GOpenCNR TAL and repository terms of use
Who may use GOpenCNR's trust anchor locator and RPKI repository and for what, how to fetch from the repository without burdening others, and how the TAL changes.
What these terms cover
GOpenCNR publishes a trust anchor locator (TAL) and an RPKI repository at cnr.gplatform.org, so that anyone can validate routes in GOpenCNR's private address space. These terms apply to everyone who fetches the TAL, or anything from the repository, over RRDP, rsync or HTTPS. How the keys are held and the objects issued is set out in the RPKI certification practice statement.
Fetching the TAL or anything from the repository means you accept these terms. You need no account and sign nothing.
Who may use them
Anyone, free of charge. You do not have to be a GOpenCNR member. A member's router has the TAL already: it is shipped inside every release of the GOpenCNR agent.
What they are for
- Route validation: route origin validation, and path checks with ASPA, for routes in GOpenCNR's space, in your own validator or on your own routers.
- Research and monitoring: fetching, measuring and studying the repository, and checking what it says against the registry and the transparency log.
For any other use, such as mirroring the repository for others or shipping the TAL in software of your own, write to contact@gplatform.org first.
What the TAL is, and what it is not
- It is GOpenCNR's own trust anchor, not part of the RPKI of the Regional Internet Registries. It certifies only GOpenCNR's private space: the IPv6 root
fdc0:0900::/24, the IPv4 pools the registry holds, starting with10.113.0.0/16, and the ASNs4223000000to4223009999. Load it beside the RIR TALs, never in place of them. - It says nothing about public space. No object under it concerns a public prefix or a public ASN.
- It says nothing about identity. A certificate under it binds resources to a key, not to a person or an organisation.
- Think before loading it where other private networks are routed. Once your validator uses the TAL, a route for a prefix GOpenCNR has a ROA for, or for a more specific part of it, is invalid unless it comes from the origin that ROA names. Another network that uses the same private ranges may find its own routes there marked invalid.
Fetch fairly
The repository is shared by everyone who validates GOpenCNR's space, and it is served from a single server.
- Use RRDP. Fetch the notification file, and then only the deltas you do not have yet. Fetch the full snapshot only when you start, or when your session no longer matches the repository's.
- Do not poll in a loop. The repository changes when the registry changes, and each manifest says when its next scheduled update is due. Keep your validator's standard refresh interval, and do not shorten it to watch for changes.
- Do not hammer rsync. rsync is there for validators that still need it. Do not run several fetches in parallel, do not fetch the whole tree on every run when RRDP would do, and do not use rsync to mirror the repository on a short timer.
- Use conditional requests and caching wherever your software supports them.
- Do not test load or attack anything through the repository. Security research follows the GOpenCNR security and disclosure policy.
We publish no fixed request limit. We may limit or block an address or a network whose fetching burdens the repository for others, without notice where that is needed to keep the repository serving, and we lift the block once the fetching has changed. If you are blocked and do not know why, write to contact@gplatform.org.
How the TAL changes
- Only in a ceremony. The trust anchor key is used only in scripted ceremonies under four-eyes, as the practice statement describes, and the TAL changes only in one of them.
- Announced twice. Every change is announced in the transparency log at
csr.gplatform.org/tlogand shipped in a release of the GOpenCNR agent. The TAL published atcnr.gplatform.orgis always the current one. - Check what you load. Compare the TAL you use with the one shipped in the latest agent release, and with the entry in the transparency log that announced it.
No warranty
The TAL and the repository are given away as they are, with no warranty and no service level. They may be unreachable, late or wrong, and you decide what your validator and your routers do when they are. GOpenCNR's own hubs keep their last good data and never start accepting origins they cannot validate; we recommend the same to you.
Liability is as the general terms of service set it out: for what is given away, it is limited to intent and gross negligence (Section 521 BGB).
What we record when you fetch
Our servers log fetches as they log every request, and those logs are deleted after 14 days. The GOpenCNR privacy notice says more.
Changes and law
These terms may change through the process the general terms set out. Every version is kept in the document archive. German law applies.