Protocol in Code · Track

RPKI

ROAs, prefix math, and the tri-state verdict under BGP policy

5 sessions Course material (English)

Sessions

RPKI track sessions

Session 01

A ROA Is A Permission Slip

What is a ROA, stripped of everything except the three facts it actually asserts?

Open Session 01
Session 02

Covering Is Prefix Math

"Does this ROA say anything about this announcement?" is really two separate questions — what are they, and why is conflating them the classic operator mistake?

Open Session 02
Session 03

Three Verdicts, Not Two

Why does origin validation return three verdicts instead of a simple valid/invalid bool, and what exactly separates the two flavors of invalid?

Open Session 03
Session 04

Policy Decides What a Verdict Means

A verdict of VALID, INVALID, or NOT_FOUND is a fact about the world. What does a router actually do with that fact, and who decides?

Open Session 04
Session 05

Build the Toy Validator Loop

What does a real RPKI validator's whole job look like when loading ROAs, checking one announcement, and sweeping a whole route table are wired into a single object instead of four separate demos?

Open Session 05