Re: Example of stupid inconsistencies between registries

Howard Eland <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On Mar 8, 2012, at 10:58 AM, Patrik Fältström wrote:

>> I don't understand how the DNSKEY would be worse for the registrant than the DS given that
>> the DNSKEY is what they already have in their hands.
> 
> Correct, we could as well have always passed the DNSKEY to the registry. The problem is not even that some registries ask for DS, some for DNSKEY, but that some refuse to accept DS (in my case). It could, as you say, also have been that some refuse to accept DNSKEY.

Ah, but this gets back to registry policy.  Earlier in this thread, someone had mentioned that protocol should not (as far as possible) dictate policy.  Because the ultimate party responsible for the DS RR is the parent, they should have the flexibility to set policy on how they want to generate this record - either have it handed to them, or to generate it themselves.  As I've stated earlier, both have valid points, so the protocol was written to allow either.

> 
> To repeat, I have encountered a number of registries accepting DS (they might accept DNSKEY as well) and now suddenly one that only accept DNSKEY and not DS.

... and this sounds like a poor (or non-existant) transition plan, not a fault of the protocol.

> 
> I felt that was a situation complicated enough for the registrar (me) and the registrant (our customers) that I wanted to discuss the situation on this list.
> 
> Which I thank you all for the ability to do. It has been a good conversation.

Indeed it has.  

-Howard
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.