Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCNR / GOpenCNR LIR sponsorship agreement

GOpenCNR LIR sponsorship agreement

The terms on which a RIPE NCC member provides PA space for GOpenCNR's sponsored public pools, with PA space only, every assignment registered by the sponsor, ROAs and route objects, abuse contacts, and how space is withdrawn without stranding members.

Last updated 1 October 2026 Auf Deutsch lesen →

On this page

  1. This agreement
  2. PA space only
  3. Every assignment is registered by the sponsor
  4. Route objects and ROAs
  5. Abuse contacts
  6. Data protection
  7. When something goes wrong, or the sponsor withdraws
  8. Payment
  9. Confidentiality
  10. Term and ending
  11. Everything else
  12. Schedule

This agreement

This agreement is between Gelhaus Solutions, as Tier 0 of GOpenCNR, and a Local Internet Registry that is a member of the RIPE NCC and provides PA space for one or more of GOpenCNR's public pools, the sponsor. It takes effect when both sides sign it together with its schedule. Publishing it here is not an offer: space is accepted only under a signed copy of the version current at the time.

The schedule names the space, the pools, the origin ASN, the contacts, the notice periods and any payment. Where the schedule and this agreement differ, the schedule wins, except on the points this agreement says no schedule can change. How members receive the space is set out in the hosted ASN and public pool terms. Warranty, the limits of liability and the governing law are in the general terms of service.

PA space only

  • The sponsor provides only PA space allocated to it by the RIPE NCC, which RIPE policy lets it assign to others. No schedule can change this.
  • PI space cannot be sponsored. RIPE policy does not let PI space be sub-assigned to other organisations. A holder of PI space may have its own space routed through GOpenCNR under the hosted ASN and public pool terms, but cannot sponsor a pool with it.
  • The sponsor confirms that it may assign the space, that the space is free of other assignments and of disputes, and it tells Tier 0 what it knows about the space's history that affects its use, such as listings on blocklists.
  • The space enters a public pool created by a motion of the GOpenCNR Community Council. That motion and the pool's policy decide how the space is handed out. The sponsor may refuse to register an assignment only where RIPE policy, the law or its own upstream obligations forbid it, and it tells Tier 0 why.

Every assignment is registered by the sponsor

  • When the GOpenCNR Community Council grants a member public exposure for an address in the sponsored space, Tier 0 sends the sponsor the assignment: the prefix, the member's handle, the member's abuse contact and whatever else RIPE policy requires for it.
  • The sponsor registers each assignment in the RIPE Database without undue delay. Tier 0 routes no address before its assignment is registered. No schedule can change this.
  • When an assignment ends, Tier 0 tells the sponsor and withdraws the announcement, and the sponsor then removes the assignment.
  • The sponsor's duties as an LIR remain its own: its membership of the RIPE NCC and its service agreement with it, RIPE policy for its allocation, the documentation of its assignments and the accuracy of its entries in the RIPE Database. Tier 0 gives the sponsor what it needs to meet them, answers its questions about any assignment, and helps it answer any request of the RIPE NCC about the sponsored space.

Route objects and ROAs

  • The sponsor creates and keeps ROAs for the sponsored space that authorise the origin ASN named in the schedule, exactly for what is announced, with no maxLength wider than the announced prefix, as RFC 9319 recommends. The routes are then RPKI-valid.
  • Matching route and route6 objects are kept in the RIPE Database, created with the authorisation the maintainers of the space and of the origin ASN give.
  • Sponsored space is announced only while a valid ROA covers it, only through GOpenCNR's announcement edge and only for the prefixes in the schedule. Tier 0 holds no public ASN for members; the origin is the one the schedule names.
  • The sponsor tells Tier 0 in advance of any change it makes to the ROAs or route objects for the space.
  • When space leaves a pool, Tier 0 withdraws the announcement first, and the sponsor removes the ROA only after that, so that no route of the space is RPKI-invalid while it is still announced.

Abuse contacts

  • Each assignment carries the member's abuse contact, as the hosted ASN and public pool terms require. The sponsor's own abuse contact stays on its allocation.
  • Reports that reach the sponsor about sponsored space are passed to abuse@gplatform.org. GOpenCNR handles them in its case system under the abuse and sanctions policy: acknowledged within 24 hours, the member acts first, within 48 hours or 12 hours for an active attack, and Tier 0 steps in where it does not.
  • Tier 0 tells the sponsor of every step of the sanctions ladder and every emergency suspension that affects sponsored space.
  • Where RIPE policy, the sponsor's upstream contracts or a binding order require the sponsor to act on sponsored space itself, it may, and it tells Tier 0 at once.
  • Requests from authorities about GOpenCNR members that reach the sponsor are passed to contact@gplatform.org and handled under the authority request policy, unless the law requires the sponsor to answer itself.

Data protection

  • Each side is a separate controller for its own processing. The sponsor is the controller for what it registers in the RIPE Database and keeps as an LIR; Gelhaus Solutions is the controller for GOpenCNR's registry, its cases and its routing. The RIPE NCC is the controller for the RIPE Database.
  • Tier 0 passes the sponsor only what an assignment needs. The sponsor uses it only for its duties as an LIR for that assignment and for abuse handling, and for nothing else.
  • Members are told before they apply that the sponsor receives these data and that the RIPE Database entry is public.
  • Each side tells the other without undue delay of a personal data breach that affects data passed under this agreement.

When something goes wrong, or the sponsor withdraws

  • Withdrawing space. The sponsor may withdraw space, or end this agreement, with the notice the schedule sets. During the notice the assignments, ROAs and route objects stay in place. Tier 0 tells the affected members at once, and they may apply for addresses in another public pool. When the notice ends, Tier 0 withdraws the announcements, and the sponsor then removes the ROAs and the assignments.
  • Losing the right to the space. If the sponsor stops being an LIR, if the RIPE NCC deregisters or reclaims the allocation, or if the sponsor can no longer register assignments, it tells Tier 0 at once. The notice then shortens to whatever time the RIPE NCC leaves.
  • A breach by the sponsor, such as failing to register an assignment, removing a ROA early or using member data for anything else: Tier 0 may stop handing out the space, ask for the breach to be remedied, and end this agreement if it is not remedied within a reasonable deadline. Members are told.
  • A breach by Tier 0, such as routing an address before its assignment is registered, announcing more than the schedule names or failing to handle abuse: the sponsor may ask for the breach to be remedied and end this agreement if it is not remedied within a reasonable deadline. Even then, the assignments stay until the members have had the notice the schedule sets, unless RIPE policy, the law or the security of the sponsor's network requires sooner.
  • At once. Where a binding requirement of the RIPE NCC or a binding order of a court or an authority requires it, or where an attack on either side's network cannot wait, either side may withdraw an announcement or space at once, telling the other. Tier 0 gives the members concerned a statement of reasons no later than when the withdrawal takes effect, unless the law forbids telling them.

Payment

No payment is owed under this agreement, in either direction, unless the schedule sets one. If Gelhaus Solutions invoices anything under the schedule, it charges no VAT while it is a small business under Section 19 UStG.

Confidentiality

Each side keeps confidential what the other discloses as confidential, or what is evidently confidential, for the term and for three years after, and uses it only for this agreement. This does not apply to what is public without breach, was already known, is independently developed or must be disclosed by law. What is in the RIPE Database, the public RPKI or GOpenCNR's public registry is not confidential.

Term and ending

  • This agreement runs for the term the schedule sets, or without a fixed term where it sets none.
  • Either side may end it with the notice the schedule sets, and for good cause as described above.
  • The duties on data protection and confidentiality, and the order of withdrawal (announcement first, then ROA, then assignment), outlast the agreement until they have been carried out.

Everything else

No service level applies, in either direction. Warranty and liability between the sides are as the general terms of service set them out for businesses. German law applies, and the place of jurisdiction is as the general terms set it out. A material change to this agreement is emailed to the sponsor at least six weeks before it takes effect and put to it for signature, in full and linked in the document archive, without a list of what changed. A new version applies only once the sponsor signs it. Until then, the version it signed stays in force. If the sponsor does not sign, we may end this agreement at its next ordinary end date under the schedule, and only then, with the notice for members still running. Every version stays in the document archive.

Schedule

Everything in square brackets is filled in, and the schedule is signed with the agreement. A part that does not apply says "none".

1. Parties

Gelhaus Solutions, a sole proprietorship of Enno Gelhaus, Eichenwald 3, 49624 Löningen, Germany, as Tier 0 of GOpenCNR, contact@gplatform.org. Small business under Section 19 UStG.

Sponsor:

  • Name: [legal name]
  • Address: [street, postcode, town, country]
  • Register: [register court and number, or "not registered"]
  • RIPE NCC organisation: [organisation handle]
  • LIR: [registry identifier]

2. Sponsored space

| Prefix | Family | Public pool | Pool created by motion | |---|---|---|---| | [prefix] | [IPv6 / IPv4] | [pool] | [motion reference] |

3. Routing

  • Origin ASN: [the ASN the ROAs authorise to originate the space]
  • Maintainers: space [maintainer]; origin ASN [maintainer]
  • ROAs created by the sponsor for: [origin ASN], exact, for the prefixes above as announced

4. Contacts

| Role | Sponsor | Gelhaus Solutions | |---|---|---| | Assignments and the RIPE Database | [name, email, telephone] | contact@gplatform.org | | Technical | [name, email, telephone] | contact@gplatform.org | | Abuse | [abuse mailbox] | abuse@gplatform.org | | Data protection | [name, email] | contact@gplatform.org |

5. Notice and term

  • Notice for withdrawing space: [period]
  • Notice for ending this agreement: [period]
  • Term: [without fixed term / until date]

6. Payment

  • [none / who pays whom, the amount, the period and how it is invoiced]

7. Signatures

| | For Gelhaus Solutions | For the sponsor | |---|---|---| | Place and date | [place, date] | [place, date] | | Name and position | Enno Gelhaus, proprietor | [name, position] | | Signature | [signature] | [signature] |

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform SSO
  • GPlatform Billing

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany