<div dir="ltr">Denis, <br><br>Thanks for repeating your position. Once again. It is already noted. <br><br>> Unfortunately, the Task Force did not attempt to identify most of these 'other' stakeholders or what data they need or why. So […] <br><br>You are wrong, Denis. The task force did in fact consider all stakeholders that we could possibly think of, and their needs for the database. We decided not to create and publish a definitive list of stakeholders in our report because, well, who are we to decide who qualifies or not as a legitimate stakeholder of the RIPE database in 2021? Should such a list be reviewed annually to be kept up-to-date and accurate? Should there also be an accompanying list of their (changing) individual requirements maintained, and why? Who should do all that work, how? Looking forward to reading your list :) <br><br>In the meantime, rather than perpetually navel gaze or crusade for a new RIPE database, the scope of this proposal - and focus of this discussion - is the potential change of address policy that states holders of PA IPv4 'must' register assignments in the database to 'should' register assignments. For the reasons outlined in the proposal, which to me personally read clear and reasonable. <br><br>We would love to hear what others in the working group think about this policy proposal. The more people we have sharing their thoughts, the better and healthier for the working group! <br><br>Regards, <br>James </div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Oct 7, 2022 at 11:45 PM denis walker <<a href="mailto:ripedenis@gmail.com">ripedenis@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Jeroen<br>
<br>
Your terminology is very confusing. You talk only about allocations<br>
and sub-allocations and keep referring to INETNUMs. You never once<br>
mention assignments. So my first question is what exactly is it that<br>
you want to be optional?<br>
<br>
The current policy says:<br>
<br>
3.0 Goals of the Internet Registry System<br>
...4.Registration: The provision of a public registry documenting<br>
address space allocations and assignments must exist. This is<br>
necessary to ensure uniqueness and to provide information for Internet<br>
troubleshooting at all levels.<br>
----<br>
4.0 Registration Requirements<br>
All assignments and allocations must be registered in the RIPE<br>
Database. This is necessary to ensure uniqueness and to support<br>
network operations.<br>
----<br>
6.2 Network Infrastructure and End User Networks<br>
...When an End User has a network using public address space this must<br>
be registered separately with the contact details of the End User.<br>
----<br>
<br>
The message from the current policy is very clear. End Users operating<br>
public networks must be documented in the RIPE Database. There are two<br>
historical reasons given, uniqueness AND network operations. You have<br>
focused your argument on the fact that uniqueness of allocations is no<br>
longer needed. But you have ignored the other stated reason. Using the<br>
database to contact network operators for troubleshooting is one of<br>
the original purposes of the database. So if you now want this<br>
information to be optional and entered if an LIR feels like it, you<br>
need to justify why internet troubleshooting is no longer necessary at<br>
an End User network level.<br>
<br>
When we talk about the purposes of the database we are not talking<br>
about the purposes of the database as a container. We mean the<br>
purposes of the data contained within the database. Over time this<br>
data in the RIPE Database about End Users has been used, for example,<br>
by LEAs and other investigators to identify the users as well as for<br>
internet operational problem solving.<br>
<br>
The Database Task Force acknowledged in their report (ripe-767) that<br>
there are now different stakeholders who use the RIPE Database for<br>
different reasons:<br>
<br>
2. The Difference between the RIPE Database and the RIPE Registry<br>
The information disclosed in the RIPE Database aims to facilitate<br>
cooperation and coordination between network operators and other<br>
stakeholders for a variety of operational tasks, including<br>
troubleshooting and preventing outages.<br>
---<br>
3. Why are we reviewing the RIPE Database functionality now?<br>
The RIPE Database provides essential information to members of the<br>
RIPE community, which helps them to keep individual networks and the<br>
overall Internet running in their region. Many stakeholders depend on<br>
the accuracy and availability of the data stored in the database to do<br>
their job properly, especially regarding cybersecurity. Some database<br>
users, such as ISPs or IXPs, have been part of the RIPE community for<br>
years, while others are relatively new, such as Law Enforcement<br>
Agencies (LEAs) or regulators. These user groups have different needs<br>
and expectations regarding the database<br>
---<br>
5.1 Data accuracy<br>
The data added to the database should be accurate to ensure uniqueness<br>
of Internet number resources and to provide reliable registration<br>
information to all parties involved in network operations. For<br>
example, contact details or information about a specific assignment<br>
should be accurate to facilitate contact with and identification of<br>
the organisation holding the assignment.<br>
---<br>
6.4 Purpose: Facilitating Internet operations and coordination<br>
The RIPE Database should facilitate communication and cooperation<br>
among stakeholders for the following reasons:<br>
-Operational issues such as measuring or troubleshooting networks<br>
-Handling abuse cases, supporting the handling of cyber incidents and<br>
supporting LEA investigations<br>
---<br>
<br>
Unfortunately, the Task Force did not attempt to identify most of<br>
these 'other' stakeholders or what data they need or why. So we are<br>
left in a position where it has been acknowledged that many different<br>
stakeholders exist that need data currently provided by the public IP<br>
address registry, but who or what is unknown. There may well now be<br>
stakeholders with very legitimate reasons for needing accurate<br>
assignment data. Until we know more about these stakeholders we cannot<br>
make informed decisions about the content of the database. But the<br>
Task Force then went on to make a recommendation about assignments<br>
based on the rationale "A core reason for registration of IPv4 PA<br>
assignments was to justify an LIR’s need for additional IPv4 allocated<br>
address space. However, since the RIPE NCC ran out of IPv4 in 2019,<br>
this policy has been rendered obsolete." Just as you are doing in this<br>
proposal, they conveniently ignored the main reason(s) for documenting<br>
assignments and focused on one obsolete reason.<br>
<br>
The Task Force recommendation was "that as resource holders have full<br>
responsibility over the registration of their IPv4 PA assignment(s),<br>
they are free to make assignments or not." Which is also the basis of<br>
your proposal. The people entering data into a public IP address<br>
registry are not necessarily the ones who should be able to decide<br>
what data must be contained in the registry. You need to consider the<br>
requirements of different aspects of the industry and even the needs<br>
of the wider (public) community (the stakeholders).<br>
<br>
I do not think we are currently in a position to make an informed<br>
decision on this Task Force recommendation or your policy proposal.<br>
<br>
cheers<br>
denis<br>
co-chair DB-WG<br>
<br>
<br>
On Fri, 7 Oct 2022 at 16:31, Jeroen Lauwers <<a href="mailto:jlauwers@a2b-internet.com" target="_blank">jlauwers@a2b-internet.com</a>> wrote:<br>
><br>
> Hi Denis,<br>
><br>
> Again we are back to asking the question, "What is the purpose of the<br>
> RIPE Database in 2022?". I know this is like the elephant in the room.<br>
> I know most people look the other way every time I mention this topic.<br>
><br>
><br>
> This policy proposal is not about the goal of the database itl is just about how far we obligate LIRs in filling in information for inetnum objects and how much freedom we give the LIR to decide it by themself. So technically the goal of the database stays the same.<br>
><br>
> BUT it is so fundamental to many discussions we are having. For<br>
> example, is the database still purely (or even primarily) only for<br>
> 'operational purposes'? A term used so often that, like so many other<br>
> terms used in this industry, is not even defined anywhere. Is using<br>
> the content of the RIPE Database to stop the use of an IP address for<br>
> criminal activity an 'operational purpose'. If someone is operating a<br>
> network using a block of IP addresses and abusing other users of the<br>
> internet, then surely knowing who is using that block of addresses and<br>
> being able to contact them has 'operational' value.<br>
><br>
><br>
> For sure we always need to keep this in mind. And I think it would be a good subject to discuss in the database working group. But so far I don’t see any reasons to be insecure about this after changing this policy.<br>
><br>
><br>
> As Sander said, knowing how much of an allocation is in use was a side<br>
> effect of this policy. Knowing who is operating a network on a block<br>
> of addresses, and being able to contact them, is the real purpose of<br>
> this policy requirement to document assignments. If we allow LIRs to<br>
> choose what info to add to the database, those LIRs that knowingly<br>
> provide resources and services to abusive end users will obviously<br>
> choose not to document it. That may be used as a selling feature to<br>
> abusive end users, to obscure and delay their identification. Whilst<br>
> most LIRs take abuse seriously we all know there are some that don't.<br>
><br>
><br>
> You are totally right. That is why this is only about inetnum objects. The LIR gets still obligated by the terms and conditions to fill in enough information for contacting efficient the maintainer as also By the Abuse Contact Management in the RIPE Database policy for having an abuse contact.<br>
><br>
> Kind regards,<br>
><br>
> Jeroen<br>
<br>
-- <br>
<br>
To unsubscribe from this mailing list, get a password reminder, or change your subscription options, please visit: <a href="https://mailman.ripe.net/" rel="noreferrer" target="_blank">https://mailman.ripe.net/</a><br>
</blockquote></div>