Re: Fwd: New Version Notification for draft-gieben-epp-keyrelay-00.txt

Klaus Malorny <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On 24/01/13 17:44, Antoin Verschuren wrote:
> Op 24-01-13 14:13, Klaus Malorny schreef:
>>
>> I cannot agree. There are certain expectations with the protocol,
>> namely that the current registrar performs the necessary steps to
>> have the DNSKEYs published on the domain's name servers, and this
>> is already "process".
>
> Ah, I see how you look at it.
> If that's the case, then we should make DNSSEC mandatory, which it
> isn't. (though I would like it :-))
>
> Secure transfers are not mandatory as well.
> The only thing koch-dnsop-dnssec-operator-change describes is "if you
> want to do a secure transfer, this is how you can do it".
> We don't say you MUST do secure transfers because there is allways an
> alternative to go insecure and we cannot mandate DNSSEC.
>
> So if a key is relayed to a registrar, it is expected that he relays
> the key to the DNS operator that is appointed by the registant. The
> DNS operator can then publish the key to satisfy his customer, but we
> have no contractual control over the DNS operator nor any RFC to make
> that compulsory.
>
> I guess we could have an expiration timer on the key, but who should
> set that timer then ? Let's say a regular secure transfer can be done
> in 3 days, what is a reasonable timer? 1 week ? And should the gaining
> registrar set that timer ? And what if a gaining registrar sets the
> timer to 1 year? Should the registry prohibit that by local policy ?
> So suppose a registry does set a local policy of max 2 weeks for the
> timer.
> Then the timer can also be set by the losing registrar based on the
> local policy of the registry, and we don't have to communicate that
> timer over the protocol. It can be set in the cooperating DNS
> operator's provisioning system, or even be deleted by hand at will.
>
> The only thing a keyrelay command does is relay a key to facilitate a
> secure transfer process for those that want on both sides, but that is
> not mandatory to implement for every registrar or DNS operator.
>

Hi Antoin,

while it would be a bit too lax for me, if it is the desired design principle to 
give no assurances about what the registrar does with the DNSKEY data in the 
message, you also need not to give any assurances on the expiration timestamp I 
suggested to be relayed along with the DNSKEYs. Let it simply be a hint to the 
(potentially) losing registrar.

Regards,

Klaus







_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.