Re: Fwd: New Version Notification for draft-gieben-epp-keyrelay-00.txt
Klaus Malorny <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On 24/01/13 09:21, Antoin Verschuren wrote:
> Hi all,
>
> This draft may be of interest to this list.
> At SIDN, we have documented how we intend to implement secure
> transfers of DNSSEC domains and this draft is to describe the EPP
> command we're going to use for that so it may be standardized.
> Comments are welcome to the authors or on this list.
>
Hi,
interesting draft. On the first glance, I'd like to note the following:
1. why is the use of the authinfo only optional? Isn't it better
to make it mandatory and reject the submission if the authinfo
is incorrect? In this case, the poll message does not need to
contain the authinfo.
2. The current registrar does not know from which registrar the
key data is coming. In case of problems, he is unable to contact
the respective registrar. Also, he is unable to determine whether
the keys come from different sources and need either to be
combined or replaced.
3. How long shall the current registrar/name server operator add the
DNSKEYs to the respective zone? If, for example, the registrant
changes his mind and does no longer want the new registrar to
transfer the domain to him, or wants to choose a different
registrar, there is no way to indicate this. Alternatively,
this could be solved by some kind of automatic timeout, i.e.
if the the <keyrelay> operation is not repeated periodically,
the current registrar shall remove the keys from the zone.
If this period is not part of the registry policy, maybe
the <keyrelay> command should contain a point in time until
which the keys shall be added. If the (potentially) gaining
registrar determines to need more time for whatever reason,
he can submit another <keyrelay> command with the same keys,
but a later date. Of course, the current registrar (or registry?)
should check the time for reasonable limits.
Regards,
Klaus
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg