Measuring IPv6 ISP performance
Measuring IPv6 ISP performanceMeasuring IPv6 ISP performance
Measuring IPv6 ISP performanceAPNIC
 

Was ist angesagt? (20)

Connecting your bank to the Internet
Connecting your bank to the InternetConnecting your bank to the Internet
Connecting your bank to the Internet
 
IANA: Who, What, Why?
IANA: Who, What, Why?IANA: Who, What, Why?
IANA: Who, What, Why?
 
JPNIC Update
JPNIC UpdateJPNIC Update
JPNIC Update
 
CCTNS IN KARNATAKA- EXPERIENCE SHARING
CCTNS IN KARNATAKA- EXPERIENCE SHARINGCCTNS IN KARNATAKA- EXPERIENCE SHARING
CCTNS IN KARNATAKA- EXPERIENCE SHARING
 
IDNOG 2: IPv4 Transfers
IDNOG 2: IPv4 TransfersIDNOG 2: IPv4 Transfers
IDNOG 2: IPv4 Transfers
 
IPv4 transfer presentation, SGNOG4
IPv4 transfer presentation, SGNOG4IPv4 transfer presentation, SGNOG4
IPv4 transfer presentation, SGNOG4
 
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE AtlasRIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
RIPE NCC Measurements Tools Workshop: RIPEstat and RIPE Atlas
 
IANA Transition Update, August 2016
IANA Transition Update, August 2016IANA Transition Update, August 2016
IANA Transition Update, August 2016
 
The IANA Stewardship Transition Overview & Background
The IANA Stewardship Transition Overview & Background The IANA Stewardship Transition Overview & Background
The IANA Stewardship Transition Overview & Background
 
IANA Activities Update by Elise Gerich [APRICOT 2015]
IANA Activities Update by Elise Gerich [APRICOT 2015]IANA Activities Update by Elise Gerich [APRICOT 2015]
IANA Activities Update by Elise Gerich [APRICOT 2015]
 
Internet measurement-ARM3/bdNOG1
Internet measurement-ARM3/bdNOG1Internet measurement-ARM3/bdNOG1
Internet measurement-ARM3/bdNOG1
 
Measuring the end user
Measuring the end userMeasuring the end user
Measuring the end user
 
An Update on Mobility in Today's Internet
An Update on Mobility in Today's InternetAn Update on Mobility in Today's Internet
An Update on Mobility in Today's Internet
 
IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27
 
APNIC Update: PITA 19
APNIC Update: PITA 19APNIC Update: PITA 19
APNIC Update: PITA 19
 
BdNOG 3: A closer look at IPv4 transfers
BdNOG 3: A closer look at IPv4 transfersBdNOG 3: A closer look at IPv4 transfers
BdNOG 3: A closer look at IPv4 transfers
 
36th TWNIC OPM: APNIC 52 Policy Update
36th TWNIC OPM: APNIC 52 Policy Update36th TWNIC OPM: APNIC 52 Policy Update
36th TWNIC OPM: APNIC 52 Policy Update
 
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]
Update from the RIPE NCC, by Axel Pawlik [APNIC 38 / Global Reports]
 
LACNIC 25 - APNIC Update
LACNIC 25 - APNIC UpdateLACNIC 25 - APNIC Update
LACNIC 25 - APNIC Update
 
Measuring IPv6 ISP performance
Measuring IPv6 ISP performanceMeasuring IPv6 ISP performance
Measuring IPv6 ISP performance
 

Ähnlich wie 34th TWNIC OPM: APNIC Policy Implementation Update

IDNIC OPM 2023 - Internet Number Registry System
IDNIC OPM 2023 - Internet Number Registry SystemIDNIC OPM 2023 - Internet Number Registry System
IDNIC OPM 2023 - Internet Number Registry SystemAPNIC
 
INNOG 2: APNIC Policy Update
INNOG 2: APNIC Policy UpdateINNOG 2: APNIC Policy Update
INNOG 2: APNIC Policy UpdateAPNIC
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICAPNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcAPNIC
 
NZNOG 2019: APNIC Update
NZNOG 2019: APNIC UpdateNZNOG 2019: APNIC Update
NZNOG 2019: APNIC UpdateAPNIC
 
40th TWNIC Open Policy Meeting: APNIC PDP update
40th TWNIC Open Policy Meeting: APNIC PDP update40th TWNIC Open Policy Meeting: APNIC PDP update
40th TWNIC Open Policy Meeting: APNIC PDP updateAPNIC
 
LEA Workshop dated 09052013
LEA Workshop dated 09052013LEA Workshop dated 09052013
LEA Workshop dated 09052013APNIC
 
PacNOG 25: APNIC Update On INR and APNIC Academy
PacNOG 25: APNIC Update On INR and APNIC Academy PacNOG 25: APNIC Update On INR and APNIC Academy
PacNOG 25: APNIC Update On INR and APNIC Academy APNIC
 
Policy Update ARM 3/bdNOG 1
Policy Update ARM 3/bdNOG 1Policy Update ARM 3/bdNOG 1
Policy Update ARM 3/bdNOG 1APNIC
 
APNIC Secretariat Report
APNIC Secretariat ReportAPNIC Secretariat Report
APNIC Secretariat ReportAPNIC
 
APNIC's Resource Certification Service
APNIC's Resource Certification ServiceAPNIC's Resource Certification Service
APNIC's Resource Certification ServiceAPNIC
 
APNIC Update - Member Briefing
APNIC Update - Member BriefingAPNIC Update - Member Briefing
APNIC Update - Member BriefingAPNIC
 
CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update APNIC
 
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]APNIC
 
APNIC Update for SANOG 24
APNIC Update for SANOG 24APNIC Update for SANOG 24
APNIC Update for SANOG 24APNIC
 

Ähnlich wie 34th TWNIC OPM: APNIC Policy Implementation Update (20)

IDNIC OPM 2023 - Internet Number Registry System
IDNIC OPM 2023 - Internet Number Registry SystemIDNIC OPM 2023 - Internet Number Registry System
IDNIC OPM 2023 - Internet Number Registry System
 
INNOG 2: APNIC Policy Update
INNOG 2: APNIC Policy UpdateINNOG 2: APNIC Policy Update
INNOG 2: APNIC Policy Update
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia Pacifc
 
NZNOG 2019: APNIC Update
NZNOG 2019: APNIC UpdateNZNOG 2019: APNIC Update
NZNOG 2019: APNIC Update
 
40th TWNIC Open Policy Meeting: APNIC PDP update
40th TWNIC Open Policy Meeting: APNIC PDP update40th TWNIC Open Policy Meeting: APNIC PDP update
40th TWNIC Open Policy Meeting: APNIC PDP update
 
Apnic-irme
Apnic-irmeApnic-irme
Apnic-irme
 
LEA Workshop dated 09052013
LEA Workshop dated 09052013LEA Workshop dated 09052013
LEA Workshop dated 09052013
 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono
 
PacNOG 25: APNIC Update On INR and APNIC Academy
PacNOG 25: APNIC Update On INR and APNIC Academy PacNOG 25: APNIC Update On INR and APNIC Academy
PacNOG 25: APNIC Update On INR and APNIC Academy
 
APNIC Policy Update
APNIC Policy Update APNIC Policy Update
APNIC Policy Update
 
Policy Update ARM 3/bdNOG 1
Policy Update ARM 3/bdNOG 1Policy Update ARM 3/bdNOG 1
Policy Update ARM 3/bdNOG 1
 
APNIC Secretariat Report
APNIC Secretariat ReportAPNIC Secretariat Report
APNIC Secretariat Report
 
APNIC's Resource Certification Service
APNIC's Resource Certification ServiceAPNIC's Resource Certification Service
APNIC's Resource Certification Service
 
APNIC Update - Member Briefing
APNIC Update - Member BriefingAPNIC Update - Member Briefing
APNIC Update - Member Briefing
 
CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update
 
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]
APNIC IRM Tutorial, by Sheryl Hermoso [APRICOT 2015]
 
APNIC Update for SANOG 24
APNIC Update for SANOG 24APNIC Update for SANOG 24
APNIC Update for SANOG 24
 

Mehr von APNIC

DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119APNIC
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119APNIC
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119APNIC
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119APNIC
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...APNIC
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonAPNIC
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonAPNIC
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPNIC
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6APNIC
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!APNIC
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023APNIC
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAPNIC
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAPNIC
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAPNIC
 
AFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAPNIC
 

Mehr von APNIC (20)

DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment Status
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressing
 
AFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & Development
 

KĂźrzlich hochgeladen

VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$kojalkojal131
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsThierry TROUIN ☁
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)Damian Radcliffe
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebJames Anderson
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...Diya Sharma
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...SofiyaSharma5
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceDelhi Call girls
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsstephieert
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607dollysharma2066
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Servicesexy call girls service in goa
 

KĂźrzlich hochgeladen (20)

VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with Flows
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girls
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girls
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 

34th TWNIC OPM: APNIC Policy Implementation Update

  • 1. 1 (More than an) APNIC Policy implementation update George Kuo 34th TWNIC OPM 8 October 2020
  • 3. 33 Overview • A brief introduction to the Policy Development Process (PDP) • Policy implementation status from APNIC 50 – prop – 132: RPKI ROAs for unallocated and unassigned APNIC address space – prop – 125 Validation of “abuse-mailbox” and other IRT emails
  • 4. 44 Policies, proposals and the PDP • APNIC policies determine the way Internet number resources (IP addresses and ASNs) are distributed, registered and managed in the Asia Pacific • A policy proposal is a formal, written submission that outlines an idea for a new policy; if a policy proposal is successful it will become a policy • Policy Development Process (PDP) is the procedure for discussing and deciding proposed changes to APNIC policies
  • 5. 55 Important values of the PDP Open Transparent Bottom-up Anyone can participate in submitting proposals, discussing policies and making decisions PDP is driven by people from the community Policy documents, policy mailing list, and Policy SIG are accessible to all 開放參與 資訊公開透明 由社群主導
  • 6. 6 From policy proposals to implementation Start here APNIC Secretariat facilitates policy discussion and stays neutral in the debate
  • 7. 7 prop-132 RPKI ROAs for unallocated and unassigned APNIC address space
  • 9. 99 Proposal history Proposal v1, v2 submitted Aug 2019 Proposal v3 submitted Sep 2019 Consensus reached APNIC 48 Sep 2019 Proposal endorsed by EC Dec 2019 Implemented Sep 2020 https://www.apnic.net/community/policy/proposals/prop-132
  • 10. 1010 Resource Public Key Infrastructure (RPKI) • RPKI uses hierarchical Public Key Infrastructure that binds Internet number resources to a public key via certificates (x.509 certificate standards) – The hierarchy of resource certificates are aligned to the Internet number resource allocation structure • Via the resource certification service, resource holders can encrypt and sign BGP routing advertisements digitally by creating ‘ROAs’ (Route Origin Authorizations)
  • 11. 1111 RFC 6483 • AS0 is reserved by IANA so that it may be used to identify non-routed networks • A ROA with a subject of AS0 (AS0 ROA) is an attestation by the holder of a prefix that the prefix described in the ROA, and any more specific prefix, should not be used in a routing context
  • 12. 1212 prop-132 implementation • APNIC’s RPKI system now publishes and maintains an AS0 ROA for all undelegated resources recorded in APNIC’s registry • It is a fully deployed service with systems monitoring 24/7 integrated into our operations platforms • Undelegated resources are the IPv4 and IPv6 addresses listed as ‘available’ or ‘reserved’ in the daily published delegated statistics files • http://ftp.apnic.net/stats/apnic/
  • 13. 1313 prop-132 implementation • Deploy an initial testbed operated on the ‘Krill’ system from NLNet Labs – A temporary, soft-keyed Trust Anchor (TA) in a Trust Anchor Locator (TAL) file created based on the daily delegated files – The ‘repository’ published inside APNIC’s VM on the test network • Introduce a delay to prevent accidental exclusions (if delegated stats files are out of synchronization with the registry) – Approx. around five mins, after live updates to the registry (delegations or returns) occur, apply updates to both main RPKI and AS0 RPKI state
  • 14. 1414 Similar AS0 ROA policies in other region? RIR Status APNIC Implemented AFRINIC Under discussion ARIN No proposal LACNIC Consensus reached, awaiting implementation RIPE NCC Proposal withdrawn
  • 15. 1515 What’s next? • Be sure to keep your ROAs updated! • Try Route Origin Validation (ROV) and share your experience – Invalid advertisements (advertisements that contradict ROA information) may be discarded or de-preferenced
  • 17. 1717 Incident Response Team (IRT) object 1717
  • 19. 1919 Proposal history Proposal submitted Aug 2018 Consensus reached APNIC 46 Sep 2018 Proposal endorsed by EC Sep 2018 Implementation Phase 1 completed Jun 2019 Implementation Phase 2 completed Dec 2019 Implementation Phase 3 ongoing https://www.apnic.net/community/policy/proposals/prop-125
  • 20. 2020 prop-125 implementation • Phase one – completed – Validations for all IRTs associated with portable delegations – Created new escalation mailbox (excalation- abuse@apnic.net) • Phase two – completed – Validations for all IRTs associated with non-portable customer assignments • Phase three – ongoing – Improved UI/UX and resolved software issues reported from Members – Added ‘abuse-c’ attribute to whois records – MyAPNIC restriction to be reinstated soon APNIC Members End user Parent, portable delegations Child, non portable customer assignments
  • 21. 2121 Validation process • Frequency – Every six months • Failure to validate – IRT objects marked invalid after 15 days – Restricted Member access to MyAPNIC after 30 days • Requirement – Abuse-mailbox responsive to legitimate reports – Validation requests responded to by human
  • 22. 2222 Some stats on validation 22 In the last six months: • 5,779 Members requested to validate emails • 6,845 email validation requests issued • 6,003 email validation requests confirmed • 87.7% validation rate As of Sep 2020
  • 23. 2323 Feedback from APNIC Members 23 Software vendor: “I am concerned about clicking links sent to verify my IRT. Hopefully, there is a better way.” Internet Service Provider: “Is this email for validate IRT contact? Any evidence that your email is from APNIC? As I receive many spam mail and hacker mail, so it is hard for me to trust and click on any links without knowing it is real or fake account."
  • 24. 2424 Feedback from APNIC Members 24 Banking/Financial “These emails are pretty problematic – they have a link to click on and it asks to validate an email address. These are very suspect in an email. I had to look at the email header to verify it did indeed come from APNIC. University/CERT “This type of automated testing is an abuse of our abuse address, is mindless robotic punishment of client organizations without regard to the impact upon those organizations and without any consideration of the realities of email deliverability or the pressures on abuse or other addresses of an organization from spam and other email threats. I would suggest you cease this automated testing.”
  • 25. 2525 APNIC Secretariat recommendations 25 • Investigate using other methods of validation, instead of unique links in emails • Change validation cycle from every six months to once annually • Consider deprecating the ‘email’ attribute in IRT objects and validating only ‘abuse-mailbox’. Members will then only be required to validate one email address Have your say and let us know if you have any suggestions!
  • 26. 2626 Similar IRT policy in other region? RIR Status APNIC Validation of “abuse-mailbox” and other IRT emails Implemented AFRINIC “Abuse Contact Policy Update (Draft 6)” Under discussion ARIN ARIN-prop-264: Validation of Abuse-mailbox Abandoned LACNIC LAC-2018-5: Registration and validation of abuse contact Consensus reached, awaiting implementation RIPE NCC Validation of abuse-mailbox Proposal withdrawn
  • 27. 2727 What’s next? • Continue working with the community to amend the policy to address current concerns – Negative feedback about the overall process – Many raising security concerns about clicking on email links • Simplifying the process and reducing the frequency of validation should help alleviate some of the pain points • Find the balance between ease of validation and achieving the policy goal — to ensure accurate and contactable network abuse contacts
  • 29. 2929 You are invited to attend • APRICOT 2021 and APNIC 51 – Online only (https://www.2021.apricot.net/) – 22 February to 4 March 2021 • APNIC 52 – Hopefully in person and online – Sapporo, Japan – 8 to 16 September 2021
  • 30. 3030 By participating you can... Make new friends Polish tech skills Share your experience Hear from experts Promote your organization Help develop policies
  • 31. 3131 References • https://tools.ietf.org/html/rfc6483 • https://www.apnic.net/community/participate/mailinglists/ • https://www.apnic.net/community/policy/proposals/ • https://www.apnic.net/community/policy/process/ • https://conference.apnic.net/50/assets/files/APCS790/prop-125- implementation-updateV2.pdf • https://conference.apnic.net/50/assets/files/APCS790/prop-132- Implementation.pdf • https://www.apnic.net/events/conferences/ • https://academy.apnic.net/en/course/policy-development-process-course/ • https://training.apnic.net/