Index | Thread | Search

From:
Theo Buehler <tb@theobuehler.org>
Subject:
Re: rpki-client: remove support for validating Geofeed data
To:
Job Snijders <job@bsd.nl>
Cc:
tech@openbsd.org
Date:
Tue, 13 Jan 2026 19:18:24 +0100

Download raw body.

Thread
On Tue, Jan 13, 2026 at 05:33:20PM +0000, Job Snijders wrote:
> Sadly, I've come to suspect RFC 9632 RPKI-based Geofeed authentication
> was a bit of a ruse to pass IESG review. The authors of the spec don't
> appear to have any plan to encourage the ecosystem to adopt RFC 9632.
> None of the RIRs currently support signing Geofeed data or have any
> plans to do so. Also, operators tend to follow the path of least
> resistance ... and this authenticator is both optional & hard to use.
> 
> Time to take it behind the barn.
> 
> OK?

ok for after 9.7 is released.

Please make sure you don't add the -lz (yet) in the regress Makefile.

> ps. Draft-ietf-opsawg-prefix-lengths comes from the same stock, so I'm
> not gonna spend any time on that one.

Agreed. As mentioned off-list, the cms.c code needs some cleanup, too.
I'll send a diff once yours is in.