Re: Registry lock - two-factor or intervention
Jan Saell <[email protected]> Sat, 21 Sep 2013 08:22:59 +0200
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi all, Here at iis we are have the registry lock implemented as a manual option (pricey) and is in the process of developing an automatic registry lock function. The lock is implemented using the ServerProhobited flags so it is visible in EPP (info), and we are setting the flags so that no change are able to be done over EPP except renew. The lock can be set by a registrar by sending in a form (handled manually) and can be removed by another form. To validate the unlock request we are calling the registrar manually today. The automatic system will use a strong login mechanism to a web based system where changes (lock and unlock) can be set. Our opinion currently is that the lock is there to avoid a registrant system being hacked and therefore is using this OOB method. We also think that its more unlikely that a registrar will do changes by mistake if they have to do this OOB unlock method as it requires extra step and hopefully will make them think twice before doing it. Currently we are aiming the pricing to be free for all registrars when we have it as a automatic procedure. Best regards Jan Saell On 09/20/2013 09:41 AM, Maarten Bosteels wrote: > Hi all, > > At DNS Belgium we are also planning to implement a Registry Lock for > .be, so I am definitely interested in developing a common standard. > > Given the limited interest (by registrants and/or registrars ?) seen at > other registries, we plan to start with a mechamism that requires little > development for the registry and > little to no development effort for the registrars. > > We recently discussed several options with our Registrar Forum and this > is what we came up with for an initial version: > > * a registry lock on a domain name can only be requested by the > sponsoring registrar and only via the web interface and will not be > visible nor updatable via EPP > * the adminsitrative part (signing agreements, passing around contact > details, etc) will be handled manually (exact procedures are still > work-in-progress) > * the registrant chooses who should be contacted when registrar requests > to unlock the domain name > => IMO this offers the most flexibility: a registrant can choose to > let his registrar handle the whole process or he can choose to be > involved in the unlocking process himself > * once the administrative part is handled, someone at the registry flags > the registration as 'registry locked' > => no updates possible to linked registrant nor to the host attributes > (NS and A records) of the domain name nor to the DS records (to be > investigated if we would allow emergency key roll-overs) > * the registrar requests (via the web interface) to unlock a domain name > => the registry seeks confirmation using the previously specified > contact details. Upon confirmation: registry unlocks the domain name > (TBD: indefinitely or for a limited time) > * price: to be decided > > We don't foresee a two-factor authentication mechanism, although one > could consider the pre-specified phonenumber as something you have. > (We do however plan to add two-factor authentication to the registrar > extranet, covering all possible transaction types not just those related > to registry lock.) > > A further simplification (to speed up the roll-out) could be to handle > lock and unlock requests entirely via the customer support system (and > not via the registrar extranet). > > In a later phase (when the feature has enough success) we will consider > to facilitate lock and unlock requests via EPP and to send EPP poll > messages to notify the registrar when the lock or unlock has been > approved. All of this of course preferably using a standardized EPP > extension. > > Best regards, > > Maarten Bosteels > Head of Development > DNS Belgium > +32 16 28 49 70 <tel:%2B32%2016%2028%2049%2070> > *www.dnsbelgium.be <http://www.dnsbelgium.be/>* > - -- +------------------------------------------------------------------- ! Irial / YASK AB ! Att: Jan Saell ! Box 59, S-692 21 KUMLA, SWEDEN ! Tel: 019-58 25 15 Int +46-19 58 25 15 Fax +46-19 58 38 05 ! E-mail: [email protected] ! PGP Fingerprint: E957 23C8 9F51 0958 B9AD 7F18 404A 5DA1 F944 A08B -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlI9O0MACgkQQEpdoflEoIt23QCgvl2e4qV6/bksz7BOLZJM9bQx TsQAoJ1OPenpt56gg4++Yj1Vc7Odu/ez =laOW -----END PGP SIGNATURE----- _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg