In the Resource Public Key Infrastructure (RPKI), Certificate Authorities publish certificates [RFC6487], RPKI signed objects [RFC6488], manifests [RFC6486], and CRLs to repositories. CAs may have an embedded mechanism to publish to these repositories, or they may use a separate Repository Server and publication protocol. RPKI repositories are currently accessible using the rsync protocol [RSYNC], allowing Relying Parties to synchronize a local copy of the RPKI repository used for validation with the remote repositories [RFC6481].

Internet Engineering Task Force (IETF)                    T. Bruijnzeels Request for Comments: 8182                                  O. Muravskiy Category: Standards Track                                       RIPE NCC ISSN: 2070-1721                                                 B. Weber                                                                 Cobenian                                                               R. Austein                                                     Dragon Research Labs                                                                July 2017

                The RPKI Repository Delta Protocol (RRDP)


   In the Resource Public Key Infrastructure (RPKI), Certificate    Authorities (CAs) publish certificates, including end-entity    certificates, Certificate Revocation Lists (CRLs), and RPKI signed    objects to repositories.  Relying Parties retrieve the published    information from those repositories.  This document specifies a new    RPKI Repository Delta Protocol (RRDP) for this purpose.  RRDP was    specifically designed for scaling.  It relies on an Update    Notification File which lists the current Snapshot and Delta Files    that can be retrieved using HTTPS (HTTP over Transport Layer Security    (TLS)), and it enables the use of Content Distribution Networks    (CDNs) or other caching infrastructures for the retrieval of these    files.

Status of This Memo

   This is an Internet Standards Track document.

   This document is a product of the Internet Engineering Task Force    (IETF).  It represents the consensus of the IETF community.  It has    received public review and has been approved for publication by the    Internet Engineering Steering Group (IESG).  Further information on    Internet Standards is available in Section 2 of RFC 7841.

   Information about the current status of this document, any errata,    and how to provide feedback on it may be obtained at

 Copyright Notice

   Copyright (c) 2017 IETF Trust and the persons identified as the    document authors.  All rights reserved.

   This document is subject to BCP 78 and the IETF Trust's Legal    Provisions Relating to IETF Documents    ( in effect on the date of    publication of this document.  Ple...