If you are using APNIC as an RPKI trust anchor, please update your Trust Anchor Set.

APNIC will be switching to a new RPKI 'split' trust anchor system on
the 25th of October. This change is needed to align APNIC administered
resources with their allocation hierarchy. These resources will also
be certified under each responsible parent registry at the appropriate
time.
...
If you have any questions please contact me.

ok. i'll bite. what the heck is this meant to support? i thought the
rirs were moving from five TALs to one.

randy, very confused

Randy, we have an operational need to separate the existing single TAL
into its discrete components for each source, so we can have production
certificates for each source, so that we can ultimately have them signed
under their appropriate parent registry,

Once there is a global trust anchor, you can validate the 5 APNIC operating
CA under a single root, single TAL. Until then, an APNIC TAL is necessary.

-George

George,

No David, no implication was intended that this is due to inaction on the part of ICANN.

Sometimes, these things just take time.

cheers

-George

ok. i'll bite. what the heck is this meant to support? i thought the
rirs were moving from five TALs to one.

Randy, we have an operational need to separate the existing single TAL
into its discrete components for each source, so we can have production
certificates for each source, so that we can ultimately have them signed
under their appropriate parent registry,

ok, i'll give. what are the five 'sources'?

randy

Perhaps the following?

AfriNIC
ARIN
APNIC
LACNIC
RIPE

Regards,

Jay