pkg.soopen package index

brew / rank 7147

Install rpki-client with Homebrew, apk, apt, dnf, MacPorts

OpenBSD portable rpki-client. Version 9.9 via Homebrew; verified 2026-09-12. Also installable with debian: sudo apt install rpki-client.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install rpki-client

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install rpki-client

MacPorts ports tree · net/rpki-client/Portfile · source: api.github.com

Linux

Alpine Linux apkverified · 92%
sudo apk add rpki-client

Alpine Linux edge package indexes · rpki-client · source: dl-cdn.alpinelinux.org

Debian aptverified · 92%
sudo apt install rpki-client

Debian stable package indexes · rpki-client · source: deb.debian.org

Fedora dnfverified · 92%
sudo dnf install rpki-client

Fedora Rawhide package metadata · rpki-client · source: dl.fedoraproject.org

overview

Package summary

OpenBSD portable rpki-client

Commands and aliases

  • rpki-client

history

Project history and usage

rpki-client is OpenBSD's relying-party validator for the Resource Public Key Infrastructure, used to validate RPKI repositories and produce routing-security payloads for BGP software.

Project history

rpki-client was developed within the OpenBSD Project by Kristaps Dzonsons, Claudio Jeker, Job Snijders, Theo de Raadt, Sebastian Benoit, and Theo Buehler. A separately maintained portable framework, modeled in part on OpenSSH and LibreSSL portability work, adapts the OpenBSD code for other Unix-like systems.

Adoption history

rpki-client ships as an OpenBSD base component on the project's six-month release cadence. Its portable build framework brought it to FreeBSD, Linux, and macOS, and official installation material notes packages for Alpine, Debian, Ubuntu, Fedora, FreeBSD, MacPorts, and Homebrew.

How it is used

Operators run rpki-client to synchronize RPKI repositories over RRDP, HTTPS, and rsync, validate certificates and signed objects, and emit VRPs, BGPsec router keys, and ASPA payloads. Outputs are available for OpenBGPD, BIRD, CSV, JSON, and metrics consumers; offline and individual-object inspection modes support operations and debugging.

Why package nerds care

rpki-client packages Internet routing-security machinery as a focused Unix utility with conservative parsing and privilege separation inherited from OpenBSD. Network operators value its direct production of OpenBGPD and BIRD configuration data, while package maintainers care about its portable compatibility layer and security-sensitive dependency stack.

Timeline

  • 2019–2020 era: rpki-client emerges as an OpenBSD RPKI validator and portable project.
  • Subsequent OpenBSD releases: It ships as a base-system component on a six-month cadence.
  • 2020s: Portable releases broaden support to FreeBSD, Linux, and macOS.
  • 2026: Portable release 9.8 continues validation, compatibility, and security hardening.

Related projects

  • OpenBGPD and BIRD consume its validated routing payloads. The portable framework borrows approaches from OpenSSH and LibreSSL and supports OpenSSL or LibreSSL-derived cryptographic libraries, libtls, Expat, and zlib.

Sources

  • Official manual: https://man.openbsd.org/rpki-client
  • Official portable repository: https://github.com/rpki-client/rpki-client-portable
  • Official portable-release page: https://www.rpki-client.org/portable.html
  • Official project site: https://www.rpki-client.org/

security posture

Risk level: blue

broad file, network, media, or database tool signal.

Risk classifier

blue risk · medium confidence · tool

Why

  • broad file, network, media, or database tool signal

Signals

  • text:client

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 3 runtime dependencies.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
/etc/rpki/*.tal/etc/rpki/*.constraints/etc/rpki/skiplist

executables

Installed executables

CommandKindExposureNote
rpki-clientcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version9.9
manager updated2026-09-12
local dataok
upstreamnot checked
latest detectednot detected

https://www.rpki-client.org/

install metadata

Package metadata

Package keybrew:rpki-client
Version9.9
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/rpki-client
Homepagehttps://www.rpki-client.org/
Upstream docshttps://www.rpki-client.org/
LicenseISC
Source archivehttps://ftp.openbsd.org/pub/OpenBSD/rpki-client/rpki-client-9.9.tar.gz
Last updated2026-09-12T11:09:02Z
Pulseupdated
Dependencieslibretls, openssl@3, rsync
Build dependenciespkgconf
Uses from macOSexpat
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namerpki-client
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Debian apt95%

rpki-client 9.5-1

OpenBSD RPKI validator

https://rpki-client.org/

sudo apt install rpki-client
  • Section: net
  • Architecture: amd64
  • 10 dependencies
  • normalized package name match
  • Matched by: Rpki Client
Debian stable package indexes · deb.debian.org · Debian stable package indexes: rpki-client from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Ubuntu apt95%

rpki-client 9.0-1build3

OpenBSD RPKI validator

https://rpki-client.org/

sudo apt install rpki-client
  • Section: universe/net
  • Architecture: amd64
  • 11 dependencies
  • normalized package name match
  • Matched by: Rpki Client
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: rpki-client from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
apk95%

rpki-client 9.9-r0

RPKI validator to support BGP Origin Validation

https://www.rpki-client.org/

sudo apk add rpki-client
  • License: ISC
  • Architecture: x86_64
  • Source Package: rpki-client
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Rpki Client
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: rpki-client from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

rpki-client-doc 9.9-r0

RPKI validator to support BGP Origin Validation (documentation)

https://www.rpki-client.org/

sudo apk add rpki-client-doc
  • License: ISC
  • Architecture: x86_64
  • Source Package: rpki-client
  • normalized package name match
  • Matched by: Rpki Client
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: rpki-client-doc from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
dnf95%

rpki-client 9.9-1.fc46

OpenBSD RPKI validator to support BGP Origin Validation

https://www.rpki-client.org/

sudo dnf install rpki-client
  • License: ISC AND BSD-2-Clause AND BSD-3-Clause AND OpenSSL AND LicenseRef-Fedora-Public-Domain
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: rpki-client
  • 11 dependencies
  • 3 provides
  • normalized package name match
  • Matched by: Rpki Client
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: rpki-client from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/652278618dec9c023176a80c435a32a2c8154869fb0eb662c267a54df28d77d9-primary.xml.zst
MacPorts95%

rpki-client

sudo port install rpki-client
  • normalized package name match
  • Matched by: Rpki Client
MacPorts ports tree · api.github.com · MacPorts ports tree: net/rpki-client/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation