Re: contact:disclose clarifications / best practices

"Hollenbeck, Scott" <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <831693C2CDA2E849A7D7A712B24E257F0D6F238F@BRN1WNEXMBX01.vcorp.ad.vrsn.com>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On
> Behalf Of Keith Gaughan
> Sent: Wednesday, January 23, 2013 9:35 AM
> To: Bernhard Reutner-Fischer
> Cc: [email protected]
> Subject: Re: [provreg] contact:disclose clarifications / best practices
> 
> On Wed, Jan 23, 2013 at 03:21:48PM +0100, Bernhard Reutner-Fischer
> wrote:
> 
> > On 23 January 2013 13:28, Hollenbeck, Scott
> <[email protected]> wrote:
> > >> -----Original Message-----
> > >> From: [email protected] [mailto:[email protected]]
> On
> > >> Behalf Of Keith Gaughan
> > >> Sent: Wednesday, January 23, 2013 7:21 AM
> > >> To: Bernhard Reutner-Fischer
> > >> Cc: [email protected]
> > >> Subject: Re: [provreg] contact:disclose clarifications / best
> > >> practices
> > >>
> > >> On Wed, Jan 23, 2013 at 11:26:31AM +0100, Bernhard Reutner-Fischer
> > >> wrote:
> > >>
> > >> > I have questions about contact:disclose.
> > >
> > > [snip]
> > >
> > >> I think the disclosure fields deal more with the likes of what's
> > >> published in WHOIS and the likes.
> > >
> > > Yes, that use case certainly applies. I've always thought of it as
> > > an indication of registrant disclosure preference in the context of
> > > registry operator policy. There is thus no single answer to what
> > > gets returned because privacy policies will vary from operator to
> operator.
> >
> > So you consider any registrar that is not sponsor of that contact to
> > not be third party, is that right?
> 
> If they have the authorisation code for a linked domain, they
> implicitly have authorisation for querying the contact in question, so
> while they might be a third party, they're a third party who's
> authorised to access the information in question.
> 
> > In other words: The disclose flag is completely ignored for every
> > contact:info command from any registrar. It is solely used to
> > determine if the affected contact-data is handed out to entities
> > outside of the registry, like public whois-service.
> 
> Lets say that the registry allowed <contact:info> for any contact
> object, regardless of whether they owned it or not. If it was queried
> by a registrar who didn't own it without the authorisation code or the
> authorisation code of a linked object, the disclosure policy would
> apply.
> 
> Registrars need to get this periodic raised access to deal with
> transfers.

Right. This is a different use case. The registrant makes an informed decision to provide the authInfo to a new registrar so that they can act as their agent to implement a transfer.

Scott
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.