Re: [eppext] [IANA #814703] INSERT “Common Object Attribute (COA) Extension for the Extensible Provisioning Protocol (EPP) "

Alexander Mayrhofer <alexander.mayrhofer@nic.at> Wed, 01 April 2015 15:03 UTC

Return-Path: <alexander.mayrhofer@nic.at>
X-Original-To: eppext@ietfa.amsl.com
Delivered-To: eppext@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AADE71ACCFC for <eppext@ietfa.amsl.com>; Wed, 1 Apr 2015 08:03:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.532
X-Spam-Level:
X-Spam-Status: No, score=-3.532 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_AT=0.424, HOST_EQ_AT=0.745, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_HI=-5, T_FILL_THIS_FORM_SHORT=0.01, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T171wRfJhfKJ for <eppext@ietfa.amsl.com>; Wed, 1 Apr 2015 08:03:12 -0700 (PDT)
Received: from mail.sbg.nic.at (mail.sbg.nic.at [83.136.33.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 858C81ACD50 for <eppext@ietf.org>; Wed, 1 Apr 2015 08:02:55 -0700 (PDT)
Received: from nics-exch2.sbg.nic.at ([10.17.175.6]) by mail.sbg.nic.at over TLS secured channel (TLSv1:AES128-SHA:128) with XWall v3.50 ; Wed, 1 Apr 2015 17:02:54 +0200
Received: from NICS-EXCH2.sbg.nic.at ([fe80::a5b2:6e42:e54d:9d57]) by NICS-EXCH2.sbg.nic.at ([fe80::a5b2:6e42:e54d:9d57%12]) with mapi id 14.03.0224.002; Wed, 1 Apr 2015 17:02:50 +0200
From: Alexander Mayrhofer <alexander.mayrhofer@nic.at>
To: "Hollenbeck, Scott" <shollenbeck@verisign.com>, "eppext@ietf.org" <eppext@ietf.org>
Thread-Topic: =?utf-8?B?W0lBTkEgIzgxNDcwM10gSU5TRVJUIOKAnENvbW1vbiBPYmplY3QgQXR0cmli?= =?utf-8?B?dXRlIChDT0EpIEV4dGVuc2lvbiBmb3IgdGhlIEV4dGVuc2libGUgUHJvdmlz?= =?utf-8?Q?ioning_Protocol_(EPP)_"?=
Thread-Index: AQHQZYXFOtC/4MadjkGKOG7s3ad3VZ0qUiOwgA3zayA=
Date: Wed, 1 Apr 2015 15:02:50 +0000
Message-ID: <19F54F2956911544A32543B8A9BDE07546798B14@NICS-EXCH2.sbg.nic.at>
References: <RT-Ticket-814703@icann.org> <6F585EDF-46C2-418B-8E7C-6E40335E129F@verisign.com> <rt-4.2.9-2033-1427127836-1220.814703-9-0@icann.org> <831693C2CDA2E849A7D7A712B24E257F49F89999@BRN1WNEXMBX01.vcorp.ad.vrsn.com>
In-Reply-To: <831693C2CDA2E849A7D7A712B24E257F49F89999@BRN1WNEXMBX01.vcorp.ad.vrsn.com>
Accept-Language: en-US, de-DE
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.10.0.163]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-XWALL-BCKS: auto
Archived-At: <http://mailarchive.ietf.org/arch/msg/eppext/HfviSbh3PXunwSGfFSQ8Aano__s>
Subject: Re: [eppext] =?utf-8?q?=5BIANA_=23814703=5D_INSERT_=E2=80=9CCommon_Ob?= =?utf-8?q?ject_Attribute_=28COA=29_Extension_for_the_Extensible_Provision?= =?utf-8?q?ing_Protocol_=28EPP=29_=22?=
X-BeenThere: eppext@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: EPPEXT <eppext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/eppext>, <mailto:eppext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/eppext/>
List-Post: <mailto:eppext@ietf.org>
List-Help: <mailto:eppext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/eppext>, <mailto:eppext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Apr 2015 15:03:16 -0000

All,

As one of the assigned Designated Experts, I've completed my review of the extension and I have the following (minor) comments:

- From reading the " VERISIGN PROPRIETARY INFORMATION" paragraph, i understand that i cannot "copy or communicate" the documentation under the link without "written prior consent of Verisign". I'm not a legal person, but personally i find this an restriction that is inappropriate for a public web page, because i can hardly even "view" the web page without my web browser "copying" it to its cache ... Anyways, i understand that such "boilerplates" are a requirement of many companies, and this probably stems from a paper version of this document?

- I do understand the XML namespace URI currently used in the document is not yet registered in the IANA XML registry, and i suggest that authors register it accordingly once the EPP extension itself is registered.

- I didn't see in the document whether or not a certain KEY could be used multiple times for a single object, or not. Clarifying this could improve interopability, and Section 2.1 would probably be an appropriate place. From the description of the "update" command, the KEY seems to be used to identify a certain Key/Value pair, so duplicate KEYs are likely not intended? 

- The specification is silent about error conditions, and does not recommend any specific EPP error codes for specific situations (eg. when an "update" tries to remove an attribute that is not set for an object, or when an attribute is not allowed due to server policy).

- Security: The specification does not specify whether or not CoA's provisioning by client A are returned to the info response for client B. I hence understand that this is server policy? If there are any restrictions on server policy in this regard, those should be listed - or, alternatively, it should be clarified that this is individual server policy.

tia & thanks,
Alex

> -----BEGIN FORM-----
> Name of Extension:
> “Common Object Attribute (COA) Extension for the Extensible Provisioning
> Protocol (EPP)"
> 
> Document Status:
> Informational
> 
> Reference:
> http://www.verisigninc.com/assets/epp-sdk/verisign_epp-
> extension_coa_v00.html
> 
> Registrant Name and Email Address:
> VeriSign Inc., epp-registry@verisign.com
> 
> TLDs: Any
> 
> IPR Disclosure: None
> 
> Status: Active
> 
> Notes: None
> -----END FORM-----
> 
> —
> 
> 
> JG
> 
> 
> 
> 
> 
> James Gould
> Distinguished Engineer
> jgould@Verisign.com
> 
> 703-948-3271
> 12061 Bluemont Way
> Reston, VA 20190
> 
> VerisignInc.com
> 
> “This message (including any attachments) is intended only for the use of the
> individual or entity to which it is addressed, and may contain information that
> is non-public, proprietary, privileged, confidential and exempt from
> disclosure under applicable law or may be constituted as attorney work
> product. If you are not the intended recipient, you are hereby notified that
> any use, dissemination, distribution, or copying of this communication is
> strictly prohibited. If you have received this message in error, notify sender
> immediately and delete this message immediately.”
> 
> Download BF09FAA4-32D8-46E0-BED0-CD72F43BD6E0[81].png
> 
> image/png 4KiB
> 
> _______________________________________________
> EppExt mailing list
> EppExt@ietf.org
> https://www.ietf.org/mailman/listinfo/eppext