Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCNR / GOpenCNR TAL and repository terms of use

GOpenCNR TAL and repository terms of use

Who may use GOpenCNR's trust anchor locator and RPKI repository and for what, how to fetch from the repository without burdening others, and how the TAL changes.

Last updated 1 October 2026 Auf Deutsch lesen →

On this page

  1. What these terms cover
  2. Who may use them
  3. What they are for
  4. What the TAL is, and what it is not
  5. Fetch fairly
  6. How the TAL changes
  7. No warranty
  8. What we record when you fetch
  9. Changes and law

What these terms cover

GOpenCNR publishes a trust anchor locator (TAL) and an RPKI repository at cnr.gplatform.org, so that anyone can validate routes in GOpenCNR's private address space. These terms apply to everyone who fetches the TAL, or anything from the repository, over RRDP, rsync or HTTPS. How the keys are held and the objects issued is set out in the RPKI certification practice statement.

Fetching the TAL or anything from the repository means you accept these terms. You need no account and sign nothing.

Who may use them

Anyone, free of charge. You do not have to be a GOpenCNR member. A member's router has the TAL already: it is shipped inside every release of the GOpenCNR agent.

What they are for

  • Route validation: route origin validation, and path checks with ASPA, for routes in GOpenCNR's space, in your own validator or on your own routers.
  • Research and monitoring: fetching, measuring and studying the repository, and checking what it says against the registry and the transparency log.

For any other use, such as mirroring the repository for others or shipping the TAL in software of your own, write to contact@gplatform.org first.

What the TAL is, and what it is not

  • It is GOpenCNR's own trust anchor, not part of the RPKI of the Regional Internet Registries. It certifies only GOpenCNR's private space: the IPv6 root fdc0:0900::/24, the IPv4 pools the registry holds, starting with 10.113.0.0/16, and the ASNs 4223000000 to 4223009999. Load it beside the RIR TALs, never in place of them.
  • It says nothing about public space. No object under it concerns a public prefix or a public ASN.
  • It says nothing about identity. A certificate under it binds resources to a key, not to a person or an organisation.
  • Think before loading it where other private networks are routed. Once your validator uses the TAL, a route for a prefix GOpenCNR has a ROA for, or for a more specific part of it, is invalid unless it comes from the origin that ROA names. Another network that uses the same private ranges may find its own routes there marked invalid.

Fetch fairly

The repository is shared by everyone who validates GOpenCNR's space, and it is served from a single server.

  • Use RRDP. Fetch the notification file, and then only the deltas you do not have yet. Fetch the full snapshot only when you start, or when your session no longer matches the repository's.
  • Do not poll in a loop. The repository changes when the registry changes, and each manifest says when its next scheduled update is due. Keep your validator's standard refresh interval, and do not shorten it to watch for changes.
  • Do not hammer rsync. rsync is there for validators that still need it. Do not run several fetches in parallel, do not fetch the whole tree on every run when RRDP would do, and do not use rsync to mirror the repository on a short timer.
  • Use conditional requests and caching wherever your software supports them.
  • Do not test load or attack anything through the repository. Security research follows the GOpenCNR security and disclosure policy.

We publish no fixed request limit. We may limit or block an address or a network whose fetching burdens the repository for others, without notice where that is needed to keep the repository serving, and we lift the block once the fetching has changed. If you are blocked and do not know why, write to contact@gplatform.org.

How the TAL changes

  • Only in a ceremony. The trust anchor key is used only in scripted ceremonies under four-eyes, as the practice statement describes, and the TAL changes only in one of them.
  • Announced twice. Every change is announced in the transparency log at csr.gplatform.org/tlog and shipped in a release of the GOpenCNR agent. The TAL published at cnr.gplatform.org is always the current one.
  • Check what you load. Compare the TAL you use with the one shipped in the latest agent release, and with the entry in the transparency log that announced it.

No warranty

The TAL and the repository are given away as they are, with no warranty and no service level. They may be unreachable, late or wrong, and you decide what your validator and your routers do when they are. GOpenCNR's own hubs keep their last good data and never start accepting origins they cannot validate; we recommend the same to you.

Liability is as the general terms of service set it out: for what is given away, it is limited to intent and gross negligence (Section 521 BGB).

What we record when you fetch

Our servers log fetches as they log every request, and those logs are deleted after 14 days. The GOpenCNR privacy notice says more.

Changes and law

These terms may change through the process the general terms set out. Every version is kept in the document archive. German law applies.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform SSO
  • GPlatform Billing

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany