Suggestion:
JUST talk about things like:
1. we have registry, registrar, registrant and DNS operator"
2. any of those might give the right to a third party to act on their behalf
3. we only know there are direct connections and knowledge between registry-registrar, registrar-registrant and registrant-dns operator
What we MUST have is:
- Enough data in the registry so that DS can be created that refer to key material used to sign the zone published by the dns operator
Today we know that we have cases like:
A. The DS is passed to the registry
B. The DNSKEY is passed to the registry that create the DS
C. The DNSKEY is fetched from the zone of the DNS operator and the DS is created
We have the following plus and minuses:
bla bla bla
Patrik
_______________________________________________
DNSOP mailing list
DNSOP@ietf...
https://www.ietf.org/mailman/listinfo/dnsop
opensubscriber is not affiliated with the authors of this message nor responsible for its content.