Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleFor hosted RPKI, is it risky to have someone host the private key to sign the ROAs?

As more services move to the cloud, it is more and more common that important security functions are run by third party providers and partners.  In  In this case, while it is true that ARIN’s hosting infrastructure holds the private key used to create your ROAssign your ROAs, the risk is low.  The private key used to create your ROA is not held by ARIN.  Specifically, no one, including ARIN, has access to this private key to generate ROAs.  Only the holder of the private key you generated to communicate with ARIN will be able to request that ROAs be signed.

...