Re: Registry lock - two-factor or intervention

Francisco Obispo <[email protected]> Wed, 18 Sep 2013 17:41:22 -0500
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
Hi Jay,

Let me give you another example,

A registrar mistakenly changes a record (even authorizes a change), without its client knowing about it, the domain name goes offline, or even worse, gets hijacked. 

My idea of a registry lock is to have a direct relationship with the registrant/name holder, so it can decide wether the domain name is allowed to be changed by the registrar.

Verisign offers a registry lock, so perhaps they can share a little bit on how they do it, and how they authenticate the request in cases where contact privacy is enabled.



On Sep 18, 2013, at 4:56 PM, Jay Daley <[email protected]> wrote:

> We came to the conclusion that a manual verification (or possibly another out-of-band verification) does not need to be to the registrant but works perfectly well to the registrar.  That of course is much better for those of us that need to maintain the registry->registrar->registrant model and not introduce a registry->registrant component.

Francisco Obispo 
email: [email protected]
Phone: +1 650 423 1374 || INOC-DBA *3557* NOC
PGP KeyID = B38DB1BE




_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg