<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.2.3) -->
<?rfc comments="yes"?>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-idr-bgp-rpki-yang-02" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="YANG Data Model for BGP about RPKI">YANG Data Model for BGP about RPKI</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-idr-bgp-rpki-yang-02"/>
    <author initials="C." surname="Lin" fullname="Changwang Lin">
      <organization>New H3C Technologies</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>linchangwang.04414@h3c.com</email>
      </address>
    </author>
	<author initials="Y." surname="Liu" fullname="Yisong Liu">
      <organization>China Mobile</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>liuyisong@chinamobile.com</email>
      </address>
    </author>
    <author initials="H." surname="Wang" fullname="Haibo Wang">
      <organization>Huawei Technologies</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>rainsword.wang@huawei.com</email>
      </address>
    </author>
    <author initials="J." surname="Roy" fullname="Jishnu Roy">
      <organization>Juniper Networks, Inc.</organization>
      <address>
        <postal>
          <street>1133 Innovation Way</street>
          <region>Sunnyvale, CA 94089</region>
          <country>United States of America</country>
        </postal>
        <email>jishnur@juniper.net</email>
      </address>
    </author>
    <author initials="D." surname="Ma" fullname="Di Ma">
      <organization>ZDNS</organization>
      <address>
        <postal>
          <street>Floor 21, Block B, Greenland Center</street>
          <city>Chaoyang Beijing, 100102</city>
          <country>China</country>
        </postal>
        <email>madi@zdns.cn</email>
      </address>
    </author>
    <date year="2026"/>
    <area>Routing</area>
    <workgroup>IDR Working Group</workgroup>
    <keyword>YANG, BGP, RPKI</keyword>
    <abstract>
      <t>This document defines YANG data models for managing
   BGP information about Resource Public Key Infrastructure (RPKI).</t>
    </abstract>
  </front>
  <middle>
    <section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="RFC6810"/> and <xref target="RFC8210"/> describe a protocol to deliver the Resource
   Public Key Infrastructure (RPKI) prefix origin data and router keys
   from a trusted cache server to a router, referred to as the RPKI to Router
   protocol. <xref target="I-D.ietf-sidrops-8210bis"/> updates <xref target="RFC8210"/> by mainly
   adding a new ASPA (Autonomous System Provider Authorization) PDU
   (Protocol Data Unit) type.</t>
      <t><xref target="RFC6811"/> validates the origination Autonomous System (AS) of BGP
   (Border Gateway Protocol) routes based on the Validated ROA Payload (VRP) received
   from the RPKI cache server. <xref target="I-D.ietf-sidrops-aspa-verification"/> makes use of
   ASPA objects in the RPKI to verify the BGP AS_PATH attribute of advertised routes.
   <xref target="RFC8635"/> describes that the public key is published in the
   RPKI and sent to the router via the RPKI to Router protocol
   for verifying the signature of BGPsec announcements.</t>
      <t>This document defines YANG <xref target="RFC7950"/> data models for managing BGP information
   about RPKI.</t>
      <t>The YANG data models in this document conform to the Network
   Management Datastore Architecture (NMDA) <xref target="RFC8342"/>.</t>
      <section anchor="terminology">
        <name>Terminology</name>
        <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
   "OPTIONAL" in this document are to be interpreted as described in
   BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they appear in all
   capitals, as shown here.</t>
      </section>
    </section>
    <section anchor="model-overview">
      <name>Model Overview</name>
      <t>Three YANG data models are defined in this document to augment BGP
   YANG model <xref target="I-D.ietf-idr-bgp-model"/>.</t>
      <t>The ietf-bgp-origin-as-validation.yang data model provides the
   methods for configuring BGP origin AS validation.</t>
      <ul spacing="normal">
        <li>
          <t>Origin AS validation parameters for BGP routes.</t>
        </li>
        <li>
          <t>Origin AS validity states of BGP routes.</t>
        </li>
      </ul>
      <t>The ietf-bgp-sec.yang data model provides the methods for
   configuring BGPsec.</t>
      <ul spacing="normal">
        <li>
          <t>BGPsec parameters for BGP routes.</t>
        </li>
        <li>
          <t>BGPsec validity states of BGP routes.</t>
        </li>
      </ul>
      <t>The ietf-bgp-aspa.yang data model provides the methods for
   configuring BGP AS_PATH Verification Based on ASPA.</t>
      <ul spacing="normal">
        <li>
          <t>BGP ASPA parameters for BGP routes.</t>
        </li>
        <li>
          <t>AS_PATH validity states of BGP routes.</t>
        </li>
      </ul>
    </section>
    <section anchor="bgp-origin-as-validation-yang-module">
      <name>BGP Origin AS Validation YANG Module</name>
      <section anchor="tree-view">
        <name>Tree View</name>
        <t>The complete tree of the ietf-bgp-origin-as-validation.yang data
   model is shown below. See <xref target="RFC8340"/> for an explanation
   of the symbols used.</t>
        <artwork type="ascii-art"><![CDATA[
module: ietf-bgp-origin-as-validation

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast:
    +--rw origin-as-validation
       +--rw enabled?             boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
       |                              /policy-definitions
       |                              /policy-definition/name
       +--rw redistribution-as?   inet:as-number

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast:
    +--rw origin-as-validation
       +--rw enabled?             boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
       |                              /policy-definitions
       |                              /policy-definition/name
       +--rw redistribution-as?   inet:as-number

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-pre:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-pre:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-post:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-post:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:loc-rib:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:loc-rib:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-pre:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-pre:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-post:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-post:
    +--ro statistics
       +--ro validation-state-unverified?   yang:gauge32
       +--ro validation-state-unknown?      yang:gauge32
       +--ro validation-state-invalid?      yang:gauge32
       +--ro validation-state-valid?        yang:gauge32

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro origin-as-validity?        origin-as-validity-state
    +--ro validity-invalid-reason?   route-validity-invalid-reason

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro origin-as-validity?        origin-as-validity-state
    +--ro validity-invalid-reason?   route-validity-invalid-reason

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:route-selection-options:
    +--rw origin-as
       +--rw enabled?           boolean
       +--rw allow-invalid?     boolean
       +--rw allow-not-found?   boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw origin-as-validity-advertisement
    |  +--rw send-origin-as-validity? boolean
    |  +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
    |                                 /policy-definitions
    |                                 /policy-definition/name
    +--rw export-origin-as-validation
       +--rw enabled?           boolean
       +--rw allow-not-found?   boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw origin-as-validity-advertisement
    |  +--rw send-origin-as-validity? boolean
    |  +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
    |                                 /policy-definitions
    |                                 /policy-definition/name
    +--rw export-origin-as-validation
       +--rw enabled?           boolean
       +--rw allow-not-found?   boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw origin-as-validity-advertisement
    |  +--rw send-origin-as-validity? boolean
    |  +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
    |                                 /policy-definitions
    |                                 /policy-definition/name
    +--rw export-origin-as-validation
       +--rw enabled?           boolean
       +--rw allow-not-found?   boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw origin-as-validity-advertisement
    |  +--rw send-origin-as-validity? boolean
    |  +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
    |                                 /policy-definitions
    |                                 /policy-definition/name
    +--rw export-origin-as-validation
       +--rw enabled?           boolean
       +--rw allow-not-found?   boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name
]]></artwork>
      </section>
      <section anchor="yang-module">
        <name>YANG Module</name>
        <t>This YANG module has normative references to <xref target="RFC6811"/>, <xref target="RFC8097"/>, <xref target="RFC8481"/>, <xref target="RFC8349"/>, <xref target="RFC8893"/>, <xref target="RFC9067"/>, <xref target="RFC9911"/>, and the BGP YANG model <xref target="I-D.ietf-idr-bgp-model"/>.</t>
        <sourcecode type="yang" markers="true" name="ietf-bgp-origin-as-validation@2026-09-28.yang"><![CDATA[
module ietf-bgp-origin-as-validation {
  yang-version "1.1";
  namespace "urn:ietf:params:xml:ns:yang:"
          + "ietf-bgp-origin-as-validation";
  prefix bgp-oav;

  import ietf-yang-types {
    prefix yang;
    reference
      "RFC 9911: Common YANG Data Types, Section 3";
  }

  import ietf-inet-types {
    prefix inet;
    reference
      "RFC 9911: Common YANG Data Types, Section 4";
  }

  import ietf-routing {
    prefix rt;
    reference
      "RFC 8349: A YANG Data Model for Routing Management
                 (NMDA Version)";
  }

  import ietf-bgp {
    prefix bgp;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-afi-safi-types {
    prefix bast;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-rib-types {
    prefix brt;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import ietf-routing-policy {
    prefix rt-pol;
    reference
      "RFC 9067: A YANG Data Model for Routing Policy Management";
  }

  organization
    "IETF IDR Working Group";

  contact
    "WG Web:  <http://datatracker.ietf.org/wg/idr/>
     WG List: IDR <mailto:idr@ietf.org>

     Authors: Changwang Lin
              <mailto:linchangwang.04414@h3c.com>
              Yisong Liu
              <mailto:liuyisong@chinamobile.com>   
              Haibo Wang
              <mailto:rainsword.wang@huawei.com>
              Jishnu Roy
              <mailto:jishnur@juniper.net>
              Di Ma
              <mailto:madi@zdns.cn>";

  description
    "This module describes configuration of the BGP origin AS
     validation.

     The key words 'MUST', 'MUST NOT', 'REQUIRED', 'SHALL', 'SHALL
     NOT', 'SHOULD', 'SHOULD NOT', 'RECOMMENDED', 'NOT RECOMMENDED',
     'MAY', and 'OPTIONAL' in this document are to be interpreted as
     described in BCP 14 (RFC 2119) (RFC 8174) when, and only when,
     they appear in all capitals, as shown here.

     Copyright (c) 2026 IETF Trust and the persons identified as
     authors of the code. All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject to
     the license terms contained in, the Revised BSD License set
     forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (https://trustee.ietf.org/license-info).

     All revisions of IETF and IANA published modules can be found
     at the YANG Parameters registry group
     (https://www.iana.org/assignments/yang-parameters).

     This version of this YANG module is part of RFC XXXX; see the
     RFC itself for full legal notices.";

  revision 2026-09-28 {
    description
      "Initial Version";
    reference
      "RFC XXXX: YANG Data Model for BGP about RPKI";
  }

  identity ineligible-origin-as {
    base brt:ineligible-route-reason;
    description
      "Route was ineligible due to origin AS validation.";
  }

  typedef route-validity-invalid-reason {
    type enumeration {
      enum ineligible-origin-as {
        description
          "Route was ineligible due to origin AS number mismatch.";
      }
      enum ineligible-max-len {
        description
          "Route was ineligible due to prefix maximum length
           mismatch.";
      }
    }
    description
      "Origin AS validation state invalid reason of BGP routes.";
  }

  typedef origin-as-validity-state {
    type enumeration {
      enum not-found {
        description
          "No VRP Covers the Route Prefix.";
      }
      enum valid {
        description
          "At least one VRP Matches the Route Prefix.";
      }
      enum invalid {
        description
          "At least one VRP Covers the Route Prefix, but no VRP
           Matches it.";
      }
      enum disabled {
        description
          "BGP origin AS validation is not enabled.";
      }
    }
    description
      "Origin AS validation state of BGP routes.";
    reference
      "RFC 6811: BGP Prefix Origin Validation";
  }

  grouping origin-as-validation-config {
    description
      "Origin AS validation of BGP prefix.";
    container origin-as-validation {
      leaf enabled {
        type boolean;
        default "false";
        description
          "Whether origin AS validation of BGP prefix is enabled.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which origin AS validation
           is enabled.";
      }
      leaf redistribution-as {
        type inet:as-number;
        description
          "Specifies an AS number that MUST be used in the
           origin AS validation for redistributed routes since
           they have no AS_PATH.";
        reference
          "RFC 8481: Clarifications to BGP Origin Validation Based
                     on Resource Public Key Infrastructure (RPKI)";
      }
      description
        "Origin AS validation of BGP prefix.";
    }
  }

  grouping origin-as-selection-option {
    description
      "Origin AS option for BGP route selection.";
    container origin-as {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the origin AS validity states are
           taken into consideration in the best-path calculation.
           If set to false, the origin AS validity states are not
           taken into consideration in the best-path calculation.";
      }
      leaf allow-invalid {
        type boolean;
        default "false";
        description
          "When set to true, routes whose origin AS validation
           state is 'invalid' MAY be taken into consideration in
           the best-path calculation.  If set to false, such
           routes MUST be excluded from the best-path
           calculation.";
      }
      leaf allow-not-found {
        type boolean;
        default "true";
        description
          "When set to true, routes whose origin AS validation
           state is 'not-found' MAY be taken into consideration
           in the best-path calculation.  If set to false, such
           routes MUST be excluded from the best-path
           calculation.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which origin AS option
           is enabled for BGP route selection.";
      }
      description
        "Origin AS option for BGP route selection.";
    }
  }

  grouping origin-as-validity-advertisement {
    description
      "Structural grouping used for advertisement of Origin
       Validation State Extended Community to neighbor(s).";
    container origin-as-validity-advertisement {
      leaf send-origin-as-validity {
        type boolean;
        default "false";
        description
          "If set to true, the origin AS validity MUST be sent
           to the neighbor(s) using the Origin Validation State
           Extended Community.";
        reference
          "RFC 8097: BGP Prefix Origin Validation State Extended
                     Community";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which Origin Validation
           State Extended Community is advertised.";
      }
      description
        "Advertisement of Origin Validation State Extended
         Community to neighbor(s).";
    }
  }

  grouping export-origin-as-validation-config {
    description
      "Export origin AS validation of BGP prefix.";
    container export-origin-as-validation {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the origin AS validity states are
           taken into consideration in BGP export.  If set to
           false, the origin AS validity states are not taken
           into consideration in BGP export.";
      }
      leaf allow-not-found {
        type boolean;
        default "false";
        description
          "When set to true, routes with 'not-found' origin AS
           MAY be sent to the neighbor.  If set to false, such
           routes MUST NOT be sent to the neighbor.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which origin AS validity
           states are considered in BGP export.";
      }
      description
        "Export origin AS validation of BGP prefix.";
      reference
        "RFC 8893: Resource Public Key Infrastructure (RPKI) Origin
                   Validation for BGP Export";
    }
  }

  grouping origin-as-validity-statistics {
    description
      "Origin AS validation statistics.";
    container statistics {
      config false;
      leaf validation-state-unverified {
        type yang:gauge32;
        description
          "The number of routes with validation state as
           unverified.";
      }
      leaf validation-state-unknown {
        type yang:gauge32;
        description
          "The number of routes with validation state as
           unknown.";
      }
      leaf validation-state-invalid {
        type yang:gauge32;
        description
          "The number of routes with validation state as
           invalid.";
      }
      leaf validation-state-valid {
        type yang:gauge32;
        description
          "The number of routes with validation state as valid.";
      }
      description
        "Statistical data for origin AS validation states.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast" {
    description
      "Origin AS validation augmentation of BGP IPv4 Unicast
       Address Family.";
    uses origin-as-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast" {
    description
      "Origin AS validation augmentation of BGP IPv6 Unicast
       Address Family.";
    uses origin-as-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-pre" {
    description
      "Augmentation of BGP IPv4 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-pre" {
    description
      "Augmentation of BGP IPv6 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-post" {
    description
      "Augmentation of BGP IPv4 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-in-post" {
    description
      "Augmentation of BGP IPv6 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:loc-rib" {
    description
      "Augmentation of BGP IPv4 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:loc-rib" {
    description
      "Augmentation of BGP IPv6 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-pre" {
    description
      "Augmentation of BGP IPv4 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-pre" {
    description
      "Augmentation of BGP IPv6 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-post" {
    description
      "Augmentation of BGP IPv4 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:neighbors/bgp:neighbor/bgp:adj-rib-out-post" {
    description
      "Augmentation of BGP IPv6 Unicast route statistics.";
    uses origin-as-validity-statistics;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "Origin AS validity augmentation of BGP IPv4 Unicast
       route.";
    leaf origin-as-validity {
      type origin-as-validity-state;
      description
        "Origin AS validity of BGP IPv4 Unicast prefix.";
    }
    leaf validity-invalid-reason {
      type route-validity-invalid-reason;
      description
        "Reason for marking a BGP IPv4 Unicast prefix as
         invalid.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "Origin AS validity augmentation of BGP IPv6 Unicast
       route.";
    leaf origin-as-validity {
      type origin-as-validity-state;
      description
        "Origin AS validity of BGP IPv6 Unicast prefix.";
    }
    leaf validity-invalid-reason {
      type route-validity-invalid-reason;
      description
        "Reason for marking a BGP IPv6 Unicast prefix as
         invalid.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:route-selection-options" {
    when "derived-from-or-self(../bgp:name, 'bast:ipv4-unicast') or "
       + "derived-from-or-self(../bgp:name, 'bast:ipv6-unicast')" {
      description
        "This augmentation is valid for IPv4 and IPv6 Unicast.";
    }
    description
      "Augmentation of BGP route selection options.";
    uses origin-as-selection-option;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "Augmentation of origin AS validation sending management
       for IPv4 Unicast neighbor.";
    uses origin-as-validity-advertisement;
    uses export-origin-as-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "Augmentation of origin AS validation sending management
       for IPv6 Unicast neighbor.";
    uses origin-as-validity-advertisement;
    uses export-origin-as-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "Augmentation of origin AS validation sending management
       for IPv4 Unicast peer group.";
    uses origin-as-validity-advertisement;
    uses export-origin-as-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "Augmentation of origin AS validation sending management
       for IPv6 Unicast peer group.";
    uses origin-as-validity-advertisement;
    uses export-origin-as-validation-config;
  }
}
]]></sourcecode>
      </section>
    </section>
    <section anchor="bgpsec-yang-module">
      <name>BGPsec YANG Module</name>
      <section anchor="tree-view-1">
        <name>Tree View</name>
        <t>The complete tree of the ietf-bgp-sec.yang data model is shown
   below. See <xref target="RFC8340"/> for an explanation of the symbols used.</t>
        <artwork type="ascii-art"><![CDATA[
module: ietf-bgp-sec

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast:
    +--rw bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast:
    +--rw bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro bgpsec-validity?     bgpsec-validity-state

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro bgpsec-validity?     bgpsec-validity-state

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:route-selection-options:
    +--rw bgpsec
       +--rw enabled?                 boolean
       +--rw allow-invalid?           boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw export-bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw export-bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw export-bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw export-bgpsec-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                      /policy-definitions
                                      /policy-definition/name
]]></artwork>
      </section>
      <section anchor="yang-module-1">
        <name>YANG Module</name>
        <t>This YANG module has normative references to <xref target="RFC8205"/>, <xref target="RFC8349"/>, <xref target="RFC9067"/>, and the BGP YANG model <xref target="I-D.ietf-idr-bgp-model"/>.</t>
        <sourcecode type="yang" markers="true" name="ietf-bgp-sec@2026-09-28.yang"><![CDATA[
module ietf-bgp-sec {
  yang-version "1.1";
  namespace "urn:ietf:params:xml:ns:yang:"
          + "ietf-bgp-sec";
  prefix bgp-sec;

  import ietf-routing {
    prefix rt;
    reference
      "RFC 8349: A YANG Data Model for Routing Management
                 (NMDA Version)";
  }

  import ietf-bgp {
    prefix bgp;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-afi-safi-types {
    prefix bast;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-rib-types {
    prefix brt;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import ietf-routing-policy {
    prefix rt-pol;
    reference
      "RFC 9067: A YANG Data Model for Routing Policy Management";
  }

  organization
    "IETF IDR Working Group";

  contact
    "WG Web:  <http://datatracker.ietf.org/wg/idr/>
     WG List: IDR <mailto:idr@ietf.org>

     Authors: Changwang Lin
              <mailto:linchangwang.04414@h3c.com>
	          Yisong Liu
              <mailto:liuyisong@chinamobile.com>
              Haibo Wang
              <mailto:rainsword.wang@huawei.com>
              Jishnu Roy
              <mailto:jishnur@juniper.net>
              Di Ma
              <mailto:madi@zdns.cn>";

  description
    "This module describes management of BGPsec.

     The key words 'MUST', 'MUST NOT', 'REQUIRED', 'SHALL', 'SHALL
     NOT', 'SHOULD', 'SHOULD NOT', 'RECOMMENDED', 'NOT RECOMMENDED',
     'MAY', and 'OPTIONAL' in this document are to be interpreted as
     described in BCP 14 (RFC 2119) (RFC 8174) when, and only when,
     they appear in all capitals, as shown here.

     Copyright (c) 2026 IETF Trust and the persons identified as
     authors of the code. All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject to
     the license terms contained in, the Revised BSD License set
     forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (https://trustee.ietf.org/license-info).

     All revisions of IETF and IANA published modules can be found
     at the YANG Parameters registry group
     (https://www.iana.org/assignments/yang-parameters).

     This version of this YANG module is part of RFC XXXX;
     see the RFC itself for full legal notices.";

  revision 2026-09-28 {
    description
      "Initial Version";
    reference
      "RFC XXXX: YANG Data Model for BGP about RPKI";
  }

  identity ineligible-bgp {
    base brt:ineligible-route-reason;
    description
      "Route was ineligible due to BGPsec.";
  }

  typedef bgpsec-validity-state {
    type enumeration {
      enum valid {
        description
          "The BGPsec validation state of the route is valid.";
      }
      enum invalid {
        description
          "The BGPsec validation state of the route is invalid.";
      }
      enum disabled {
        description
          "BGPsec validation is not enabled.";
      }
    }
    description
      "BGPsec validation state of BGP routes.";
    reference
      "RFC 8205: BGPsec Protocol Specification";
  }

  grouping bgpsec-validation-config {
    description
      "BGPsec validation of BGP prefix.";
    container bgpsec-validation {
      leaf enabled {
        type boolean;
        default "false";
        description
          "Whether BGPsec validation of BGP prefix is enabled.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which BGPsec validation
           is enabled.";
      }
      description
        "BGPsec validation of BGP prefix.";
    }
  }

  grouping bgpsec-selection-option {
    description
      "BGPsec option for BGP route selection.";
    container bgpsec {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the BGPsec validity states are
           taken into consideration in the best-path calculation.
           If set to false, the BGPsec validity states are not
           taken into consideration in the best-path calculation.";
      }

      leaf allow-invalid {
        type boolean;
        default "false";
        description
          "When set to true, routes whose BGPsec validity state
           is 'invalid' MAY be taken into consideration in the
           best-path calculation.  If set to false, such routes
           MUST be excluded from the best-path calculation.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which BGPsec option
           is enabled in BGP route selection.";
      }
      description
        "BGPsec option for BGP route selection.";
    }
  }

  grouping export-bgpsec-validation-config {
    description
      "Export BGPsec validation of BGP prefix.";
    container export-bgpsec-validation {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the BGPsec validity states are
           taken into consideration in BGP export.  If set to
           false, the BGPsec validity states are not taken into
           consideration in BGP export.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which BGPsec validity
           states are considered in BGP export.";
      }
      description
        "Export BGPsec validation of BGP prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast" {
    description
      "BGPsec augmentation of BGP IPv4 Unicast Address Family.";
    uses bgpsec-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast" {
    description
      "BGPsec augmentation of BGP IPv6 Unicast Address Family.";
    uses bgpsec-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "BGPsec augmentation of BGP IPv4 Unicast route.";
    leaf bgpsec-validity {
      type bgpsec-validity-state;
      description
        "BGPsec validity of BGP IPv4 Unicast prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "BGPsec augmentation of BGP IPv6 Unicast route.";
    leaf bgpsec-validity {
      type bgpsec-validity-state;
      description
        "BGPsec validity of BGP IPv6 Unicast prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:route-selection-options" {
    when "derived-from-or-self(../bgp:name, 'bast:ipv4-unicast') or "
       + "derived-from-or-self(../bgp:name, 'bast:ipv6-unicast')" {
      description
        "This augmentation is valid for IPv4 and IPv6 Unicast.";
    }
    description
      "BGPsec augmentation of BGP route selection options.";
    uses bgpsec-selection-option;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "BGPsec augmentation for IPv4 Unicast neighbor.";
    uses export-bgpsec-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "BGPsec augmentation for IPv6 Unicast neighbor.";
    uses export-bgpsec-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "BGPsec augmentation for IPv4 Unicast peer group.";
    uses export-bgpsec-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "BGPsec augmentation for IPv6 Unicast peer group.";
    uses export-bgpsec-validation-config;
  }
}
]]></sourcecode>
      </section>
    </section>
    <section anchor="bgp-aspa-yang-module">
      <name>BGP ASPA YANG Module</name>
      <section anchor="tree-view-2">
        <name>Tree View</name>
        <t>The complete tree of the ietf-bgp-aspa.yang data model is
   shown below. See <xref target="RFC8340"/> for an explanation of the
   symbols used.</t>
        <artwork type="ascii-art"><![CDATA[
module: ietf-bgp-aspa

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor:
    +--rw peer-role?           peer-role

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group:
    +--rw peer-role?           peer-role

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast:
    +--rw aspa-verification
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast:
    +--rw aspa-verification
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro aspa-verification-state?  aspa-verification-state

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:rib
            /bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast
            /bgp:loc-rib/bgp:routes/bgp:route:
    +--ro aspa-verification-state?  aspa-verification-state

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:global
            /bgp:afi-safis/bgp:afi-safi/bgp:route-selection-options:
    +--rw aspa
       +--rw enabled?                 boolean
       +--rw allow-invalid?           boolean
       +--rw allow-unknown?           boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw export-aspa-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:neighbors
            /bgp:neighbor/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw export-aspa-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv4-unicast:
    +--rw export-aspa-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name

  augment /rt:routing/rt:control-plane-protocols
            /rt:control-plane-protocol/bgp:bgp/bgp:peer-groups
            /bgp:peer-group/bgp:afi-safis/bgp:afi-safi
            /bgp:ipv6-unicast:
    +--rw export-aspa-validation
       +--rw enabled?                 boolean
       +--rw eligible-prefix-policy?  -> /rt-pol:routing-policy
                                         /policy-definitions
                                         /policy-definition/name
]]></artwork>
      </section>
      <section anchor="yang-module-2">
        <name>YANG Module</name>
        <t>This YANG module has normative references to <xref target="RFC8349"/>, <xref target="RFC9067"/>, the BGP YANG model <xref target="I-D.ietf-idr-bgp-model"/>, and the ASPA verification algorithm <xref target="I-D.ietf-sidrops-aspa-verification"/>.</t>
        <sourcecode type="yang" markers="true" name="ietf-bgp-aspa@2026-09-28.yang"><![CDATA[
module ietf-bgp-aspa {
  yang-version "1.1";
  namespace "urn:ietf:params:xml:ns:yang:"
          + "ietf-bgp-aspa";
  prefix bgp-aspa;

  import ietf-routing {
    prefix rt;
    reference
      "RFC 8349: A YANG Data Model for Routing Management
                 (NMDA Version)";
  }

  import ietf-bgp {
    prefix bgp;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-afi-safi-types {
    prefix bast;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import iana-bgp-rib-types {
    prefix brt;
    reference
      "I-D.ietf-idr-bgp-model: YANG Model for Border Gateway
                 Protocol (BGP-4)";
  }

  import ietf-routing-policy {
    prefix rt-pol;
    reference
      "RFC 9067: A YANG Data Model for Routing Policy Management";
  }

  organization
    "IETF IDR Working Group";

  contact
    "WG Web:  <http://datatracker.ietf.org/wg/idr/>
     WG List: IDR <mailto:idr@ietf.org>

     Authors: Changwang Lin
              <mailto:linchangwang.04414@h3c.com>
	          Yisong Liu
              <mailto:liuyisong@chinamobile.com>
              Haibo Wang
              <mailto:rainsword.wang@huawei.com>
              Jishnu Roy
              <mailto:jishnur@juniper.net>
              Di Ma
              <mailto:madi@zdns.cn>";

  description
    "This module describes management of the BGP AS_PATH
     Verification Based on ASPA.

     The key words 'MUST', 'MUST NOT', 'REQUIRED', 'SHALL', 'SHALL
     NOT', 'SHOULD', 'SHOULD NOT', 'RECOMMENDED', 'NOT RECOMMENDED',
     'MAY', and 'OPTIONAL' in this document are to be interpreted as
     described in BCP 14 (RFC 2119) (RFC 8174) when, and only when,
     they appear in all capitals, as shown here.

     Copyright (c) 2026 IETF Trust and the persons identified as
     authors of the code. All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject to
     the license terms contained in, the Revised BSD License set
     forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (https://trustee.ietf.org/license-info).

     All revisions of IETF and IANA published modules can be found
     at the YANG Parameters registry group
     (https://www.iana.org/assignments/yang-parameters).

     This version of this YANG module is part of RFC XXXX;
     see the RFC itself for full legal notices.";

  revision 2026-09-28 {
    description
      "Initial Version";
    reference
      "RFC XXXX: YANG Data Model for BGP about RPKI";
  }

  identity ineligible-aspa {
    base brt:ineligible-route-reason;
    description
      "Route was ineligible due to ASPA verification.";
  }

  typedef peer-role {
    type enumeration {
      enum customer {
        description
          "The role of the BGP peer is customer.";
      }
      enum provider {
        description
          "The role of the BGP peer is provider.";
      }
      enum lateral-peer {
        description
          "The role of the BGP peer is lateral peer.";
      }
      enum rs {
        description
          "The role of the BGP peer is Route Server (RS).";
      }
      enum rs-client {
        description
          "The role of the BGP peer is RS-client.";
      }
      enum mutual-transit {
        description
          "The role of the BGP peer is mutual-transit.";
      }
    }
    description
      "Roles of BGP peers.";
    reference
      "I-D.ietf-sidrops-aspa-verification: BGP AS_PATH Verification
                 Based on Autonomous System Provider Authorization
                 (ASPA) Objects";
  }

  typedef aspa-verification-state {
    type enumeration {
      enum valid {
        description
          "The ASPA verification outcome is valid.";
      }
      enum invalid {
        description
          "The ASPA verification outcome is invalid.";
      }
      enum unknown {
        description
          "The ASPA verification outcome is unknown.";
      }
      enum disabled {
        description
          "BGP ASPA verification is not enabled.";
      }
    }
    description
      "ASPA verification state of BGP routes.";
    reference
      "I-D.ietf-sidrops-aspa-verification: BGP AS_PATH Verification
                 Based on Autonomous System Provider Authorization
                 (ASPA) Objects";
  }

  grouping aspa-config {
    description
      "ASPA verification of BGP prefix.";
    container aspa-verification {
      leaf enabled {
        type boolean;
        default "false";
        description
          "Whether ASPA verification of BGP prefix is enabled.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which ASPA verification
           is enabled.";
      }
      description
        "ASPA verification of BGP prefix.";
    }
  }

  grouping aspa-selection-option {
    description
      "ASPA option for BGP route selection.";
    container aspa {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the ASPA verification states are
           taken into consideration in the best-path calculation.
           If set to false, the ASPA verification states are not
           taken into consideration in the best-path calculation.";
      }
      leaf allow-invalid {
        type boolean;
        default "false";
        description
          "When set to true, routes whose ASPA verification state
           is 'invalid' MAY be taken into consideration in the
           best-path calculation.  If set to false, such routes
           MUST be excluded from the best-path calculation.";
      }
      leaf allow-unknown {
        type boolean;
        default "true";
        description
          "When set to true, routes whose ASPA verification state
           is 'unknown' MAY be taken into consideration in the
           best-path calculation.  If set to false, such routes
           MUST be excluded from the best-path calculation.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which ASPA option
           is enabled in BGP route selection.";
      }
      description
        "ASPA option for BGP route selection.";
    }
  }

  grouping export-aspa-validation-config {
    description
      "Export AS_PATH validation of BGP prefix.";
    container export-aspa-validation {
      leaf enabled {
        type boolean;
        default "false";
        description
          "When set to true, the AS_PATH validity states are
           taken into consideration in BGP export.  If set to
           false, the AS_PATH validity states are not taken into
           consideration in BGP export.";
      }
      leaf eligible-prefix-policy {
        type leafref {
          path "/rt-pol:routing-policy/rt-pol:policy-definitions/"
             + "rt-pol:policy-definition/rt-pol:name";
        }
        description
          "A reference to a routing policy which can be used to
           restrict the prefixes for which AS_PATH validity
           states are considered in BGP export.";
      }
      description
        "Export AS_PATH validation of BGP prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor" {
    description
      "Augmentation of BGP peer roles for neighbors.";
    leaf peer-role {
      type peer-role;
      description
        "Role of the peer.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group" {
    description
      "Augmentation of BGP peer roles for peer groups.";
    leaf peer-role {
      type peer-role;
      description
        "Role of the peer group.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast" {
    description
      "ASPA verification augmentation of BGP IPv4 Unicast
       Address Family.";
    uses aspa-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast" {
    description
      "ASPA verification augmentation of BGP IPv6 Unicast
       Address Family.";
    uses aspa-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv4-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "ASPA verification state augmentation of BGP IPv4
       Unicast route.";
    leaf aspa-verification-state {
      type aspa-verification-state;
      description
        "ASPA verification state of BGP IPv4 Unicast prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:rib"
        + "/bgp:afi-safis/bgp:afi-safi/bgp:ipv6-unicast"
        + "/bgp:loc-rib/bgp:routes/bgp:route" {
    description
      "ASPA verification state augmentation of BGP IPv6
       Unicast route.";
    leaf aspa-verification-state {
      type aspa-verification-state;
      description
        "ASPA verification state of BGP IPv6 Unicast prefix.";
    }
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:global"
        + "/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:route-selection-options" {
    when "derived-from-or-self(../bgp:name, 'bast:ipv4-unicast') or "
       + "derived-from-or-self(../bgp:name, 'bast:ipv6-unicast')" {
      description
        "This augmentation is valid for IPv4 and IPv6 Unicast.";
    }
    description
      "Augmentation of BGP route selection options.";
    uses aspa-selection-option;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "ASPA export validation augmentation for IPv4 Unicast
       neighbor.";
    uses export-aspa-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:neighbors"
        + "/bgp:neighbor/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "ASPA export validation augmentation for IPv6 Unicast
       neighbor.";
    uses export-aspa-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv4-unicast" {
    description
      "ASPA export validation augmentation for IPv4 Unicast
       peer group.";
    uses export-aspa-validation-config;
  }

  augment "/rt:routing/rt:control-plane-protocols"
        + "/rt:control-plane-protocol/bgp:bgp/bgp:peer-groups"
        + "/bgp:peer-group/bgp:afi-safis/bgp:afi-safi"
        + "/bgp:ipv6-unicast" {
    description
      "ASPA export validation augmentation for IPv6 Unicast
       peer group.";
    uses export-aspa-validation-config;
  }
}
]]></sourcecode>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>This section is modeled after the template described in Section 3.7.1
   of <xref target="RFC9907"/>.</t>
      <t>All the YANG modules in this document define data models that are
   designed to be accessed via YANG-based management protocols, such as Network Configuration
   Protocol (NETCONF) <xref target="RFC6241"/> and RESTCONF <xref target="RFC8040"/>. These YANG-based management
   protocols (1) have to use a secure transport layer (e.g., Secure Shell (SSH) <xref target="RFC4252"/>,
   TLS <xref target="RFC9846"/>, and QUIC <xref target="RFC9000"/>) and (2) have to use mutual authentication.</t>
      <t>The Network Configuration Access Control Model (NACM) <xref target="RFC8341"/>
   provides the means to restrict access for particular NETCONF or
   RESTCONF users to a preconfigured subset of all available NETCONF or
   RESTCONF protocol operations and content.</t>
      <t>There are a number of data nodes defined in these YANG modules that are
   writable/creatable/deletable (i.e., config true, which is the
   default). All writable data nodes are likely to be sensitive or
   vulnerable in some network environments. Write operations (e.g.,
   edit-config) and delete operations to these data nodes without proper
   protection or authentication can have a negative effect on network
   operations. The following subtrees and data nodes have particular
   sensitivities/vulnerabilities:</t>
      <ul spacing="compact">
        <li>
          <t>ietf-bgp-origin-as-validation:</t>
          <ul spacing="compact">
            <li><t>/bgp-oav:origin-as-validation/bgp-oav:enabled</t></li>
            <li><t>/bgp-oav:origin-as-validation/bgp-oav:redistribution-as</t></li>
            <li><t>/bgp-oav:origin-as/bgp-oav:enabled</t></li>
            <li><t>/bgp-oav:origin-as/bgp-oav:allow-invalid</t></li>
            <li><t>/bgp-oav:origin-as/bgp-oav:allow-not-found</t></li>
            <li><t>/bgp-oav:origin-as-validity-advertisement/bgp-oav:send-origin-as-validity</t></li>
            <li><t>/bgp-oav:export-origin-as-validation/bgp-oav:enabled</t></li>
            <li><t>/bgp-oav:origin-as-validation/bgp-oav:eligible-prefix-policy</t></li>
            <li><t>/bgp-oav:origin-as/bgp-oav:eligible-prefix-policy</t></li>
            <li><t>/bgp-oav:origin-as-validity-advertisement/bgp-oav:eligible-prefix-policy</t></li>
            <li><t>/bgp-oav:export-origin-as-validation/bgp-oav:eligible-prefix-policy</t></li>
          </ul>
        </li>
        <li>
          <t>ietf-bgp-sec:</t>
          <ul spacing="compact">
            <li><t>/bgp-sec:bgpsec-validation/bgp-sec:enabled</t></li>
            <li><t>/bgp-sec:bgpsec/bgp-sec:enabled</t></li>
            <li><t>/bgp-sec:bgpsec/bgp-sec:allow-invalid</t></li>
            <li><t>/bgp-sec:export-bgpsec-validation/bgp-sec:enabled</t></li>
            <li><t>/bgp-sec:bgpsec-validation/bgp-sec:eligible-prefix-policy</t></li>
            <li><t>/bgp-sec:bgpsec/bgp-sec:eligible-prefix-policy</t></li>
            <li><t>/bgp-sec:export-bgpsec-validation/bgp-sec:eligible-prefix-policy</t></li>
          </ul>
        </li>
        <li>
          <t>ietf-bgp-aspa:</t>
          <ul spacing="compact">
            <li><t>/bgp-aspa:peer-role</t></li>
            <li><t>/bgp-aspa:aspa-verification/bgp-aspa:enabled</t></li>
            <li><t>/bgp-aspa:aspa/bgp-aspa:enabled</t></li>
            <li><t>/bgp-aspa:aspa/bgp-aspa:allow-invalid</t></li>
            <li><t>/bgp-aspa:aspa/bgp-aspa:allow-unknown</t></li>
            <li><t>/bgp-aspa:export-aspa-validation/bgp-aspa:enabled</t></li>
            <li><t>/bgp-aspa:aspa-verification/bgp-aspa:eligible-prefix-policy</t></li>
            <li><t>/bgp-aspa:aspa/bgp-aspa:eligible-prefix-policy</t></li>
            <li><t>/bgp-aspa:export-aspa-validation/bgp-aspa:eligible-prefix-policy</t></li>
          </ul>
        </li>
      </ul>
      <t>There are no particularly sensitive readable data nodes.</t>
      <t>There are no particularly sensitive RPC or action operations.</t>
      <t>These YANG modules define a set of identities, types, and
   groupings, and augment nodes defined in the modules they import (e.g.,
   ietf-bgp <xref target="I-D.ietf-idr-bgp-model"/>). An attacker modifying the nodes
   augmented in ietf-bgp can influence BGP route handling. Refer to the
   Security Considerations of <xref target="I-D.ietf-idr-bgp-model"/> for information as to
   which data nodes in the augmented and imported modules may be
   considered sensitive or vulnerable in network environments.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>RFC Ed.: In this section, replace all occurrences of 'XXXX' with the
   actual RFC number (and remove this note).</t>
      <section anchor="ietf-xml-registry">
        <name>IETF XML Registry</name>
        <t>The IANA is requested to assign the following URI in the "IETF XML
   Registry" <xref target="RFC3688"/>:</t>
        <artwork type="ascii-art"><![CDATA[
   URI: urn:ietf:params:xml:ns:yang:ietf-bgp-origin-as-validation
   Registrant Contact: The IESG.
   XML: N/A; the requested URI is an XML namespace.

   URI: urn:ietf:params:xml:ns:yang:ietf-bgp-sec
   Registrant Contact: The IESG.
   XML: N/A; the requested URI is an XML namespace.

   URI: urn:ietf:params:xml:ns:yang:ietf-bgp-aspa
   Registrant Contact: The IESG.
   XML: N/A; the requested URI is an XML namespace.
]]></artwork>
      </section>
      <section anchor="yang-module-names-registry">
        <name>YANG Module Names Registry</name>
        <t>This document registers the following YANG modules in the "YANG
   Module Names" registry <xref target="RFC6020"/>:</t>
        <artwork type="ascii-art"><![CDATA[
   Name:      ietf-bgp-origin-as-validation
   Maintained by IANA?  N
   Namespace: urn:ietf:params:xml:ns:yang:
              ietf-bgp-origin-as-validation
   Prefix:    bgp-oav
   Reference: RFC XXXX

   Name:      ietf-bgp-sec
   Maintained by IANA?  N
   Namespace: urn:ietf:params:xml:ns:yang:ietf-bgp-sec
   Prefix:    bgp-sec
   Reference: RFC XXXX

   Name:      ietf-bgp-aspa
   Maintained by IANA?  N
   Namespace: urn:ietf:params:xml:ns:yang:ietf-bgp-aspa
   Prefix:    bgp-aspa
   Reference: RFC XXXX
]]></artwork>
        <!-- 
# Acknowledgments

#Thanks to Mohamed Boucadair for review and comments.

#Thanks to David Blacka for the DNSDIR, Mike Ounsworth for the SECDIR,
#Michael P for the OPSDIR, Robert Wills for the YANGDOCTORS, and
#Behcet Sarikaya for the GENART review.

#Thanks to Deb Cooley, Eric Vyncke, Gorry Fairhurst, Roman Danyliw, Andy Newton,
#Christopher Inacio, Mahesh Jethanandani, Mike Bishop, Charles Eckel, Gunter Van de Velde,
#Jim Guichard, Ketan Talaulikar, and Tommy Jensen for the IESG review.
-->

</section>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC2119" target="https://www.rfc-editor.org/info/rfc2119" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC3688" target="https://www.rfc-editor.org/info/rfc3688" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.3688.xml">
          <front>
            <title>The IETF XML Registry</title>
            <author fullname="M. Mealling" initials="M." surname="Mealling"/>
            <date month="January" year="2004"/>
            <abstract>
              <t>This document describes an IANA maintained registry for IETF standards which use Extensible Markup Language (XML) related items such as Namespaces, Document Type Declarations (DTDs), Schemas, and Resource Description Framework (RDF) Schemas.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="81"/>
          <seriesInfo name="RFC" value="3688"/>
          <seriesInfo name="DOI" value="10.17487/RFC3688"/>
        </reference>
        <reference anchor="RFC6020" target="https://www.rfc-editor.org/info/rfc6020" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.6020.xml">
          <front>
            <title>YANG - A Data Modeling Language for the Network Configuration Protocol (NETCONF)</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="October" year="2010"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration and state data manipulated by the Network Configuration Protocol (NETCONF), NETCONF remote procedure calls, and NETCONF notifications. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6020"/>
          <seriesInfo name="DOI" value="10.17487/RFC6020"/>
        </reference>
        <reference anchor="RFC6811" target="https://www.rfc-editor.org/info/rfc6811" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.6811.xml">
          <front>
            <title>BGP Prefix Origin Validation</title>
            <author fullname="P. Mohapatra" initials="P." surname="Mohapatra"/>
            <author fullname="J. Scudder" initials="J." surname="Scudder"/>
            <author fullname="D. Ward" initials="D." surname="Ward"/>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <date month="January" year="2013"/>
            <abstract>
              <t>To help reduce well-known threats against BGP including prefix mis- announcing and monkey-in-the-middle attacks, one of the security requirements is the ability to validate the origination Autonomous System (AS) of BGP routes. More specifically, one needs to validate that the AS number claiming to originate an address prefix (as derived from the AS_PATH attribute of the BGP route) is in fact authorized by the prefix holder to do so. This document describes a simple validation mechanism to partially satisfy this requirement. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6811"/>
          <seriesInfo name="DOI" value="10.17487/RFC6811"/>
        </reference>
        <reference anchor="RFC7950" target="https://www.rfc-editor.org/info/rfc7950" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.7950.xml">
          <front>
            <title>The YANG 1.1 Data Modeling Language</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration data, state data, Remote Procedure Calls, and notifications for network management protocols. This document describes the syntax and semantics of version 1.1 of the YANG language. YANG version 1.1 is a maintenance release of the YANG language, addressing ambiguities and defects in the original specification. There are a small number of backward incompatibilities from YANG version 1. This document also specifies the YANG mappings to the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7950"/>
          <seriesInfo name="DOI" value="10.17487/RFC7950"/>
        </reference>
        <reference anchor="RFC8097" target="https://www.rfc-editor.org/info/rfc8097" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8097.xml">
          <front>
            <title>BGP Prefix Origin Validation State Extended Community</title>
            <author fullname="P. Mohapatra" initials="P." surname="Mohapatra"/>
            <author fullname="K. Patel" initials="K." surname="Patel"/>
            <author fullname="J. Scudder" initials="J." surname="Scudder"/>
            <author fullname="D. Ward" initials="D." surname="Ward"/>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <date month="March" year="2017"/>
            <abstract>
              <t>This document defines a new BGP opaque extended community to carry the origin validation state of a route as computed according to RFC 6811.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8097"/>
          <seriesInfo name="DOI" value="10.17487/RFC8097"/>
        </reference>
        <reference anchor="RFC8174" target="https://www.rfc-editor.org/info/rfc8174" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
        <reference anchor="RFC8205" target="https://www.rfc-editor.org/info/rfc8205" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8205.xml">
          <front>
            <title>BGPsec Protocol Specification</title>
            <author fullname="M. Lepinski" initials="M." role="editor" surname="Lepinski"/>
            <author fullname="K. Sriram" initials="K." role="editor" surname="Sriram"/>
            <date month="September" year="2017"/>
            <abstract>
              <t>This document describes BGPsec, an extension to the Border Gateway Protocol (BGP) that provides security for the path of Autonomous Systems (ASes) through which a BGP UPDATE message passes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8205"/>
          <seriesInfo name="DOI" value="10.17487/RFC8205"/>
        </reference>
        <reference anchor="RFC8341" target="https://www.rfc-editor.org/info/rfc8341" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8341.xml">
          <front>
            <title>Network Configuration Access Control Model</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>The standardization of network configuration interfaces for use with the Network Configuration Protocol (NETCONF) or the RESTCONF protocol requires a structured and secure operating environment that promotes human usability and multi-vendor interoperability. There is a need for standard mechanisms to restrict NETCONF or RESTCONF protocol access for particular users to a preconfigured subset of all available NETCONF or RESTCONF protocol operations and content. This document defines such an access control model.</t>
              <t>This document obsoletes RFC 6536.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="91"/>
          <seriesInfo name="RFC" value="8341"/>
          <seriesInfo name="DOI" value="10.17487/RFC8341"/>
        </reference>
        <reference anchor="RFC8342" target="https://www.rfc-editor.org/info/rfc8342" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8342.xml">
          <front>
            <title>Network Management Datastore Architecture (NMDA)</title>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="J. Schoenwaelder" initials="J." surname="Schoenwaelder"/>
            <author fullname="P. Shafer" initials="P." surname="Shafer"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <author fullname="R. Wilton" initials="R." surname="Wilton"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>Datastores are a fundamental concept binding the data models written in the YANG data modeling language to network management protocols such as the Network Configuration Protocol (NETCONF) and RESTCONF. This document defines an architectural framework for datastores based on the experience gained with the initial simpler model, addressing requirements that were not well supported in the initial model. This document updates RFC 7950.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8342"/>
          <seriesInfo name="DOI" value="10.17487/RFC8342"/>
        </reference>
        <reference anchor="RFC8349" target="https://www.rfc-editor.org/info/rfc8349" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8349.xml">
          <front>
            <title>A YANG Data Model for Routing Management (NMDA Version)</title>
            <author fullname="L. Lhotka" initials="L." surname="Lhotka"/>
            <author fullname="A. Lindem" initials="A." surname="Lindem"/>
            <author fullname="Y. Qu" initials="Y." surname="Qu"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>This document specifies three YANG modules and one submodule for the management of a router: routing management, Routing Information Bases (RIBs), and control-plane protocols. The YANG modules conform to the Network Management Datastore Architecture (NMDA).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8349"/>
          <seriesInfo name="DOI" value="10.17487/RFC8349"/>
        </reference>
        <reference anchor="RFC8481" target="https://www.rfc-editor.org/info/rfc8481" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8481.xml">
          <front>
            <title>Clarifications to BGP Origin Validation Based on Resource Public Key Infrastructure (RPKI)</title>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <date month="September" year="2018"/>
            <abstract>
              <t>Deployment of BGP origin validation based on Resource Public Key Infrastructure (RPKI) is hampered by, among other things, vendor inconsistency, partial implementation, and the lack of operational guidance. This document provides clarification of RFC 6811.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8481"/>
          <seriesInfo name="DOI" value="10.17487/RFC8481"/>
        </reference>
        <reference anchor="RFC8893" target="https://www.rfc-editor.org/info/rfc8893" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8893.xml">
          <front>
            <title>Resource Public Key Infrastructure (RPKI) Origin Validation for BGP Export</title>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <author fullname="R. Volk" initials="R." surname="Volk"/>
            <author fullname="J. Heitz" initials="J." surname="Heitz"/>
            <date month="September" year="2020"/>
            <abstract>
              <t>A BGP speaker may perform Resource Public Key Infrastructure (RPKI) origin validation on routes it receives. This document describes how it can use that validation state for routes it exports.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8893"/>
          <seriesInfo name="DOI" value="10.17487/RFC8893"/>
        </reference>
        <reference anchor="RFC9067" target="https://www.rfc-editor.org/info/rfc9067" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9067.xml">
          <front>
            <title>A YANG Data Model for Routing Policy Management</title>
            <author fullname="Y. Qu" initials="Y." surname="Qu"/>
            <author fullname="J. Tantsura" initials="J." surname="Tantsura"/>
            <author fullname="A. Lindem" initials="A." surname="Lindem"/>
            <author fullname="X. Liu" initials="X." surname="Liu"/>
            <date month="October" year="2021"/>
            <abstract>
              <t>This document defines a YANG data model for configuring and managing routing policies in a vendor-neutral way and providing a framework for defining common routing policy building blocks.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9067"/>
          <seriesInfo name="DOI" value="10.17487/RFC9067"/>
        </reference>
        <reference anchor="RFC9911" target="https://www.rfc-editor.org/info/rfc9911" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9911.xml">
          <front>
            <title>Common YANG Data Types</title>
            <author fullname="J. Schoenwaelder" initials="J." role="editor" surname="Schoenwaelder"/>
            <date month="December" year="2025"/>
            <abstract>
              <t>This document defines a collection of common data types to be used with the YANG data modeling language. This document obsoletes RFC 6991.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9911"/>
          <seriesInfo name="DOI" value="10.17487/RFC9911"/>
        </reference>
        <reference anchor="I-D.ietf-idr-bgp-model" target="https://datatracker.ietf.org/doc/html/draft-ietf-idr-bgp-model-21" xml:base="https://bib.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-idr-bgp-model.xml">
          <front>
            <title>YANG Model for Border Gateway Protocol (BGP-4)</title>
            <author fullname="Mahesh Jethanandani" initials="M." surname="Jethanandani">
              <organization>Kloud Services</organization>
            </author>
            <author fullname="Keyur Patel" initials="K." surname="Patel">
              <organization>Arrcus</organization>
            </author>
            <author fullname="Susan Hares" initials="S." surname="Hares">
              <organization>Huawei</organization>
            </author>
            <author fullname="Jeff Haas" initials="J." surname="Haas">
              <organization>HPE</organization>
            </author>
            <date day="14" month="August" year="2026"/>
            <abstract>
              <t>This document defines a YANG data model for configuring and managing BGP, including protocol, policy, and operational aspects, such as RIB, based on data center, carrier, and content provider operational requirements.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-idr-bgp-model-21"/>
        </reference>
        <reference anchor="I-D.ietf-sidrops-aspa-verification" target="https://datatracker.ietf.org/doc/html/draft-ietf-sidrops-aspa-verification-28" xml:base="https://bib.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-sidrops-aspa-verification.xml">
          <front>
            <title>BGP AS_PATH Verification Based on Autonomous System Provider Authorization (ASPA) Objects</title>
            <author fullname="Alexander Azimov" initials="A." surname="Azimov">
              <organization>Yandex</organization>
            </author>
            <author fullname="Eugene Bogomazov" initials="E." surname="Bogomazov">
              <organization>Qrator Labs</organization>
            </author>
            <author fullname="Randy Bush" initials="R." surname="Bush">
              <organization>Internet Initiative Japan &amp; Arrcus, Inc.</organization>
            </author>
            <author fullname="Keyur Patel" initials="K." surname="Patel">
              <organization>Arrcus</organization>
            </author>
            <author fullname="Job Snijders" initials="J." surname="Snijders">
              <organization>BSD Software Development</organization>
            </author>
            <author fullname="Kotikalapudi Sriram" initials="K." surname="Sriram">
              <organization>USA National Institute of Standards and Technology</organization>
            </author>
            <date day="24" month="August" year="2026"/>
            <abstract>
              <t>This document describes procedures that make use of Autonomous System Provider Authorization (ASPA) objects in the Resource Public Key Infrastructure (RPKI) to verify the Border Gateway Protocol (BGP) AS_PATH attribute of advertised routes. This AS_PATH verification enhances routing security by adding means to detect and mitigate route leaks and AS_PATH manipulations.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-sidrops-aspa-verification-28"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC4252" target="https://www.rfc-editor.org/info/rfc4252" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.4252.xml">
          <front>
            <title>The Secure Shell (SSH) Authentication Protocol</title>
            <author fullname="T. Ylonen" initials="T." surname="Ylonen"/>
            <author fullname="C. Lonvick" initials="C." role="editor" surname="Lonvick"/>
            <date month="January" year="2006"/>
            <abstract>
              <t>The Secure Shell Protocol (SSH) is a protocol for secure remote login and other secure network services over an insecure network. This document describes the SSH authentication protocol framework and public key, password, and host-based client authentication methods. Additional authentication methods are described in separate documents. The SSH authentication protocol runs on top of the SSH transport layer protocol and provides a single authenticated tunnel for the SSH connection protocol. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4252"/>
          <seriesInfo name="DOI" value="10.17487/RFC4252"/>
        </reference>
        <reference anchor="RFC6241" target="https://www.rfc-editor.org/info/rfc6241" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.6241.xml">
          <front>
            <title>Network Configuration Protocol (NETCONF)</title>
            <author fullname="R. Enns" initials="R." role="editor" surname="Enns"/>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <author fullname="J. Schoenwaelder" initials="J." role="editor" surname="Schoenwaelder"/>
            <author fullname="A. Bierman" initials="A." role="editor" surname="Bierman"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>The Network Configuration Protocol (NETCONF) defined in this document provides mechanisms to install, manipulate, and delete the configuration of network devices. It uses an Extensible Markup Language (XML)-based data encoding for the configuration data as well as the protocol messages. The NETCONF protocol operations are realized as remote procedure calls (RPCs). This document obsoletes RFC 4741. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6241"/>
          <seriesInfo name="DOI" value="10.17487/RFC6241"/>
        </reference>
        <reference anchor="RFC6810" target="https://www.rfc-editor.org/info/rfc6810" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.6810.xml">
          <front>
            <title>The Resource Public Key Infrastructure (RPKI) to Router Protocol</title>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <date month="January" year="2013"/>
            <abstract>
              <t>In order to verifiably validate the origin Autonomous Systems of BGP announcements, routers need a simple but reliable mechanism to receive Resource Public Key Infrastructure (RFC 6480) prefix origin data from a trusted cache. This document describes a protocol to deliver validated prefix origin data to routers. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6810"/>
          <seriesInfo name="DOI" value="10.17487/RFC6810"/>
        </reference>
        <reference anchor="RFC8040" target="https://www.rfc-editor.org/info/rfc8040" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8040.xml">
          <front>
            <title>RESTCONF Protocol</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <date month="January" year="2017"/>
            <abstract>
              <t>This document describes an HTTP-based protocol that provides a programmatic interface for accessing data defined in YANG, using the datastore concepts defined in the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8040"/>
          <seriesInfo name="DOI" value="10.17487/RFC8040"/>
        </reference>
        <reference anchor="RFC8210" target="https://www.rfc-editor.org/info/rfc8210" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8210.xml">
          <front>
            <title>The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1</title>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <date month="September" year="2017"/>
            <abstract>
              <t>In order to verifiably validate the origin Autonomous Systems and Autonomous System Paths of BGP announcements, routers need a simple but reliable mechanism to receive Resource Public Key Infrastructure (RFC 6480) prefix origin data and router keys from a trusted cache. This document describes a protocol to deliver them.</t>
              <t>This document describes version 1 of the RPKI-Router protocol. RFC 6810 describes version 0. This document updates RFC 6810.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8210"/>
          <seriesInfo name="DOI" value="10.17487/RFC8210"/>
        </reference>
        <reference anchor="RFC8340" target="https://www.rfc-editor.org/info/rfc8340" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8340.xml">
          <front>
            <title>YANG Tree Diagrams</title>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="L. Berger" initials="L." role="editor" surname="Berger"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>This document captures the current syntax used in YANG module tree diagrams. The purpose of this document is to provide a single location for this definition. This syntax may be updated from time to time based on the evolution of the YANG language.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="215"/>
          <seriesInfo name="RFC" value="8340"/>
          <seriesInfo name="DOI" value="10.17487/RFC8340"/>
        </reference>
        <reference anchor="RFC8635" target="https://www.rfc-editor.org/info/rfc8635" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8635.xml">
          <front>
            <title>Router Keying for BGPsec</title>
            <author fullname="R. Bush" initials="R." surname="Bush"/>
            <author fullname="S. Turner" initials="S." surname="Turner"/>
            <author fullname="K. Patel" initials="K." surname="Patel"/>
            <date month="August" year="2019"/>
            <abstract>
              <t>BGPsec-speaking routers are provisioned with private keys in order to sign BGPsec announcements. The corresponding public keys are published in the Global Resource Public Key Infrastructure (RPKI), enabling verification of BGPsec messages. This document describes two methods of generating the public-private key pairs: router-driven and operator-driven.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8635"/>
          <seriesInfo name="DOI" value="10.17487/RFC8635"/>
        </reference>
        <reference anchor="RFC9000" target="https://www.rfc-editor.org/info/rfc9000" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9000.xml">
          <front>
            <title>QUIC: A UDP-Based Multiplexed and Secure Transport</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="M. Thomson" initials="M." role="editor" surname="Thomson"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TLS for key negotiation, loss detection, and an exemplary congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9000"/>
          <seriesInfo name="DOI" value="10.17487/RFC9000"/>
        </reference>
        <reference anchor="RFC9846" target="https://www.rfc-editor.org/info/rfc9846" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9846.xml">
          <front>
            <title>The Transport Layer Security (TLS) Protocol Version 1.3</title>
            <author fullname="E." initials="E." surname="Rescorla"/>
            <date month="July" year="2026"/>
            <abstract>
              <t>This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery. This document obsoletes RFC 8446, which specified TLS 1.3. This document obsoletes RFC 5246 (specifying TLS 1.2) and RFCs 5077, 6961, 7627, and 8422, all of which pertain to TLS 1.2 or earlier, and updates RFCs 5705 and 6066. This document also specifies new requirements for TLS 1.2 implementations.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9846"/>
          <seriesInfo name="DOI" value="10.17487/RFC9846"/>
        </reference>
        <reference anchor="RFC9907" target="https://www.rfc-editor.org/info/rfc9907" xml:base="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9907.xml">
          <front>
            <title>Guidelines for Authors and Reviewers of Documents Containing YANG Data Models</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Boucadair" initials="M." role="editor" surname="Boucadair"/>
            <author fullname="Q. Wu" initials="Q." surname="Wu"/>
            <date month="March" year="2026"/>
            <abstract>
              <t>This document provides guidelines for authors and reviewers of specifications containing YANG data models, including IANA-maintained YANG modules. Recommendations and procedures are defined, which are intended to increase interoperability and usability of Network Configuration Protocol (NETCONF) and RESTCONF protocol implementations that utilize YANG modules.</t>
              <t>This document obsoletes RFC 8407; it also updates RFC 8126 by providing additional guidelines for writing the IANA considerations for RFCs that specify IANA-maintained YANG modules.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="216"/>
          <seriesInfo name="RFC" value="9907"/>
          <seriesInfo name="DOI" value="10.17487/RFC9907"/>
        </reference>
        <reference anchor="I-D.ietf-sidrops-8210bis" target="https://datatracker.ietf.org/doc/html/draft-ietf-sidrops-8210bis-27" xml:base="https://bib.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-sidrops-8210bis.xml">
          <front>
            <title>The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 2</title>
            <author fullname="Randy Bush" initials="R." surname="Bush">
              <organization>Arrcus, DRL, &amp; IIJ Research</organization>
            </author>
            <author fullname="Rob Austein" initials="R." surname="Austein">
              <organization>Dragon Research Labs</organization>
            </author>
            <author fullname="Tom Harrison" initials="T." surname="Harrison">
              <organization>Asia Pacific Network Information Centre</organization>
            </author>
            <date day="13" month="August" year="2026"/>
            <abstract>
              <t>In order to validate the origin Autonomous Systems (ASes) and Autonomous System relationships behind BGP announcements, routers need a simple but reliable mechanism to receive Resource Public Key Infrastructure (RFC6480) prefix origin data, Router Keys, and ASPA data from a trusted cache. This document describes a protocol to deliver them. This document describes version 2 of the RPKI-Router protocol. [RFC6810] describes version 0, and [RFC8210] describes version 1. This document is compatible with both.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-sidrops-8210bis-27"/>
        </reference>
      </references>
    </references>
    <section anchor="contributors" numbered="false" toc="include" removeInRFC="false">
      <name>Contributors</name>
      <contact fullname="Jeffrey Haas">
        <organization>Juniper Networks, Inc.</organization>
        <address>
          <postal>
            <street>1133 Innovation Way</street>
            <region>Sunnyvale, CA 94089</region>
            <country>United States of America</country>
          </postal>
          <email>jhaas@juniper.net</email>
        </address>
      </contact>
      <contact fullname="Hongwei Liu">
        <organization>ZTE Corporation</organization>
        <address>
          <postal>
            <country>China</country>
          </postal>
          <email>liu.hongwei3@zte.com.cn</email>
        </address>
      </contact>
      <contact fullname="Mengxiao Chen">
        <organization>H3C</organization>
        <address>
          <postal>
            <country>China</country>
          </postal>
          <email>chen.mengxiao@h3c.com</email>
        </address>
      </contact>
    </section>
  </back>

</rfc>
