RIPE NCC Account Registration and Database Setup Guide
Last updated: July 2026
Audience: Customers who have purchased ASN sponsorship services from SKNK (Shikanoko Networks). SKNK submits the ASN request to RIPE NCC on your behalf and assigns an IPv6 PA /48 from SKNK's LIR allocation. This document covers the parts you need to do yourself: registering a RIPE NCC Access account, creating RIPE Database objects, and the necessary setup after receiving your resources.
Disclaimer: This guide is provided for informational purposes only and does not constitute legal or professional advice. RIPE NCC policies, procedures, and interface designs may change at any time — always refer to the official RIPE NCC documentation for the most current information. Shikanoko Networks is not liable for any issues arising from the use of this guide. SKNK is an independent RIPE NCC LIR member and is not affiliated with or endorsed by RIPE NCC. RIPE NCC is a trademark of RIPE NCC.
1. Prerequisites
Before you begin, make sure you have the following ready:
| Item | Description |
|---|---|
| Registration documents | Verifiable registration documents for the applying organisation or registered sole trader. SKNK's standard service does not accept unregistered individuals. |
| Evidence supporting the network need | Information or documents showing a policy-compliant ASN need connected to the RIPE NCC service region. The exact evidence depends on the case. |
| Planned upstream or peering information | The networks you expect to connect or peer with. SKNK reviews whether the information is sufficient and may request clarification. |
| Contact email | Used for RIPE NCC Access registration and RIPE Database contacts. Important: This email will receive verification messages, so be sure to use a real, accessible address. |
| Postal address | The applicant's verifiable registered or business address. |
2. Registering RIPE NCC Access Account
RIPE NCC Access is your unified portal for managing RIPE resources. All RIPE services require this account to log in.
- Navigate to https://access.ripe.net/registration
- Enter your email address and set a password
- Two-Factor Authentication (2FA) is mandatory -- RIPE NCC now requires it
- Complete registration after verifying your email
⚠️ Keep your RIPE NCC Access account credentials safe. You will need it to log in for all subsequent RIPE Database operations.
3. Creating Role and Maintainer Objects
This is the most critical step. In the RIPE Database, a contact object (role or person) represents your contact information, and a maintainer (mntner) object controls who can modify your database records. These two objects must be created together, because they reference each other.
💡 Contact objects: A registered organisation or sole trader may use a person object for an individual technical contact or a role object for a function such as a NOC. This choice does not change SKNK's applicant-eligibility rules. The steps below use a role as an example.
3.1 Creating role + mntner Together
Open the following link: 👉 https://apps.db.ripe.net/db-web-ui/webupdates/create/RIPE/role/self
Fill in the following fields:
| Field | Description | Example |
|---|---|---|
mntner |
Maintainer identifier. May only contain letters (A-Z, a-z), digits, _- |
YOURNAME-MNT |
role |
Role object name. If using person, enter your full name | YOURNAME NOC or John Doe |
address |
Your postal address (can be multi-line) | 128 City Road, London, UK |
e-mail |
Your contact email | noc@example.com |
phone |
Phone number (person object has this field; role does not) | +44 20 1234 5678 |
Click SUBMIT once done.
📌 Important: After successful submission, the page will display
role with primary key "XXXX-RIPE". Make a note of this value (e.g.,AB1234-RIPE) -- you will need to submit it to SKNK later. Also note your mntner name. Until the ASN is allocated, you will not be able to find these objects by searching the RIPE Database, so keep them on record yourself.
3.2 Understanding the Relationship Between role/person and mntner
- The
mntnerobject protects other objects via themnt-byattribute -- any modification to an object requires maintainer authentication. - The
role/personobject is linked to the maintainer via theadmin-cattribute, providing administrator contact information. - They reference each other: the mntner's
admin-cpoints to the role, and the role'smnt-bypoints to the mntner. This is why they must be created together.
4. Setting Up Abuse Notification Mailbox
RIPE NCC requires every organisation object to be associated with a contact object that has an abuse-mailbox attribute.
Quick method (recommended): When creating your organisation in the next step, click the 🔔 bell icon next to the abuse-c field. The system will automatically create a role object with abuse-mailbox and populate it for you. Done in one click.
Manual method (if you have already created the organisation or prefer to manage it manually): Add the abuse notification mailbox to the role you created in Step 3.
- Open https://apps.db.ripe.net/db-web-ui/query
- Enter the role primary key from Step 3 (e.g.,
AB1234-RIPE) in the search box and click search - Click Update object in the top-right corner of the search results
- Click the + sign next to the
e-mailfield and add theabuse-mailboxattribute - Enter your abuse notification email (can be the same as your contact email)
- Click SUBMIT to save
⚠️ RIPE NCC will verify that this mailbox is valid, so please ensure it is real and accessible. The abuse notification mailbox is used to receive network abuse complaints -- hopefully you will never need it, but it is mandatory.
5. Creating Organisation Object
The organisation object represents the legally registered applicant, and the ASN is associated with this object.
- Open https://apps.db.ripe.net/db-web-ui/webupdates/create/RIPE/organisation
- Fill in the following fields:
| Field | Description | Example |
|---|---|---|
mnt-by |
Who manages this object. Auto-filled with the mntner from Step 3 | YOURNAME-MNT (auto-filled) |
organisation |
Defaults to AUTO-1. The system will generate an identifier automatically |
Leave blank |
org-name |
Full registered name of the organisation or sole trader | YOUR COMPANY LLC |
address |
Registered address | 128 City Road, London, UK |
e-mail |
Contact email | noc@example.com |
abuse-c |
Abuse contact. Click the 🔔 bell icon on the right to create one automatically | System auto-generates from your email |
mnt-ref |
Who may reference this organisation. At minimum, include your own mntner + SKNK's mntner (SKNK will provide theirs) | YOURNAME-MNT, lir-uk-shikanoko-1-MNT |
- Click SUBMIT
📌 After successful submission, the page will display
organisation "ORG-XXXX-RIPE". Make a note of this value and submit it to SKNK later.
6. Submitting Information to SKNK
After completing the steps above, you need to submit the following information to SKNK (via the order system or email):
| Item | Where to get it |
|---|---|
org |
Organisation identifier from Step 5 (e.g., ORG-XX1-RIPE) |
admin-c |
Role primary key from Step 3 (e.g., AB1234-RIPE) |
tech-c |
Can be the same as admin-c, or create a dedicated role |
abuse-c |
Role primary key with abuse-mailbox set up in Step 4 |
mnt-by |
Mntner identifier from Step 3 (e.g., YOURNAME-MNT) |
as-name |
Desired AS name (e.g., YOURCOMPANY-AS) |
| Registration and identity documents | For applicant verification |
| Evidence supporting the network need | Case-appropriate network, upstream, or peering information |
Once submitted, SKNK will use this information to file an ASN request with RIPE NCC. RIPE NCC reviews each request independently, and timing varies with the case and any follow-up questions.
7. Creating route6 Object After Receiving ASN
When SKNK notifies you that your ASN and IPv6 prefix are ready, check whether your upstream requires a route6 object to bind the prefix to your ASN. IRR requirements vary by upstream. SKNK does not provide IRR management, so creating and maintaining any required route object is your responsibility and depends on the applicable maintainer authorization.
- Log in to RIPE Database
- Select Create an Object
- Choose route6 as the object type
- Fill in:
| Field | Description | Example |
|---|---|---|
route6 |
Your IPv6 prefix | 2001:db8:abcd::/48 |
origin |
Your ASN | AS215000 |
mnt-by |
Your mntner | YOURNAME-MNT |
- Click SUBMIT
After successful creation, view your IPv6 resource in the RIPE Database. You will see a green IRR badge next to it, indicating that route registration was successful.
💡 If you have multiple IPv6 prefixes, each one needs its own
route6object.
8. Setting Up RPKI / ROA
RPKI (Resource Public Key Infrastructure) uses ROAs (Route Origin Authorizations) to cryptographically verify that your IP prefix genuinely belongs to your ASN. Without a ROA, your routes are vulnerable to hijacking, and some upstream providers will reject unverified route announcements.
8.1 RPKI Setup for PA Prefixes
Because the IPv6 PA /48 comes from Provider Aggregatable address space held by SKNK's LIR, RPKI authority for that resource is controlled by SKNK. SKNK creates, maintains, and withdraws the corresponding ROA. You have the right to use the prefix but do not directly hold its RIPE NCC resource certificate, so you cannot independently manage the PA prefix's ROA in the RIPE NCC Portal.
What you need to do: Contact SKNK (via email or order system) and specify:
Please add a ROA for
2001:db8:abcd::/48with originAS215000and maxLength/48.
SKNK will create the ROA for you. After it is created, you can verify the RPKI status on RIPEstat.
8.2 The Role of ROA maxLength (Important)
The maxLength in a ROA determines the smallest sub-prefix you are allowed to announce. Incorrect settings will cause routes to be rejected.
Example: Your prefix is 2001:db8:f0::/44, and the ROA sets maxLength to /46:
| Prefix you announce | Result | Reason |
|---|---|---|
2001:db8:f0::/44 |
✅ Accepted | Within allowed range |
2001:db8:fa::/46 |
✅ Accepted | Equal to maxLength, allowed |
2001:db8:f3::/48 |
❌ Rejected | /48 is more specific than maxLength /46, sub-prefixes narrower than maxLength are not allowed |
2001:db8:f8::/48 |
❌ Rejected | Same as above |
💡 Simple rule: If you have a single /48 prefix, set maxLength to
/48. Do not set it to/32or/0-- that would allow anyone to announce any subset of your prefix using any ASN.
8.3 RPKI vs IRR route6 Objects
- RPKI ROA uses cryptographic verification and takes highest priority. When a ROA is present, a mismatched route6 object can still pass validation (RPKI takes precedence).
- route6 objects (IRR) are the older generation of validation. Some legacy networks still use IRR filtering only, without RPKI.
SKNK creates the ROA for its PA /48. You should create and maintain an IRR route6 object only where your upstream or routing policy requires it; IRR management is not included in the SKNK service.
8.4 If You Need Independent Address Resources
SKNK's standard package provides an IPv6 PA /48, so SKNK must manage its ROA. IPv6 PI is a separate independent-resource request with different eligibility, agreement, fees, and RPKI operating arrangements; it is not an upgrade that preserves the same PA addresses. If independent addressing is a requirement, assess PI with a sponsoring LIR before ordering the PA service.
9. Creating AS-SET (Optional but Recommended)
An as-set object groups your ASNs together. Upstream providers and IXPs use it to generate prefix filters. If you plan to peer with multiple networks, creating one is recommended.
- In the RIPE Database, select Create an Object
- Choose as-set as the object type
- Fill in:
| Field | Description | Example |
|---|---|---|
as-set |
AS-SET name. Must begin with AS- |
AS-YOURNAME |
descr |
Short description | Your Company AS-SET |
members |
Your ASN | AS215000 |
tech-c |
Technical contact role primary key | AB1234-RIPE |
admin-c |
Administrative contact role primary key | AB1234-RIPE |
mnt-by |
Your mntner | YOURNAME-MNT |
- Click SUBMIT
10. Frequently Asked Questions
Q: I am an individual, not a company. Can I still apply?
RIPE NCC resource processes may accept natural persons in some cases, but SKNK's standard service currently accepts legally registered organisations and registered sole traders that can provide verifiable registration documents. Contact SKNK before ordering if you do not have a registered business.
Q: The relationship between role/mntner/org in the RIPE Database is too complicated. What should I do?
Here is a simple way to think about it:
- organisation = your identity (who owns these resources)
- role = your contact information (who to contact when something goes wrong)
- mntner = your key (only you can modify your own objects)
Q: I keep getting authentication errors when creating objects?
Make sure you are logged in to RIPE NCC Access. Use the dedicated link provided above for creating role + mntner -- it handles initial authentication automatically.
Q: Forgot mntner password / lost access?
Use RIPE NCC's mntner recovery tool. You will need to log in with your RIPE NCC Access account to verify your identity.
Q: Is my IPv6 prefix PA or PI?
SKNK provides an IPv6 PA (Provider Aggregatable) /48 from its LIR allocation. It can be announced when your upstream accepts it, but RIPE NCC does not guarantee global routability. It is not functionally or contractually identical to PI: the PA prefix depends on SKNK, its ROA is managed by SKNK, and service termination normally requires withdrawal and renumbering.
Q: How do I start running BGP after receiving my ASN?
You need to:
- Confirm that SKNK's ROA matches your origin ASN and complete any IRR setup required by your upstream
- Install a BGP daemon on your VPS or server (BIRD 2 or FRRouting recommended)
- Contact your upstream providers for BGP session configuration parameters
- Configure and establish BGP peering
SKNK does not provide BGP configuration support, but plenty of tutorials are available online.
Q: Can I switch LIR?
ASN and IPv6 need to be considered separately:
- ASN: The ASN is an independent resource assigned to your organisation. You can generally keep it when changing sponsoring LIR after signing a new agreement and completing RIPE NCC's contractual relationship change process; this is not a transfer of ownership to another organisation.
- IPv6 PA prefix: No, it cannot be taken with you. PA prefixes are allocated from SKNK's LIR resources and belong to SKNK, not your ORG. After switching LIR, the new LIR will need to allocate a new prefix.
- If you need a portable IPv6 prefix, assess a separate PI (Provider Independent) request before ordering. It is not an automatic conversion of the existing PA addresses.
Appendix A: PA vs PI Comparison
SKNK's standard package provides PA (Provider Aggregatable) space. PI (Provider Independent) is a separate resource request, not an upgrade of the same prefix.
| PA (SKNK standard service) | PI (separate request) | |
|---|---|---|
| Prefix ownership | Registered under SKNK's LIR | Allocated directly to your ORG |
| Routing | Subject to upstream acceptance and route policy | Subject to upstream acceptance and route policy |
| Portability | Does not move to another sponsor; renumbering normally required | Designed as an independent end-user assignment, subject to its sponsoring agreement |
| RPKI management | Managed by SKNK | Confirm the exact CA/ROA operating model with the PI sponsoring LIR |
| Use case | Projects that accept sponsor dependency and PA lifecycle | End-user infrastructure that requires independent addressing |
Verify Your Live Routing Data
After publishing a ROA or route object, verify the public result rather than relying only on the portal confirmation:
- RPKI & BGP Status Lookup — confirm origin authorization, maxLength, route visibility, and observed paths.
- IRR Route Object Lookup — confirm the exact
routeorroute6object exists in RIPE Database. - BGP & IRR Consistency Audit — find BGP announcements that do not match public IRR records.
- Reverse DNS Consistency Check — check reverse-DNS delegation coverage for an allocated prefix.
Last updated: July 2026
Questions? Contact SKNK: admin@shikanoko-networks.com