RPKI best practices and lessons learned

26/09/2025

RPKI best practices and lessons learned
Image assisted/created by AI

By Sofia Silva Berenguer

This document describes Resource Public Key Infrastructure (RPKI) related best practices and lessons learned. It provides general recommendations aimed at supporting the implementation and operation of RPKI in diverse environments.

These insights are drawn from practical experience and collaborative discussions but are not intended to be prescriptive. Operators and stakeholders should adapt the guidance according to their specific technical, organizational, and policy contexts.

The recommendations presented here should be viewed as a starting point for informed decision making rather than a definitive or one-size-fits-all approach.

Additional reading:

Best practices for ROA creation

Just about to enable RPKI for your organization and wondering whether you should select hosted mode or delegated mode?

If you’re just getting started with RPKI, use hosted RPKI.

Using delegated mode?

(Free access, no subscription required)

If you are using the delegated mode (sometimes called self-hosted), it is highly recommended to use an RPKI publication server provided by your parent Certification Authority (CA), if available, to simplify operations.

Note: Publication as a service is available to Members of ARIN, APNIC and the RIPE NCC.

What prefixes should I create Route Origin Authorizations (ROAs) for?

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments