Re: DNSSEC EPP Extension (RFC 4310) Usability Question

Patrik Fältström <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On 12 dec 2008, at 10.23, Klaus Malorny wrote:

> Shouldn't the name server operator get a separate out-of-the-band  
> channel to the registry operator to submit the DS data directly, for  
> example with a subset of RFC 4931/RFC 4310? Any comments on this?

My immediate reaction is "no". There is the same attack vector as  
changes in NS records or glue. I think the DS data should definitely  
follow the same path as other domain related data.

That said, the registry can easily do some checks and balances  
calculation when the data arrive -- before the zone is published. Just  
like they can check glue, that servers are auth etc, they can also  
check the KSK in the child zone that it matches the DS passed to them.

    Patrik
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.