Re: Example of stupid inconsistencies between registries
Patrik Fältström <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On 8 mar 2012, at 07:35, Jay Daley wrote: > On 8/03/2012, at 7:02 PM, Patrik Fältström wrote: > >>> To explain what I mean, here's a simple idea - could the protocol have been designed to better minimise pain for registrars while maintaining the choice for registries? >> >> I think this is a case that creates a problem for the _registrant_. > > How? Because compared to other discussions we have, this implies the registrant (or, more correctly, the DNS hosting provider) have to do completely different actions depending on the policy of the TLD. >> So the DS should be enough. Everything else is bonus. Or am I completely confused before enough coffee here in the morning? > > You are assuming a particular sequence of provisioning (i.e. that there are published DNSKEY records when the DS is received). Many registries make no assumptions and so don't expect to contact delegated nameservers during the provisioning process. Correct, just like many registries already today require delegations to be made before registration can be done. I.e. some registries do not allow registration without delegation. My point is that without delegation, sending KEY does not make any sense. It is when delegating the dnssec data is needed and because of that the KEY can be fetched at time of delegation. Patrik _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg