Re: Implementation of EPP AuthInfo
Keith Gaughan <[email protected]> Thu, 9 May 2013 14:12:40 +0100
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On Tue, May 07, 2013 at 08:51:55AM +0200, Vlad Dinculescu wrote: > Thanks for the reply, please see responses inline below. > > On 07 May 2013, at 8:33 AM, Francisco Obispo <[email protected]> wrote: > > > Hi Vlad, > > > > What are the problems you're trying to address with these measures? > > Simply put, we are attempting to avoid registrars performing updates > on Contact information that are not authorised or requested by the > Contact. We have found that "bringing out the big stick" doesn't work > effectively, so now we are attempting to put the decision making where > it belongs, in the hands of the registrant. As Michele wrote (albeit in different terms), that's a sociological problem, not a technical problem. By necessity, the registrar has to be a trusted intermediary between the registrant and the registry. If a registrar is being that abusive, then the solution is to remove their accreditation, not to place roadblocks in front of those registrars who behave themselves. An alternative might be this: allow registrars to submit whatever updates they want, but if the changes trigger some heuristic, hold the change for review and rather than responding with a 1000 response code, respond with 1001, thus indicating that the change has been held for review. Later, assuming you implement the message queue, you can put a <contact:panData> message on the message queue either confirming or denying the update request (SS3.3 of RFC 5733). That leaves it up to you how you implement the review process, which could be done on your end or by contacting the existing contact to confirm the request, or whatever. Just a suggestion. K. -- Keith Gaughan, Development Lead PGP/GPG key ID: 82AC3634 Blacknight Internet Solutions Ltd. <http://blacknight.com/> 12A Barrowside Business Park, Carlow, Ireland Registered in Ireland, Company No.: 370845 _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg