Re: Registry lock - setting statuses on hosts

Stuart Olmstead-Wilcox <[email protected]> Thu, 10 Oct 2013 01:45:27 +0000
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
> Do we actually know exactly what changes are no longer allowed when there is a registry lock?

> For example, what about DNSSEC material?

Our initial approach will be to adhere strictly to the serverUpdateProhibited definition.  If set via lock, then no domain updates will be permitted - including DNSSEC material.  

If this begins to pose a problem in the future (we will be fully epp DNSSEC compliant 1st quarter 2014) we will revisit.

Stu

-----Original Message-----
From: Patrik Fältström [mailto:[email protected]] 
Sent: October-07-13 9:56 AM
To: Stuart Olmstead-Wilcox
Cc: [email protected]
Subject: Re: [provreg] Registry lock - setting statuses on hosts


On 3 okt 2013, at 17:13, Stuart Olmstead-Wilcox <[email protected]> wrote:

> At CIRA we are working through our approach to Registry Lock and are wondering what perspectives there are out there on the approach to setting of server statuses on hosts - i.e. the locking of hosts.
>  
> We are considering two main approaches:
>  
> 1.       From the setting of a "domain lock" (serverUpdate, serverTransfer and serverDelete prohibited statuses set), automatically cascade the related host statuses (serverUpdate and serverDelete prohibited) to all host entities assigned (nameservers) to the domain in question.
>  
> 2.       Separate the locking of domains and hosts into disparate transactions - i.e. one domain update transaction to set the domain server statuses followed by subsequent host update transactions to set server statuses on desired hosts.
>  
> Our main considerations here are balancing ease of use from a registrar's perspective vs differing too far from a consistent industry approach. 

Do we actually know exactly what changes are no longer allowed when there is a registry lock?

For example, what about DNSSEC material?

   Patrik

_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg