User Tools

Site Tools


hints:rpki

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
hints:rpki [2026/03/13 05:47] – [Initial Preparation] philiphints:rpki [2026/07/20 14:54] (current) – [RPKI-client] philip
Line 32: Line 32:
 ===== NLnetLabs Routinator ===== ===== NLnetLabs Routinator =====
  
-Nothing to say here, the instructions just work, the validator installs sweetly, and just runs. As long as the instructions are followed. The current version of Routinator is 0.15.1, at time of writing.+Nothing to say here, the instructions just work, the validator installs sweetly, and just runs. As long as the instructions are followed. The current version of Routinator is 0.15.2, at time of writing.
  
-If using Debian/Ubuntu as I do, then just use the supplied package and your favourite package manager. Described in NLnetLabs'[[https://github.com/NLnetLabs/routinator#quick-start-with-debian-and-ubuntu-packages| Github]] repo. +If using Debian/Ubuntu as I do, then just use the supplied package and your favourite package manager. The instructions for how to install are in NLnetLabs excellent [[https://routinator.docs.nlnetlabs.nl/en/stable/installation.htmldocumentation]].
- +
-If the link to the supplied package is added to your package manager, for example **apt** on Ubuntu, then create an entry in **/etc/apt/sources.list.d** called **nlnetlabs.list** and put this in it (which is for Ubuntu 22.04): +
- +
-<code> +
-deb [arch=amd64] https://packages.nlnetlabs.nl/linux/ubuntujammy main +
-</code> +
- +
-(Note: if you are trying this on Ubuntu 24.04, there is no package for ''noble'' as yet, but I found that using the 22.04 setup works fine.) +
- +
-Then run: +
- +
-<code> +
-wget -qO- https://packages.nlnetlabs.nl/aptkey.asc sudo tee /etc/apt/trusted.gpg.d/nlnetlabs.asc +
-</code> +
- +
-And then finally: +
- +
-<code> +
-apt-get update +
-apt install routinator +
-</code> +
- +
-Easy!+
  
 The installer will set up the necessary **systemd** file so that Routinator starts automatically on boot. Remember to modify the **/etc/routinator/routinator.config** file so that Routinator listens on the IPv4 (and IPv6) ports of the system - and you can enable the default statistics pages which listen on port 8323. A working configuration file would look like this: The installer will set up the necessary **systemd** file so that Routinator starts automatically on boot. Remember to modify the **/etc/routinator/routinator.config** file so that Routinator listens on the IPv4 (and IPv6) ports of the system - and you can enable the default statistics pages which listen on port 8323. A working configuration file would look like this:
Line 95: Line 72:
  
 <code> <code>
-wget https://github.com/NICMx/FORT-validator/releases/download/1.6.7/fort_1.6.7-1_amd64.deb+wget https://github.com/NICMx/FORT-validator/releases/download/1.6.8/fort_1.6.8-1_amd64.deb
 </code> </code>
 and then install it: and then install it:
 <code> <code>
-sudo apt install ./fort_1.6.7-1_amd64.deb+sudo apt install ./fort_1.6.8-1_amd64.deb
 </code> </code>
  
Line 190: Line 167:
 **rpki-client** is just a validator - it does not have the functionality to accept connections from a router. We'll come to that later on (we'll need to use [[rpki#stayrtr|StayRTR]], which is a fork of Cloudflare's now unmaintained GoRTR). **rpki-client** is just a validator - it does not have the functionality to accept connections from a router. We'll come to that later on (we'll need to use [[rpki#stayrtr|StayRTR]], which is a fork of Cloudflare's now unmaintained GoRTR).
  
-**rpki-client** has now been packaged and is available across most mainstream Linux/Unix-based platforms. Including as part of the Ubuntu 22.04 and later distributions. However, the packaged version in Ubuntu is old (version 7.6 on 22.04, 9.0 on 24.04). At the time of writing, the current release of **rpki-client** is version 9.7. There is a version of **rpki-client** on the Ubuntu Snap Store, but it is unclear which version of **rpki-client** this is.+**rpki-client** has now been packaged and is available across most mainstream Linux/Unix-based platforms. Including as part of the Ubuntu 22.04 and later distributions. However, the packaged version in Ubuntu is old (version 7.6 on 22.04, 9.0 on 24.04). At the time of writing, the current release of **rpki-client** is version 9.8. There is a current version of **rpki-client** on the Ubuntu Snap Store, but not every sysadm wishes to use yet another package manager on Ubuntu.
  
-So to stay up to date on Ubuntu, we have to build it ourselves. A pity that the **rpki-client** maintainers don't build their own deb package, or pre-build packages like NLnetLabs do with Routinator, given that Ubuntu maintainers seem to be unable to keep the software current. Oh well.+My preference is to stay up to date on Ubuntu, and so we have to build it ourselves. A pity that the **rpki-client** maintainers don't build their own deb package, or pre-build packages like NLnetLabs do with Routinator, given that Ubuntu maintainers seem to be unable to keep the software current. Oh well.
  
  
Line 198: Line 175:
 ==== Initial Preparation ==== ==== Initial Preparation ====
  
-Before you attempt to download and build it, the **rpki-client** instructions note that you need a few other packages in place. These include **automake**, **autoconf**, **make**, **git** itself, **libtool** and **expat**. This is all quite easy using the Ubuntu package manager. +Before you attempt to download and build it, the **rpki-client** instructions note that you need a few other packages in place. These include **automake**, **autoconf**, **make**, **git** itself, **libtool****expat**, **libssl-dev**, **libtls-dev**, **rsync** and **zlib1g-dev**. This is all quite easy using the Ubuntu package manager (and some of these packages may already be installed by default).
-<code> +
-sudo apt install automake autoconf make git libtool libexpat1-dev +
-</code> +
-The other required package noted in the instructions is **tls** from LibreSSL. LibreSSL is a branch of OpenSSL and is used on OpenBSD - not found on Linuxbut seems to be appearing in the latest Debian/Ubuntu beta builds. So we need to download the bits we need and install. The **rpki-client** instructions don't say anything about how to do that. +
- +
-First we go to [[https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/|https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/]] and select the latest packagewhich is libressl-4.2.1.tar.gz at time of writing +
-<code> +
-wget https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-4.2.1.tar.gz +
-</code> +
-We then unpack it: +
-<code> +
-tar zxf libressl-3.9.2.tar.gz +
-</code> +
-and then build it: +
-<code> +
-cd libressl-3.9.2 +
-./configure --enable-libtls-only +
-make +
-sudo make install +
-</code> +
-Note the option to only build **libtls** - we don't need the rest of LibreSSL and it could well interfere with OpenSSL which will already be on the system. Now that **libtls** is built, the **install** action will put the libraries in **/usr/local/lib** like this: +
-<code> +
--rw-r--r-- 1 root root 18679208 Jul 14 10:11 libtls.a +
--rw-r--r-- 1 root root      923 Jul 14 10:11 libtls.la +
-lrwxrwxrwx 1 root root       16 Jul 14 10:11 libtls.so -> libtls.so.29.0.0 +
-lrwxrwxrwx 1 root root       16 Jul 14 10:11 libtls.so.29 -> libtls.so.29.0.0 +
--rw-r--r-- 1 root root  8721528 Jul 14 10:11 libtls.so.29.0.0 +
-</code> +
-Run **sudo ldconfig** so that the system knows about the new libraries. +
- +
-Next we need to get some packages that **rpki-client** needs. These are **libssl-dev**, **rsync** and **zlib1g-dev**.+
 <code> <code>
-sudo apt install libssl-dev rsync zlib1g-dev+sudo apt install automake autoconf make git libtool libexpat1-dev libssl-dev libtls-dev zlib1g-dev
 </code> </code>
  
Line 256: Line 202:
 <code> <code>
 sudo groupadd _rpki-client sudo groupadd _rpki-client
-sudo useradd g _rpki-client s /sbin/nologin d /nonexistent c "rpki-client user" _rpki-client+sudo useradd -g _rpki-client -s /sbin/nologin -d /nonexistent -c "rpki-client user" _rpki-client
 </code> </code>
 Now we can install RPKI-client: Now we can install RPKI-client:
Line 344: Line 290:
 <code> <code>
 cd dist cd dist
-sudo cp -p stayrtr-v0.6.3-8-g9586f8f-linux-x86_64 /usr/local/bin/stayrtr +sudo cp -p stayrtr-v0.6.4-1-g4bad963-linux-x86_64 /usr/local/bin/stayrtr 
-sudo cp -p rtrdump-v0.6.3-8-g9586f8f-linux-x86_64 /usr/local/bin/rtrdump +sudo cp -p rtrdump-v0.6.4-1-g4bad963-linux-x86_64 /usr/local/bin/rtrdump 
-sudo cp -p rtrmon-v0.6.3-8-g9586f8f-linux-x86_64 /usr/local/bin/rtrmon+sudo cp -p rtrmon-v0.6.4-1-g4bad963-linux-x86_64 /usr/local/bin/rtrmon
 </code> </code>
  
hints/rpki.1773380843.txt.gz · Last modified: by philip