Re: [DNSOP] Verifying TLD operator authorisation

Bjarni Rúnar Einarsson <bre@isnic.is> Tue, 18 June 2019 10:15 UTC

Return-Path: <bre@isnic.is>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ACC34120665 for <dnsop@ietfa.amsl.com>; Tue, 18 Jun 2019 03:15:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XGJ2fzdiIgPX for <dnsop@ietfa.amsl.com>; Tue, 18 Jun 2019 03:15:07 -0700 (PDT)
Received: from lugh.isnic.is (lugh.isnic.is [193.4.58.86]) by ietfa.amsl.com (Postfix) with ESMTP id 24A641205EC for <dnsop@ietf.org>; Tue, 18 Jun 2019 03:15:07 -0700 (PDT)
Received: by lugh.isnic.is (Postfix, from userid 2516) id EF015AA4E2; Tue, 18 Jun 2019 10:15:05 +0000 (GMT)
Content-Type: multipart/mixed; boundary="==UHcFpcAA3yzWJK8a5sIs8XioKZsaXt=="
MIME-Version: 1.0
From: Bjarni Rúnar Einarsson <bre@isnic.is>
To: Nick Johnson <nick=40ethereum.org@dmarc.ietf.org>
Cc: "dnsop@ietf.org" <dnsop@ietf.org>
In-Reply-To: <CAFz7pMvkQUz78Qow03RsFKHof3nrnGu3BUwUP0zstWgVtP3Msw@mail.gmail.com>
References: <CAFz7pMvkQUz78Qow03RsFKHof3nrnGu3BUwUP0zstWgVtP3Msw@mail.gmail.com>
User-Agent: Mailpile
Message-Id: <tqjbSfSi2Kv3DHpi6nBJVi2e6tCZFTdVyrKpxiud2348@mailpile>
Date: Tue, 18 Jun 2019 10:13:46 -0000
Autocrypt: addr=bre@isnic.is; keydata=xsDNBFyh/HMBDADeTUDSeFjLIlG/S4OkGDwsdHgc cAjnWun+MhVHlm/AK5nQ+Nr+dMgPoDKgtTz9TZgmewpvEWnGIdBhsBSFMAncFaGxWBjvNRjcy3QZZ ndwfKRBUsbbkhQbQ8qIxKYZxw8cY4JGPIUiqNZjIYORKuchN0MXqsUjkmsSrMQEw3n8Nsi+aQT/w/ lnKJO9cCPTaCThTN0odwva2QWe8WWLQ3Fr5UBuhb/LzbMVZn61ASjehnTt2YKYXsiRcLRs/XfqaqU vIwM3WqFKH9IZl49V+wQBHu4kljLchLw2DPLpf+mv2VoZMaks2DmTJDTlKkXp3X9YXvGUBcHGyF7S 4KqsKTZnplVxNE89X4Fg1FjGdHHAsXVBpOibKGpPqc91hsj5SbcipfXfIBl0FzLlGZvWUTtQsq46k fa4k06oSpcr89g5zVnLOHL0ftpSX6ScIVgKsV1uEYgWhjWjATBuUdKXG93rSluZDVIrf34Jb/EsTf bT8ff0SipaiYizRTLXZ4KiDZ8AEQEAAc0mQmphcm5pIFLDum5hciBFaW5hcnNzb24gPGJyZUBpc25 pYy5pcz7CwQ4EEwEKADgWIQQs8AwZMbeQyjfTmy5ZC1sMA8ImhQUCXKH8cwIbAwULCQgHAgYVCgkI CwIEFgIDAQIeAQIXgAAKCRBZC1sMA8ImhZYHC/9cd4KB4EwhvFm3sNwv2iTUouDGQCsDeK0WMvozS ZwR/vG0s8katBlCL1XOmKGDGADS3FcmmjlguvOT572WXLZvx2Tn0U9g5N69htB0VeUJjaGpVNzUwf I+W6M6NDYQolQ2y4Ndm7HCjwDPStelZyE2cXMVBsxZYl3UMoUfScI6BNneA+EiUxit/PU+LbFc59a oTEVOtBcID/3RmFHDL7WyZjEvZh2UVzu+dIsJuINd+G+GPnvS1UfHsMsEQhk84VCCG4VYkbwN81Wa zoL7mWCNjjJnqh9ERjVwYyUhRVw+9VcimUrsZf6s1GlEtEI2kquSsTH1BZ5v0POYVJ/mHK/kCDCAP 6B2I78ExppGi1mL52YwuwovO//OVkCiVBciCA/NKtk3mGnhMWoB4vDmaFY2H+gOeV/sSxGnsuUicR zcPlUjwtUx1+T6/b/ib0px2JXzOYBV2gCNzUDC7iQ3Ahsf7V1Yi4nCDN9gJsCDEj/JItWIAz2rUKB dQiMKSpF6LOjOwM0EXKH8cwEMAMmjYLjn/M7kxb0Uasyeg6jv7KDS92jdkh3fjV2TsgL1gTRqQrNH gejBP19Wwg6oc7cRmmoDfQ6mtNyXvNfd+5cF5MdR62q01TGb4ciatUbpoMA8IfyqeopuafMwteoE+ M8oO5OfHc0PeXORr059KK9P8vLcnit8GM6y/DkTZPnZOwDnM4SoPFSZZXcBogsHPjbklIzGoqwjMA ehmo2riJOrgL1XR3U83cOY45mLsw68mCGiYTtFG+gNW0wq4Hkj8kizMJ3nlEuIkhQ+wVQ+BIU+xQo bNhoorY3oK7aeJf2dmpF49nNUFSORYrcSzADP9a9Fj9fThfK0yJ7RgLQeCAZgxuYyDHeF6v03UVyo WIx1KMm3K/PHhHhxr4f1oZl+Y35czg9I8UkyCuoSa4Vrb8neBTJaOq+7ZQqSk0xBKf+NIHEBlb4zt Niru+WQv0PkJypUDQZvKhB5frnId5brpUUPfGOX/EL7w2LVlHQVEkPeUCyewIKBcCCW0wdtSrrzew ARAQABwsD2BBgBCgAgFiEELPAMGTG3kMo305suWQtbDAPCJoUFAlyh/HMCGwwACgkQWQtbDAPCJoU 0cQwAy+0RUc+JERn2V7bP/04aH+mmcpRtQQxrRRxTdzYSA6laCMhmzBZkCJA38ESuD3cCLu9zGJkR j1iu/FO4PejB0G0+1EMv9BNWqyOcehQH2ZjNPSQX2kCdBuGdqXuJIapV0EpIUi735h8u5igTUbagO tGZ4fifo4B2tOVtfoC82EA9jsdyUELGy/irLQG0DVqqD5yV+OmWVNd3kErJYjVBd0EWtSeqedLVSF hL5xT3xNo7UbzvqeS6X1c6hF7CyH6mgzYN0N3+r5ZikN9tWXamVW7FImnDl58ydUm9um0T6IIP7Ah +KkMEHwZX3Ndfyy+DAXfB5Irs013wL8nLCprTFylHPrQP0F7yOsOt9v1aVgoHC3Z7Kg+ejGYHkq4A NixzuzrMNjqZHxkwC6MYH2vvrKsB3rLII7vee1eskSXMupx+8FZuZ04IPfTC8qaAoDNUqUqn1ZwT+ uSA0ner6+/oJP9ImxEcJdP40hmHjc6EsnkwG6fuLmeQodh2twspeFQr
OpenPGP: id=2CF00C1931B790CA37D39B2E590B5B0C03C22685; preference=sign
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/qaDjnArp98T0gIBYQbUfswwaxrg>
Subject: Re: [DNSOP] Verifying TLD operator authorisation
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Jun 2019 10:15:15 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi Nick, everyone,

Nick Johnson <nick=40ethereum.org@dmarc.ietf.org> wrote:
> I'm working on a system that needs to authenticate a TLD
> owner/operator in order to take specific actions. We had
> intended to handle this by requiring them to publish a token in
> a TXT record under a subdomain of nic.tld, but it's been
> brought to our attention that we can't rely on nic.tld being
> owned by the TLD operators - this is only a reserved domain on
> ICANN new-gTLDs, not on ccTLDs or older gTLDs.

The SOA record for a TLD contains two DNS names which should be
under the control of the NIC: that of the primary master
nameserver, and the e-mail of the responsible administrator
(which includes a domain name).

Intro: https://en.wikipedia.org/wiki/SOA_record

People on this list can probably comment on whether my above
assumption is correct, and whether those are good candidates for
what you have in mind.

Hope this helps,
 - Bjarni

- -- 
Sent using Mailpile, Free Software from www.mailpile.is

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEELPAMGTG3kMo305suWQtbDAPCJoUFAl0IuWgACgkQWQtbDAPC
JoU+ywwAyMBQ1MgOrAifji6SIjn1M4/TSaamsE1MB57IPVIF0mWO5x+rTldzmIxd
ftiGOB60Xd1Z/sKLi/i7QLIaw5Efme53n8hRccCDBwdnm+gGvEVvvkuMk8TkiYuE
QJl5xTKzqCXi9PEI/Se2EmpxklHoLI+DdZX2aGgIc2Vi2uTRPqSgCYT8Chg+WvNM
g32q4+Ldzto57fOry4KMum80XK5B8hSztPjK0k8hQgT/U2iX+2qY9S0wBYZXvOMP
7sp+7VeGnAv64EUqtpMik5BnnO95o0v9hdRbSF1GJ0qUehwo8eZzYdR0C73aM1aQ
0aW+7TYqovwsQhLuQKnKi+x8DP0Q/G4+uVQC7ecMY3cQLNyzyocte7JWNH+ZIQgu
QDXp9jkw0Z52zrDIDXZCjkzfl71B/hkhYnd9nh7AQ3onlCs4m7fzXbTZF1ors4Td
kG1OG5RXGfu/F5ecDfme/Mc6rF4Aqkrg6LALvcXYUE3u7GRx9vjH017hr6Ej+WWs
xI3Wv5U3
=YxQ/
-----END PGP SIGNATURE-----