Re: Example of stupid inconsistencies between registries

Michael Young <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
Nice turn Andrew, reminds that you have a background in logic :-)

However I would say the dnskey belongs to the subordinate zone and the DS is an artifact of that key - making them responsible, not the registry. Having a bad DS in the registry breaks the  validation path but then so does have the wrong delegated nameservers. The registry IMHO authenticates the party authorized to make changes regarding a registration, not determine if the registrant set their related DNS data right ( and yes I know that there are ccTLDs that prevent registration if this isn't right.) I think monitoring, testing and notifying registrars of mistakes is great and everyone should do it.  But ultimately if they get it wrong it's their zone that breaks, not the TLDs hence why it's their job,......






Michael Young

M:647-289-1220

On 2012-03-08, at 1:17 PM, Andrew Sullivan <[email protected]> wrote:

> On Thu, Mar 08, 2012 at 12:50:40PM -0500, Michael Young wrote:
>> argue about what those responsibilities really should be, but I think it
>> starts and ends with what they can control.    
> 
> If that's your position, then you must agree that they should require
> the DNSKEY and generate the DS themselves, because the DS is data for
> which they are authoritative.
> 
> Best,
> 
> A
> 
> -- 
> Andrew Sullivan
> [email protected]
> _______________________________________________
> provreg mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/provreg
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.