Morero oa OpenBSD o hlahisitse tokollo ea pele e nkehang ea rpki-client

Baetsi ba OpenBSD e phatlalalitsoeng tokollo ea pele ea phatlalatsa ea khatiso e nkehang ea sephutheloana rpki-client ka ho kenya tšebetsong mochini oa RPKI (Resource
Public Key Infrastructure) bakeng sa RP (Mekha e Amanang), e sebelisoang ho fana ka tumello ea mohloli oa liphatlalatso tsa BGP. RPKI eu lumella hore u tsebe hore na phatlalatso ea BGP e tsoa ho mong'a marang-rang kapa che, e leng ho sebelisa lisebelisoa tsa bohlokoa tsa sechaba bakeng sa mekhoa e ikemetseng le liaterese tsa IP, ho hahoa ketane ea tšepo, e hahiloeng ho tloha ho IANA ho ea ho bangolisi ba libaka (RIRs). ), bafani (LIRs) le basebelisi ba ho qetela ba liaterese . Khoutu e phatlalalitsoe tlasa laesense ea BSD.

Lenaneo rpki-client e etsa hore ho khonehe ho romela kopo sebakeng sa polokelo ea RPKI le ho hlahisa ntho ea VRP (Validated ROA Payload) e tiisang mohloli oa tsela (ROA, Route Origin Authorization) ka mokhoa oa ho tsamaisa li-packet setting. OpenBGPD и NONYANE, hammoho le liforomo tsa CSV kapa tsa JSON bakeng sa ho sebelisoa mekhoeng e meng ea litsela. Ho fumana sebaka sa polokelo, sebelisa lisebelisoa openrsync, e fumanang disetifikeiti tsohle tsa X.509, dipontsho, le di-CRL. Joale
rpki-client e hlahloba setifikeiti se seng le se seng se amanang le ROA, ho haha ​​le ho netefatsa ketane eohle ea tšepo, ha ka nako e le 'ngoe e hlahloba CRL bakeng sa ho hlakoloa ha setifikeiti.

Source: opennet.ru