LAC-2026-3: Require Valid ROA Coverage for Requesting Additional Resources - ROA para solicitud de recursos

General information

Original language
Español
Last modified
07/08/2026
Status
In discussion
14 %. Next step would be First consensus assessment

Authors
Sergio Kleiman Schwarzstein - Version [1]
In discussion
12/08/2026

Summary

This proposal specifies that any organization requesting additional IPv4 or IPv6 resources from LACNIC must demonstrate 80% valid Route Origin Authorization (ROA) coverage for the IPv4 and IPv6 resources registered in its name and allocated or assigned by LACNIC. The goal of the proposal is to encourage RPKI adoption and strengthen the security of the regional routing system. Creating and maintaining ROAs is a widely recognized practice for mitigating the risk of route hijacking, unauthorized advertisements, and BGP configuration errors.

The proposal incorporates ROA adoption as an additional criterion for evaluating subsequent resource requests, complementing the criteria already set forth in the Policy Manual.

Rationale (Describe the problem you intend to solve)

The Internet ecosystem has made significant progress in adopting RPKI as a mechanism for validating the origin of BGP routes. Although issuing ROAs is currently a recommended practice, there is no policy requirement promoting high levels of ROA coverage for resources registered in the region. As a result, some prefixes remain without cryptographic origin protection. According to a study published by LACNIC in 2025 (https://blog.lacnic.net/adopcion-rpki-america-latina/), RPKI adoption in the region has reached significant levels, with ROA coverage exceeding 46% for IPv4 and approximately 60% for IPv6. These numbers demonstrate that a substantial majority of the community already has the technical knowledge and operational capacity needed to deploy these solutions.

Securing global Internet routing is a shared responsibility of the entire Internet ecosystem. Historically, the criteria for evaluating the allocation of additional resources have been limited to quantitative metrics of address space utilization (e.g., 80% utilization for IPv4 or the HD-Ratio metric for IPv6). However, given the current state of the Internet, proper resource stewardship cannot be separated from organizations’ responsibility to ensure these resources are not exposed to route hijacking or route leaks that could compromise the region’s stability. For this reason, security must be formally adopted as an essential metric of operational efficiency.

LACNIC currently provides tools that can be used to verify the level of ROA coverage (BGP&RPKI Tool at https://tools.labs.lacnic.net/tools/rpki?id=xxxx).

This evolution is now possible thanks to the technical maturity of the RPKI system integrated into the MiLACNIC platform. LACNIC has established a robust, stable, and high-availability cryptographic infrastructure, providing intuitive interfaces, automation APIs, and diagnostic tools that remove technical barriers for operators regardless of their size. Since the platform allows delegating and creating ROAs efficiently and in bulk, the technical barriers to ROA adoption have been significantly reduced.

Organizations requesting additional resources demonstrate continuous growth in their operations. Therefore, it is reasonable to require compliance with minimum operational security practices before granting additional number resources.

Current text

Item 1 of section “2.3.4. Policies for the Distribution of Additional IPv4 Address Space.”

Section “4.4.2.1 Subsequent Allocation Criteria”.

New text
Analyze diff

Add the following text at the end of item 1 of Section “2.3.4. Policies for the Distribution of Additional IPv4 Address Space”:

Additionally, at least 80% of the IPv4 and IPv6 resources that the organization has been assigned or allocated by LACNIC must be covered by valid Route Origin Authorizations (ROAs). LACNIC will verify compliance with this requirement using the operational mechanisms it deems appropriate for this purpose. Compliance with this requirement will be a prerequisite for approving any subsequent allocation of resources.

Add the following text at the end of Section “4.4.2.1 Subsequent Allocation Criteria”:

Additionally, at least 80% of the IPv4 and IPv6 resources that the organization has been assigned or allocated by LACNIC must be covered by valid Route Origin Authorizations (ROAs). LACNIC will verify compliance with this requirement using the operational mechanisms it deems appropriate for this purpose. Compliance with this requirement will be a prerequisite for approving any subsequent allocation of resources.

Additional information

Impact on LACNIC Members: Organizations requesting additional address space must audit their resources through MiLACNIC and enable RPKI/ROA for any resources that are not yet covered. This requirement does not affect members who do not require additional address space or to new members. The proposal does not affect legacy resources or resources not obtained from LACNIC.

Impact on LACNIC Staff: The LACNIC registration team must incorporate into its validation workflows a verification of the coverage level of valid ROAs corresponding to the requesting organization before authorizing the release of new resources from the inventory.

Timetable

-

References

-

Presented at:

-