SlideShare a Scribd company logo
#apricot2019 2019 47
Core Registry & Related Services
Product Family Update
George Michaelson
ggm@apnic.net
APNIC
#apricot2019 2019 47
APNIC registry services
β€’ The services which support our primary role: responsible
management of Internet Number Resources (INR)
– Maintenance of the database of resources (β€œcore” registry database)
– Public query services (WHOIS, RDAP, WHOWAS)
– Reverse-DNS delegation (ip6.arpa & in-addr.arpa)
– Resource Public-Key Infrastructure (RPKI)
β€’ Public interfaces to manage all these registry elements
– β€œMyAPNIC” and API endpoints for scripted management & integration
β€’ Registry is a set of Authority statements
– What we did, applying address policy to resources
– Our records of β€œwe distributed resources to” events
– Delegations into internet-wide information & registration services
#apricot2019 2019 47
Current registry services
β€’ IP address & ASN delegations and transfers
– Our fundamental record keeping
– Includes β€œpool management” for the ranges we have assigned
authority over (from IANA, and transfers in from other RIR)
β€’ Whois Database (including Internet Routing Registry)
– A Public view of Registry records
– Includes data submitted by delegated authorities
β€’ Mixture of authority and non-authority statements in one service
#apricot2019 2019 47
Current registry services (continued)
β€’ Reverse DNS
– Anchor and sub-delegation in the in-addr.arpa and ip6.arpa DNS tree
β€’ Registration Data Access Protocol (RDAP) (NEW since 2015)
– JSON structured data over HTTP (replacing WHOIS)
β€’ Resource Public Key Infrastructure (RPKI) (since 2010)
– Cryptographically verifiable statements about INR
4
#apricot2019 2019 47
Registry Accuracy
β€’ Apply current public records standards to all data including
block allocations to NIR
– Complements Organization and PoC update activity in APNIC
β€’ Review of KRNIC block transactions underway
β€’ Delegated, transfer and related stats files will change
β€’ Other NIR will follow in 2019
β€’ Continuous Improvement goal from strategic plan
– We are auditing software paths which update registry
– We are adopting an event log model of transactions and changes
5
#apricot2019 2019 47
rDNS improvements
β€’ Problem: NIR historical blocks, some entire /8 are not available
for rDNS delegation unless resource is maintained inside the NIR
– but we now have transfers which can go out of economy or to
management in APNIC
β€’ Discussing improvements to support reverse-DNS zone sharing
with NIR
– Leverage existing inter-RIR API
β€’ Goal: equivalent rDNS functionality for any INR in any NIR or
APNIC, irrespective of who holds the address ranges
β€’ Operations Improvements in rDNS logging, service delivery and
reporting
6
#apricot2019 2019 47
WHOIS improvements
β€’ Goal: consistent WHOIS data at APNIC for all resources irrespective of
which NIR or APNIC maintains the INR
β€’ Mirrors of all NIR data offered from APNIC whois
– Continuing activity from 2018
β€’ Problem: IRR (radb) flag support not working well for some tools used
by BGP operators
– Discussing deployment of NTT β€˜irrd’ as a discrete service
β€’ Offers integration with RPKI activities, data consistency checks
– We propose to relocate all IRR data into a new stand-alone WHOIS which will be
mirrored by APNIC whois services, but run as a discrete SOURCE
β€’ To be discussed with the community
7
#apricot2019 2019 47
RDAP/WHOWAS
β€’ JSON based public record system, closely aligned between
number and name based services
– WHOWAS tracks historical states, RDAP shows current head state
β€’ Globally connected
– HTTP(s) protocol with 302 redirection and steerage map
– Consistent data format for all servers worldwide
β€’ Goal: implement RDAP for all APNIC/NIR WHOIS records
– Continuing activity from 2018
β€’ Standardization work in IETF
– Bulk data, Search
8
#apricot2019 2019 47
RPKI
β€’ Goal: consistent RPKI service for all eligible INR holders in
APNIC region
– Three NIR operate a local service under APNIC RPKI
– Four NIR operate in APNIC RPKI services through MyAPNIC for their
subaccount holders
β€’ Anysigner: a CMS model of signing arbitrary data with RPKI
– In github, test client and web services will deploy in 2019
β€’ Standardization work
– Progress β€˜validation reconsidered’ deployment draft inIETF
– β€˜anysigner’ model related draft in IETF
– NRO ECG coordination on counting/measuring RPKI
9
#apricot2019 2019 47
Questions?
201947
#apricot2019
18 – 28 February 2019
DAEJEON
SOUTHKOREA

More Related Content

PDF
APNIC services and Policy Development Process | IDNOG 5
Β 
PDF
NZNOG2013 - APNIC Update
Β 
PDF
LACNIC19 - APNIC Updates
Β 
PDF
RIPE NCC Update
PDF
Axel RIPE-NCC_Update
PPTX
IRUS R5: open and flexible access to standardised repository usage data
Β 
PDF
RIPE NCC Data Sets for Researchers
PDF
ARIN Update
Β 
APNIC services and Policy Development Process | IDNOG 5
Β 
NZNOG2013 - APNIC Update
Β 
LACNIC19 - APNIC Updates
Β 
RIPE NCC Update
Axel RIPE-NCC_Update
IRUS R5: open and flexible access to standardised repository usage data
Β 
RIPE NCC Data Sets for Researchers
ARIN Update
Β 

What's hot (20)

PDF
Adress Transfers in APNIC region @ LACNIC 24
Β 
PPTX
ARIN Update [APRICOT 2015]
Β 
PDF
IANA Services Update
Β 
PDF
Owen
PDF
PacNOG 21: APNIC Update
Β 
PDF
The RIPE Community and Ethical Considerations
PDF
APNIC IPv4 Market Transfer
Β 
PPTX
Pillar 4 Implementation Plan (P4IP) and current soil information developments
PDF
IPv6 Deployment in the Middle East - Amman, Jordan 2013
PDF
RIPE Routing Information Service
PDF
Get Internet Number Resources from ARIN (IPv4, IPv6, ASNs)
Β 
PDF
PLNOG 6: Sandra BrΓ‘s - What’s hot at the RIPE NCC
PDF
RIR Collaboration on RIPEstat
PDF
Customizing Online Services for a Better Experience
Β 
PDF
Registry Data Quality
PDF
How RIPE NCC Tools Can Help with Online Investigations
PDF
Local Waste Service Standards Pilot Project: Phase 2 Planning Workshop | Lind...
PDF
ARIN 35 Tutorial: Life after IPv4 depletion
Β 
PDF
Improving the IPv4 transfer experience
Β 
PPTX
Getting Internet Number Resources from ARIN
Β 
Adress Transfers in APNIC region @ LACNIC 24
Β 
ARIN Update [APRICOT 2015]
Β 
IANA Services Update
Β 
Owen
PacNOG 21: APNIC Update
Β 
The RIPE Community and Ethical Considerations
APNIC IPv4 Market Transfer
Β 
Pillar 4 Implementation Plan (P4IP) and current soil information developments
IPv6 Deployment in the Middle East - Amman, Jordan 2013
RIPE Routing Information Service
Get Internet Number Resources from ARIN (IPv4, IPv6, ASNs)
Β 
PLNOG 6: Sandra BrΓ‘s - What’s hot at the RIPE NCC
RIR Collaboration on RIPEstat
Customizing Online Services for a Better Experience
Β 
Registry Data Quality
How RIPE NCC Tools Can Help with Online Investigations
Local Waste Service Standards Pilot Project: Phase 2 Planning Workshop | Lind...
ARIN 35 Tutorial: Life after IPv4 depletion
Β 
Improving the IPv4 transfer experience
Β 
Getting Internet Number Resources from ARIN
Β 
Ad

Similar to Core Registry and Related Services (20)

PDF
NIR SIG Report
Β 
PDF
MyNOG 8: Next Generation Internet Number Registry Services
Β 
PDF
The Next Generation Internet Number Registry Services
Β 
PDF
ThaiNOG Day 2019: Internet Number Registry Services, the Next Generation
Β 
PDF
Whowas: History of resources at APNIC
Β 
PPTX
31st TWNC IP OPM and TWNOG: RDAP and RPKI
Β 
PDF
Thoughts on Securing BGP
Β 
PPTX
NZNOG 2019: APNIC Update
Β 
PDF
Information Services
Β 
PDF
SANOG 34: Internet number registry services - the next generation
Β 
PDF
APNIC47 Hackathon Report
Β 
PDF
Experience Using RIR Whois
Β 
PDF
09 (IDNOG01) Introduction about APNIC by Wita Laksono
PPTX
ARIN 42: APNIC Update
Β 
PDF
Intro and APNIC's info products update
Β 
PDF
ARIN 51: APNIC Update
Β 
PDF
Foreign Objects in RIPE IRR
Β 
PPTX
RDAP @ .at
PPTX
btNOG 6: Next Generation Internet Registry Services - RDAP
Β 
PDF
APNIC Secretariat Report
Β 
NIR SIG Report
Β 
MyNOG 8: Next Generation Internet Number Registry Services
Β 
The Next Generation Internet Number Registry Services
Β 
ThaiNOG Day 2019: Internet Number Registry Services, the Next Generation
Β 
Whowas: History of resources at APNIC
Β 
31st TWNC IP OPM and TWNOG: RDAP and RPKI
Β 
Thoughts on Securing BGP
Β 
NZNOG 2019: APNIC Update
Β 
Information Services
Β 
SANOG 34: Internet number registry services - the next generation
Β 
APNIC47 Hackathon Report
Β 
Experience Using RIR Whois
Β 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
ARIN 42: APNIC Update
Β 
Intro and APNIC's info products update
Β 
ARIN 51: APNIC Update
Β 
Foreign Objects in RIPE IRR
Β 
RDAP @ .at
btNOG 6: Next Generation Internet Registry Services - RDAP
Β 
APNIC Secretariat Report
Β 
Ad

More from APNIC (20)

PPTX
APNIC Report, presented at APAN 60 by Thy Boskovic
Β 
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Β 
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
PDF
The Internet -By the Numbers, Sri Lanka Edition
Β 
PDF
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
PDF
DNSSEC Made Easy, presented at PHNOG 2025
Β 
PDF
BGP Security Best Practices that Matter, presented at PHNOG 2025
Β 
PDF
APNIC's Role in the Pacific Islands, presented at Pacific IGF 2205
Β 
PDF
IPv6 Deployment and Best Practices, presented by Makito Lay
Β 
PDF
Cleaning up your RPKI invalids, presented at PacNOG 35
Β 
PDF
The Internet - By the numbers, presented at npNOG 11
Β 
PDF
Transmission Control Protocol (TCP) and Starlink
Β 
PDF
DDoS in India, presented at INNOG 8 by Dave Phelan
Β 
PDF
Global Networking Trends, presented at the India ISP Conclave 2025
Β 
PDF
Make DDoS expensive for the threat actors
Β 
PDF
Fast Reroute in SR-MPLS, presented at bdNOG 19
Β 
PDF
DDos Mitigation Strategie, presented at bdNOG 19
Β 
PDF
ICP -2 Review – What It Is, and How to Participate and Provide Your Feedback
Β 
PDF
APNIC Update - Global Synergy among the RIRs: Connecting the Regions
Β 
PDF
Measuring Starlink Protocol Performance, presented at LACNIC 43
Β 
APNIC Report, presented at APAN 60 by Thy Boskovic
Β 
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Β 
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
The Internet -By the Numbers, Sri Lanka Edition
Β 
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
DNSSEC Made Easy, presented at PHNOG 2025
Β 
BGP Security Best Practices that Matter, presented at PHNOG 2025
Β 
APNIC's Role in the Pacific Islands, presented at Pacific IGF 2205
Β 
IPv6 Deployment and Best Practices, presented by Makito Lay
Β 
Cleaning up your RPKI invalids, presented at PacNOG 35
Β 
The Internet - By the numbers, presented at npNOG 11
Β 
Transmission Control Protocol (TCP) and Starlink
Β 
DDoS in India, presented at INNOG 8 by Dave Phelan
Β 
Global Networking Trends, presented at the India ISP Conclave 2025
Β 
Make DDoS expensive for the threat actors
Β 
Fast Reroute in SR-MPLS, presented at bdNOG 19
Β 
DDos Mitigation Strategie, presented at bdNOG 19
Β 
ICP -2 Review – What It Is, and How to Participate and Provide Your Feedback
Β 
APNIC Update - Global Synergy among the RIRs: Connecting the Regions
Β 
Measuring Starlink Protocol Performance, presented at LACNIC 43
Β 

Recently uploaded (20)

PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
newyork.pptxirantrafgshenepalchinachinane
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
E -tech empowerment technologies PowerPoint
PDF
Introduction to the IoT system, how the IoT system works
PPTX
Introduction to cybersecurity and digital nettiquette
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PPTX
SAP Ariba Sourcing PPT for learning material
PPTX
Slides PPTX World Game (s) Eco Economic Epochs.pptx
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PDF
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PPTX
Mathew Digital SEO Checklist Guidlines 2025
PPTX
Introduction to Information and Communication Technology
Sims 4 Historia para lo sims 4 para jugar
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
Paper PDF World Game (s) Great Redesign.pdf
newyork.pptxirantrafgshenepalchinachinane
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
SASE Traffic Flow - ZTNA Connector-1.pdf
The New Creative Director: How AI Tools for Social Media Content Creation Are...
E -tech empowerment technologies PowerPoint
Introduction to the IoT system, how the IoT system works
Introduction to cybersecurity and digital nettiquette
Job_Card_System_Styled_lorem_ipsum_.pptx
SAP Ariba Sourcing PPT for learning material
Slides PPTX World Game (s) Eco Economic Epochs.pptx
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
INTERNET------BASICS-------UPDATED PPT PRESENTATION
Design_with_Watersergyerge45hrbgre4top (1).ppt
Mathew Digital SEO Checklist Guidlines 2025
Introduction to Information and Communication Technology

Core Registry and Related Services

  • 1. #apricot2019 2019 47 Core Registry & Related Services Product Family Update George Michaelson ggm@apnic.net APNIC
  • 2. #apricot2019 2019 47 APNIC registry services β€’ The services which support our primary role: responsible management of Internet Number Resources (INR) – Maintenance of the database of resources (β€œcore” registry database) – Public query services (WHOIS, RDAP, WHOWAS) – Reverse-DNS delegation (ip6.arpa & in-addr.arpa) – Resource Public-Key Infrastructure (RPKI) β€’ Public interfaces to manage all these registry elements – β€œMyAPNIC” and API endpoints for scripted management & integration β€’ Registry is a set of Authority statements – What we did, applying address policy to resources – Our records of β€œwe distributed resources to” events – Delegations into internet-wide information & registration services
  • 3. #apricot2019 2019 47 Current registry services β€’ IP address & ASN delegations and transfers – Our fundamental record keeping – Includes β€œpool management” for the ranges we have assigned authority over (from IANA, and transfers in from other RIR) β€’ Whois Database (including Internet Routing Registry) – A Public view of Registry records – Includes data submitted by delegated authorities β€’ Mixture of authority and non-authority statements in one service
  • 4. #apricot2019 2019 47 Current registry services (continued) β€’ Reverse DNS – Anchor and sub-delegation in the in-addr.arpa and ip6.arpa DNS tree β€’ Registration Data Access Protocol (RDAP) (NEW since 2015) – JSON structured data over HTTP (replacing WHOIS) β€’ Resource Public Key Infrastructure (RPKI) (since 2010) – Cryptographically verifiable statements about INR 4
  • 5. #apricot2019 2019 47 Registry Accuracy β€’ Apply current public records standards to all data including block allocations to NIR – Complements Organization and PoC update activity in APNIC β€’ Review of KRNIC block transactions underway β€’ Delegated, transfer and related stats files will change β€’ Other NIR will follow in 2019 β€’ Continuous Improvement goal from strategic plan – We are auditing software paths which update registry – We are adopting an event log model of transactions and changes 5
  • 6. #apricot2019 2019 47 rDNS improvements β€’ Problem: NIR historical blocks, some entire /8 are not available for rDNS delegation unless resource is maintained inside the NIR – but we now have transfers which can go out of economy or to management in APNIC β€’ Discussing improvements to support reverse-DNS zone sharing with NIR – Leverage existing inter-RIR API β€’ Goal: equivalent rDNS functionality for any INR in any NIR or APNIC, irrespective of who holds the address ranges β€’ Operations Improvements in rDNS logging, service delivery and reporting 6
  • 7. #apricot2019 2019 47 WHOIS improvements β€’ Goal: consistent WHOIS data at APNIC for all resources irrespective of which NIR or APNIC maintains the INR β€’ Mirrors of all NIR data offered from APNIC whois – Continuing activity from 2018 β€’ Problem: IRR (radb) flag support not working well for some tools used by BGP operators – Discussing deployment of NTT β€˜irrd’ as a discrete service β€’ Offers integration with RPKI activities, data consistency checks – We propose to relocate all IRR data into a new stand-alone WHOIS which will be mirrored by APNIC whois services, but run as a discrete SOURCE β€’ To be discussed with the community 7
  • 8. #apricot2019 2019 47 RDAP/WHOWAS β€’ JSON based public record system, closely aligned between number and name based services – WHOWAS tracks historical states, RDAP shows current head state β€’ Globally connected – HTTP(s) protocol with 302 redirection and steerage map – Consistent data format for all servers worldwide β€’ Goal: implement RDAP for all APNIC/NIR WHOIS records – Continuing activity from 2018 β€’ Standardization work in IETF – Bulk data, Search 8
  • 9. #apricot2019 2019 47 RPKI β€’ Goal: consistent RPKI service for all eligible INR holders in APNIC region – Three NIR operate a local service under APNIC RPKI – Four NIR operate in APNIC RPKI services through MyAPNIC for their subaccount holders β€’ Anysigner: a CMS model of signing arbitrary data with RPKI – In github, test client and web services will deploy in 2019 β€’ Standardization work – Progress β€˜validation reconsidered’ deployment draft inIETF – β€˜anysigner’ model related draft in IETF – NRO ECG coordination on counting/measuring RPKI 9
  • 11. 201947 #apricot2019 18 – 28 February 2019 DAEJEON SOUTHKOREA