Re: Registry lock - setting statuses on hosts

Antoin Verschuren <[email protected]> Tue, 15 Oct 2013 15:39:55 +0200
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

op 15-10-13 12:49, Mark Elkins schreef:

> I believe it is "No" - in order to keep DNSSEC updates as simple
> as possible. (KISS).  Even if the Nameservers (and associated)
> records of a domain are no longer being published (In a
> Delete/Redemption or ClientHold) - I think the Registry should
> still not hinder a DNSSEC Update/Key Rollover. This could stop a
> Key-Rollover completing if the DNS Provider can not see "DS's" -
> because Records are not being published - but that is a different
> problem.
> 
> What do registries say/do?

There is a scenario where you hijack the registrar, and change the
DNSSEC key material at the registry to DOS the victim. Or delete the
DNSSEC key material so you can do cache pollution.

So I think the registrant should be able to state what should be locked:
- -Administrative parameters to prevent legal registrant/registrar changes
- -NS and in bailiwick glue records to prevent delegation redirection
- -DNSSEC key material changes to adjust security levels

If you do the latter, you should unlock before you do a key rollover,
but that is your own child policy decision.
I would personally do so as my child policy is to only do a well
prepared key rollover every X years.

In stead of a very strict administrative (un)lock procedure, I would
also favor a mechanism where a registrant needs to approve every
change at the registry by supplying a credential that the registry and
registrant both know. A request could be approved by the registrants
pgp signature for example, where the public key is registered at the
registry when the domain is registered. But that would need to be
supported over the complete chain, and needs standardization.


- -- 
Antoin Verschuren

Technical Policy Advisor SIDN
Meander 501, PO Box 5022, 6802 EA Arnhem, The Netherlands

P: +31 26 3525500  M: +31 6 23368970
Mailto: [email protected]
XMPP: [email protected]
HTTP://www.sidn.nl/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQEcBAEBAgAGBQJSXUWlAAoJEDqHrM883AgnOZoH/R4iHsk4WPKc3D8hFAcNGQQG
4fgBW6EfGr+oWP34b93jIo1ordSBnLl0frbMg3hx3nxu/Xka0tFFb5RooD2uT2dh
4Ox7YEeo0ubsWI2g/hb3TWAY0udKTKWaIrsNMNSIutY+gAalI3YJwmnGyuXqSKmK
i9dPkxYk54SDU7leXFx4LtpfoAXvaZBBFMl8IuCkzYNVFgm5MeN6mlsOwqlAswGb
7RmyV5CDaqr9EF3b0ESU7yjAa/roj7bym+c3IOCLay64+HFScNuMxnsoBwLQXTPU
apTWSWAFk5Le3wg2h6GOjqZn/6Q0TDJ7Oc2StSnJ9DaQs8lZqyEsFqjks04/OS4=
=OGue
-----END PGP SIGNATURE-----
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg