Re: Implementation of EPP AuthInfo
"Gould, James" <[email protected]> Tue, 7 May 2013 12:42:39 +0000
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <CDAE6BBC.4F03E%[email protected]> |
Vlad, The main question is what you're attempting to mitigate with requiring the authinfo on an update for a contact or domain. The first item is that the sponsoring registrars can and do have the authinfo values, so there is no guarantee and is unlikely that the registrant will be presented anything by the sponsoring registrar. Are you attempting to mitigate a compromised registrant account or a compromised registrar? In both cases, the sponsoring registrar can pass the authinfo automatically without any additional steps from the registrant, so requiring the authinfo on update will not mitigate these vulnerabilities. The authinfo works for actions taken by non-sponsoring registrars like for an info or transfer, since the registrant must pass the authinfo that was received by the sponsoring registrar to authorize the action. Use of the authinfo for actions by the sponsoring registrar will add no additional security since the information is available to the sponsoring registrar without any direct action from the registrant. -- JG James Gould Principal Software Engineer [email protected] 703-948-3271 (Office) 12061 Bluemont Way Reston, VA 20190 VerisignInc.com On 5/7/13 2:23 AM, "Vlad Dinculescu" <[email protected]> wrote: >All, > >Please share your thoughts regarding the implementation of the Contact >AuthInfo for the approval of initiated contact updates. > >Our current process looks to have the registrant provide the code as an >indication of approval regarding the update of their information, >completing the update instantly. Updates that are not provided with the >code will not execute. > >Further to this, we are looking to implement the Domain AuthInfo code as >a definite measure for approving registrant changes to a linked domain. >In this instance the current registrant must provide the Domain AuthInfo >code as approval of the registrant change. > >Regards, >Vlad Dinculescu >-------------------------------- >Domain Name Services >_______________________________________________ >provreg mailing list >[email protected] >https://www.ietf.org/mailman/listinfo/provreg _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg