Re: Registry lock - setting statuses on hosts
Antoin Verschuren <[email protected]> Tue, 15 Oct 2013 15:39:55 +0200
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 op 15-10-13 12:49, Mark Elkins schreef: > I believe it is "No" - in order to keep DNSSEC updates as simple > as possible. (KISS). Even if the Nameservers (and associated) > records of a domain are no longer being published (In a > Delete/Redemption or ClientHold) - I think the Registry should > still not hinder a DNSSEC Update/Key Rollover. This could stop a > Key-Rollover completing if the DNS Provider can not see "DS's" - > because Records are not being published - but that is a different > problem. > > What do registries say/do? There is a scenario where you hijack the registrar, and change the DNSSEC key material at the registry to DOS the victim. Or delete the DNSSEC key material so you can do cache pollution. So I think the registrant should be able to state what should be locked: - -Administrative parameters to prevent legal registrant/registrar changes - -NS and in bailiwick glue records to prevent delegation redirection - -DNSSEC key material changes to adjust security levels If you do the latter, you should unlock before you do a key rollover, but that is your own child policy decision. I would personally do so as my child policy is to only do a well prepared key rollover every X years. In stead of a very strict administrative (un)lock procedure, I would also favor a mechanism where a registrant needs to approve every change at the registry by supplying a credential that the registry and registrant both know. A request could be approved by the registrants pgp signature for example, where the public key is registered at the registry when the domain is registered. But that would need to be supported over the complete chain, and needs standardization. - -- Antoin Verschuren Technical Policy Advisor SIDN Meander 501, PO Box 5022, 6802 EA Arnhem, The Netherlands P: +31 26 3525500 M: +31 6 23368970 Mailto: [email protected] XMPP: [email protected] HTTP://www.sidn.nl/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQEcBAEBAgAGBQJSXUWlAAoJEDqHrM883AgnOZoH/R4iHsk4WPKc3D8hFAcNGQQG 4fgBW6EfGr+oWP34b93jIo1ordSBnLl0frbMg3hx3nxu/Xka0tFFb5RooD2uT2dh 4Ox7YEeo0ubsWI2g/hb3TWAY0udKTKWaIrsNMNSIutY+gAalI3YJwmnGyuXqSKmK i9dPkxYk54SDU7leXFx4LtpfoAXvaZBBFMl8IuCkzYNVFgm5MeN6mlsOwqlAswGb 7RmyV5CDaqr9EF3b0ESU7yjAa/roj7bym+c3IOCLay64+HFScNuMxnsoBwLQXTPU apTWSWAFk5Le3wg2h6GOjqZn/6Q0TDJ7Oc2StSnJ9DaQs8lZqyEsFqjks04/OS4= =OGue -----END PGP SIGNATURE----- _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg