Re: Proposal: A standard EPP OT&E test suite for each object type and extension type

Patrick Mevzek <[email protected]>
Newsgroups gmane.ietf.provreg
Organization Dot And Co
Message-ID <[email protected]>
Hello Keith,

Keith Gaughan <[email protected]> 2011-06-16 18:26
> This is the first in a series of suggestions from a registrar's point of view
> improvements that can be made to and around EPP to make the life of registrars
> easier. Consider them food for thought if nothing else.
 
At least personnally I welcome your initiative and wish that other
registrars participate here and do the same.

> A standard EPP test suite from OT&E would, I think, serve two important
> purposes. Firstly, it would be an immense help to registrar who are
> developing their domain management systems for the first time as not all of
> us use Net::DRI for Perl or EPP-RTK for Java and C++. Ours, for instance, is
> written in a combination of Python and PHP. Secondly, it would mean that
> registrars would only need to run through the test suite *once*, which would
> greatly reduce the management overhead for both registrars and registries
> during accreditation. A central registry, likely maintained by ICANN, listing
> whether a registrar has successfully completed a particular part of the test
> suite, would also be useful.
 
I'm not sure this suits ICANN mandate or role. I even fear it would
complicate the system.

However, I also agree with Klaus and Wil: current accreditation tests
are *worthless* and I would say even *dangerous*.

They mandate to do things specifically forbidden in EPP (such as
syntax of some elements outside accepted values), and seem to concentrate in detail with some
arcane parts that almost never appear in production.

Obviously, not all registry certification tests are equal, some are more
worthless than others :-)

End results (and it's not an hypothesis, I have direct personal proof
of that): registrars build (or buy) a quick custom script that send to
the registries the rubbish they wait for, and pass the accreditation
test without problems. It has no bearing on what they will really use in production,
meaning it would be something completely different. So the tests in
that case do not verify anything... except maybe the registry own
systems :-)

There are also some registries that also accepts tests even if
not 100% passed.

So I'm not against certification tests per se, as I believe they could
fulfill an useful role of making sure that registrars technical team
EPP knowledge level is raised up an acceptable level, before having it
in production, and through the support channel. Again, as a personal
direct observation, many calls to registry support people are tied
with some very basic questions such as "how to do a connection from
language X" (when X is not included in registries SDK) or "how to
setup my SSL certificate".

But technical tests as they are done today are a burden without actual
benefits.
Back in ICANN 2010 Brussels, I've proposed the idea of having a
cross-registry EPP test suite
(
http://www.dotandco.com/services/software/Net-DRI/docs/netdri-future-epp-icann-brussels-ccnso-techday-201006/index.html#slide19
)
that could be done in such a way that it works for both directions,
and may also solve part of the problem raised here by Keith in another
thread, such as the registry policies for various operations.
And following Jim's idea there, it could be done as a BCP.

What also seems to me more important is mandating the registries to have a
working OT&E system well used during upgrades with enough advance
warnings and documentations on new/changed extensions.

I would also suppose that the first registrars of the new gTLDs will
be current registrars, meaning they obviously already have a working
EPP implementation. Forcing them to pass new certification tests would
be a loss of time, except if they are limited to each registry
specific parts and new extensions.

-- 
Patrick Mevzek
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.