Re: Implementation of EPP AuthInfo

Keith Gaughan <[email protected]> Thu, 9 May 2013 14:12:40 +0100
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On Tue, May 07, 2013 at 08:51:55AM +0200, Vlad Dinculescu wrote:

> Thanks for the reply, please see responses inline below.
> 
> On 07 May 2013, at 8:33 AM, Francisco Obispo <[email protected]> wrote:
> 
> > Hi Vlad,
> > 
> > What are the problems you're trying to address with these measures?
> 
> Simply put, we are attempting to avoid registrars performing updates
> on Contact information that are not authorised or requested by the
> Contact.  We have found that "bringing out the big stick" doesn't work
> effectively, so now we are attempting to put the decision making where
> it belongs, in the hands of the registrant.

As Michele wrote (albeit in different terms), that's a sociological
problem, not a technical problem. By necessity, the registrar has to be
a trusted intermediary between the registrant and the registry. If a
registrar is being that abusive, then the solution is to remove their
accreditation, not to place roadblocks in front of those registrars who
behave themselves.

An alternative might be this: allow registrars to submit whatever
updates they want, but if the changes trigger some heuristic, hold the
change for review and rather than responding with a 1000 response code,
respond with 1001, thus indicating that the change has been held for
review.

Later, assuming you implement the message queue, you can put a
<contact:panData> message on the message queue either confirming or
denying the update request (SS3.3 of RFC 5733).

That leaves it up to you how you implement the review process, which
could be done on your end or by contacting the existing contact to
confirm the request, or whatever.

Just a suggestion.

K.

-- 
Keith Gaughan, Development Lead
PGP/GPG key ID: 82AC3634
Blacknight Internet Solutions Ltd. <http://blacknight.com/>
12A Barrowside Business Park, Carlow, Ireland
Registered in Ireland, Company No.: 370845
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg