Re: Registry lock - two-factor or intervention
Patrik Fältström <[email protected]> Fri, 20 Sep 2013 15:52:30 +0200
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On 20 sep 2013, at 14:59, MICHAEL YOUNG <[email protected]> wrote: > Some thoughts below: > >> I see no problems what so ever to "turn on" via epp, and think that is what should be done. > > > The original use case for the "Registry Lock" service offering, at least at the gTLDs was to provide some backup restrictions in the event a registrar's credentials/systems were compromised. ...which I think is still a good goal. > Registrars can already "lock" a domain through Client prohibited statuses. Not in all TLDs. Don't just talk about gTLDs... ;-) > Early Registry Lock service offering required the Registrar to authenticate in an out of band mechanism from the EPP server, this typically meant calling into the Registry support desk and providing a personal authentication code/password/token, etc at which time the Registry staff would apply the lock. Later some Registries talked about provided an out of band API separate from the Registry system to automate the same concept. > > If this is still the business justification (protection against a compromised Registrar), then there is a problem with facilitating turning on the Registry Lock via the EPP server. Well, I see that as a potential denial of service attack. But my only point was that we should see the "Turn ON", "Turn OFF", "Make changes" as separate operations as they MIGHT require different mechanisms. > Although a separate system, with separate credentials that happens to use an EPP API would be fine. Personally I think one should only use an EPP API where necessary, it's easier to use Restful API over xml or json for non-core registry requests. If you have an automated system, why implementing something else than EPP? >> I think you absolutely must have a two-factor authentication in the form of two phone numbers, physical surface post or whatever. Something that is extremely hard to socially engineer. Require two persons to be involved or whatever. > > Exactly the point to requiring them to contact customer service as past of the Registry Lock process, no actual direct machine interface method to apply or remove the lock and multiple steps. You now need to have the personal credentials of an authorized Registrar employee versus the main login credentials for the registrar. Of course, as always, the greatest exposure is the Registrar's and Registry's own staff. Correct. And that is why it is so important to look in detail on each operation and define what can be done to secure it. I would say that we need two different communication mechanisms where at least one, if not two, humans are involved to do some changes that have to do with these locks. Patrik _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg
signature.asc
(application/pgp-signature, 203 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iEYEARECAAYFAlI8Ux8ACgkQrMabGguI182ZrQCfeigSBkJY4HNT5aWxIjsn8Z9r 348AoIaTE2Q0SE481DoU4EoFDEMPSSpl =x9ku -----END PGP SIGNATURE-----