Ondrej Zajicek 
							
						 
					 
					
						
						
							
						
						116285f2b0 
					 
					
						
						
							
							RPKI: Fix conflict in config grammar  
						
						 
						
						
						
						
					 
					
						2023-08-25 04:32:01 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ondrej Zajicek (work) 
							
						 
					 
					
						
						
							
						
						fc1e3211b1 
					 
					
						
						
							
							RPKI: Add 'ignore max length' option  
						
						 
						
						... 
						
						
						
						Add 'ignore max length' option to RPKI protocol, which ignores received
max length in ROA records and instead uses max value (32 or 128). This
may be useful for implementing loose RPKI check for blackholes. 
						
						
					 
					
						2020-10-11 01:00:54 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Maria Matejka 
							
						 
					 
					
						
						
							
						
						027a3e66f7 
					 
					
						
						
							
							RPKI: Allow build without libSSH  
						
						 
						
						
						
						
					 
					
						2020-02-04 10:15:35 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Vincent Bernat 
							
						 
					 
					
						
						
							
						
						3b62417c35 
					 
					
						
						
							
							RPKI: Fix allocation of hostname when using an IPv6 address  
						
						 
						
						
						
						
					 
					
						2019-07-29 15:42:30 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Jan Maria Matejka 
							
						 
					 
					
						
						
							
						
						f851f0d7e3 
					 
					
						
						
							
							Config: Dropping CF_ADDTO.  
						
						 
						
						
						
						
					 
					
						2018-06-26 14:29:03 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Pavel Tvrdík 
							
						 
					 
					
						
						
							
						
						65d2a88dd2 
					 
					
						
						
							
							RPKI protocol with one cache server per protocol  
						
						 
						
						... 
						
						
						
						The RPKI protocol (RFC 6810) using the RTRLib
(http://rpki.realmv6.org/) that is integrated inside
the BIRD's code.
Implemeted transports are:
 - unprotected transport over TCP
 - secure transport over SSHv2
Example configuration of bird.conf:
  ...
  roa4 table r4;
  roa6 table r6;
  protocol rpki {
    debug all;
    # Import both IPv4 and IPv6 ROAs
    roa4 { table r4; };
    roa6 { table r6; };
    # Set cache server (validator) address,
    # overwrite default port 323
    remote "rpki-validator.realmv6.org" port 8282;
    # Overwrite default time intervals
    retry   10;         # Default 600 seconds
    refresh 60;         # Default 3600 seconds
    expire 600;         # Default 7200 seconds
  }
  protocol rpki {
    debug all;
    # Import only IPv4 routes
    roa4 { table r4; };
    # Set cache server address to localhost,
    # use default ports tcp => 323 or ssh => 22
    remote 127.0.0.1;
    # Use SSH transport instead of unprotected transport over TCP
    ssh encryption {
      bird private key "/home/birdgeek/.ssh/id_rsa";
      remote public key "/home/birdgeek/.ssh/known_hosts";
      user "birdgeek";
    };
  }
  ... 
						
						
					 
					
						2016-12-07 09:35:24 +01:00