Re: Merging RRP and Whois

Eric Brunner-Williams in Portland Maine <[email protected]>
Newsgroups gmane.ietf.whois
Message-ID <[email protected]>
James,

Patrik (AD hatted) wrote about cases for extending the RRP. I replied,
in part pointing out that anonymous read access isn't on my todo list,
or any registry provisioning requirement I have seen. Perhaps you have
misunderstood the exchange. Perhaps I misunderstand your commentary.

The second part of my reply concerned the role of the registrar. In the
case Patrik offered, registrant modification of registry data without
interposition by a registrar, several issues arise which don't in the
interposition case:

Technical issues (non-exhaustive):
	scaling the RRP aaa mechanisms,
	scoping the registry access mechanism,

Economic issues (non-exhaustive):
	scoping registrar liability and compensation,

Public Policy issues (non-exhaustive):
	registry competition with registrars

As I mentioned, where the write-access is registrar-mediated, the aaa
and access mechanism issues are simplified, and other issues don't
arise in addition to those which already exist for the registrar-mediated
service.

In your commentary you mentioned privacy as a motivation, positing the
"thickness" of the data, and presumably the policed data, in the care of
several actors -- you listed registry, registrar, and reseller, then
placed the duty to notice any of the registrant's privacy policy (which
may be something other than a preference or a consideration, and need not
be static) upon the registrant, to necessitate registrant participation
in a registrar-registry service model. 

Since the actors having the roles of registrant, reseller, registrar, and
registry are not fixed, in particular, the reseller and registrar parts
may be fluid, and the registrant's policy not required to be fixed, if the
protocol does not also notice the registrant of changes in the upstream
service providors, then the direct access (to intermediaries!) mechanism
fails to meet the sufficiency test for policing of provisioned data.

Non-necessity was my point to Patrik, non-sufficiency my point to you (James).

The third part of my reply concerned Patrik's speculation w.r.t. dnssec
and key management. "Out of band" means by another mechanism. 

Eric
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.