How to Get an RPKI FORT Validator Up and Running in Under Two Hours

August 10, 2026

How to Get an RPKI FORT Validator Up and Running in Under Two Hours

By Nicolas Antoniello, Sr. Technical Engagement Manager at ICANN

How can we be sure that a network advertised through BGP, and claiming to originate from a specific Autonomous System, has actually been delegated to that Autonomous System? In other words, what tool can I use to verify that a BGP advertisement originates from an Autonomous System authorized to make that announcement?

The answer to these questions is what is known as Origin Validation, and the protocol created to establish and verify this validation is Resource Public Key Infrastructure (RPKI).

Basically, the global RPKI infrastructure connects the networks advertised by BGP to the Autonomous Systems authorized to advertise them, using digital certificates known as Route Origin Authorizations (ROAs).

(Free access, no subscription required)

So, who generates these ROAs?

ROAs must be generated by the holders of number resources — meaning IP addresses in either of their two versions, IPv4 and IPv6 — delegated by one of the five Regional Internet Registries. In our region, that registry is LACNIC.

To achieve this, RPKI infrastructure currently manages, on the one hand, certificates that establish which IP address blocks and Autonomous System Numbers (ASNs) have been legitimately assigned by the corresponding Regional Internet Registry to an Internet service provider or organization. These certificates are known as Infrastructure Objects.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted