BGP picking a best path doesn't mean the origin AS is authorized — read RPKI origin validation as code and see why valid, invalid, and not_found are three distinct answers.

BGP picking a best path doesn't mean the origin AS is authorized — read RPKI origin validation as code and see why valid, invalid, and not_found are three distinct answers.

RPKI tells you a route is invalid — it does not tell the router to drop it. Read the BGP policy layer as code and see why validation and policy are separate.