Re: [regext] Alissa Cooper's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)

"Hollenbeck, Scott" <shollenbeck@verisign.com> Wed, 01 August 2018 11:52 UTC

Return-Path: <shollenbeck@verisign.com>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B0C73130E6A; Wed, 1 Aug 2018 04:52:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cwapQzuTTxSV; Wed, 1 Aug 2018 04:52:43 -0700 (PDT)
Received: from mail4.verisign.com (mail4.verisign.com [69.58.187.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1F147130E77; Wed, 1 Aug 2018 04:52:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=3424; q=dns/txt; s=VRSN; t=1533124363; h=from:to:cc:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version:subject; bh=2MDsThpKOQy1n/icUOthXL6ZWnDJD55s0NYABIVV/ME=; b=PbVrPQPd/mbNnldoJXbH3miZ7quQRrs6kF3auXBSqwb7d4rkDRMnWVx4 U0LpD7kn6llCAPY5evtX2TcFUAEgcK6o+WBSL+boCbIoyxt+EscYIb+C/ AypTCXncCkPc1XqT+oUkqs0QNox41AUKMPD/akFHEp4jg9nuqK9VFHgzZ BE9x5xghbVQisAb0XMhuhw1MXdzFgz4evfpEitjag13Ne42PWq1OsecBR Ixm38Xxzqv9SsOcqCwoi4MSH80WHuFv1H5Tr034neyVugo3K9PnRZJnSb IPG8WBa2syEPPOHQhnp4wdcf3OlZ5hSoC+AObuFPpcGjn7P5k6wlpeOrE w==;
X-IronPort-AV: E=Sophos;i="5.51,431,1526356800"; d="scan'208";a="5356397"
IronPort-PHdr: 9a23:1OralRBshDmRemcOCaO+UyQJP3N1i/DPJgcQr6AfoPdwSP35osiwAkXT6L1XgUPTWs2DsrQY07SQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbAhEmDuwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VC+85Kl3VhDnlCYHNyY48G7JjMxwkLlbqw+lqxBm3oLYfJ2ZOP94c6jAf90VWHBBU95RWSJfH428c4UBAekPPelaronyu1QAohSlCAmwH+zvyCNEimPq0aA41ekqDAHI3BYnH9ILqHnYotf7NKAWUeCx0qbIyy7MYO1K1jf+8ITDbw0vru2LXbJsbcrdx1QkGgTejlWQrozlOzeV2foLs2eA8eVvSeGvhnU5qw5vuDivx9wsiojGhoIT0FzL6SJ5wIMsKNC+VUV1b9mkEJ5KuCGbMYt7WsIiTH90uCY00LEGvoS7fCcSxJQixx/fb/uHfJSS7RLnTuaRIC14iGhieLKliBa/91WrxO7kVsSszVpGsjBJnsTOu30DzRDf98iKR/Vn8kqu2juDzx3f5v1eLUwpl6fXN4QtzqM/m5cQq0jPAyz7lF34jKCIdUgo5u2l5uHlb7r6upOTLYp5hhziPasyn8GyAfk3PRYAX2We/emzyaDs8lP/Tb5XlPM5iLPZv4rfJckDo665BBJa3Zg75hakCjemzMwYnX4aLFJZYB6Hj5bmO1XJIP3gEPqxn0yinCpryP7eMbPuA4nBImXZnLf/Ybl97FRcyBIpwd9F+p1YEK8BIOjoWk/3rtDXEhg5Mwmsz+bmDtVyyJ8eVHqSDqOFKq/erF2F6+w1L+WRZIIYtizxJvcm6vL2iH82g14dfa2n3ZsNb3C4G+xrI16ZYXrrhtcBFXkFvgwlQ+P0lFKCUiVeZ2isUKIm5zE7E4OmDYjFRoy3nLOB2yK7EoVMZm9aElCMDWvod4KcVvgWbCKSI9RhkiceWrW6V4Ah0hautBfkxLp9IOvY4CwYtZT73thv++LTjQ0y9SBzD8mF0mGCUXp0nmwTSj83wq9/vUJ9xk2E0ahijPxSDcZT6O9RUgcmKZ7cyPR3BM3oWg3bcNeJVE+qQtS4DjEtQNI92sUObFhyG9q8gRHDwzOmA6UImLORHJw466Xc0GPzJ8lj13nGyLAtj0U8TctALmCmh7Bw9xTdB4LTlEWZjamqf7wG3CHR7GeD0XaOvEZAXQ5qT6rFUm4QZ0TKrdjg+kzCT6WhCbU9Mgta0sOCK7VFasHnjVlcQ/fjItveaXqrm2isHRaI2q+MbI3ydmUHwirdB1YLkg8P/XudNAgxGDuho2zEADxpD1LvbBCkze4r4jyySk4v1AiiZEpmz7ev5VgUg7PWA6ca2rMfoy4JoDJzBFunwJTXDYzE70AufahHbvs87UtJk2XDuEM3dsihIrttrl8TbwoxuFnhgUZZEIJFxIIKq3cuwQx4JKmblBt6fDSEwdq4bqbXLW328RalZqXV8k/TyteN+6gJrv8/rgOw70mSCkM+/iA/gJFu2HyG68CPVVJKXA==
X-IPAS-Result: A2GzBwDInWFb/zCZrQpbGwEBAQEDAQEBCQEBAYQxgScKg3WWUYMuDpIwgWYLIwuBAoM8AheDRzgUAQIBAQEBAQECAQECgQUMgjUkAQ4vHD0BAQEBAQEmAQEBAQEBASMCMxEsAQEBAQMjETcODAQCAQgRBAEBAwIfBwICAjAVCAgCBAENBQiDGYIOsEOBLopWgQuIFIFCPoESgxKDGwIBAgGBKgESAYMgglUCh3qEdY0tAwYChheJG4FQRYNZiCuKVoRbAYJnAgQCBAUCFIFYgQNYEQhwgzkJgkSISIU+bwGNPoEfgRsBAQ
Received: from BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) by BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1466.3; Wed, 1 Aug 2018 07:52:41 -0400
Received: from BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde]) by BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde%4]) with mapi id 15.01.1466.003; Wed, 1 Aug 2018 07:52:41 -0400
From: "Hollenbeck, Scott" <shollenbeck@verisign.com>
To: "'alissa@cooperw.in'" <alissa@cooperw.in>, "'iesg@ietf.org'" <iesg@ietf.org>
CC: "'draft-ietf-regext-rdap-object-tag@ietf.org'" <draft-ietf-regext-rdap-object-tag@ietf.org>, "Gould, James" <jgould@verisign.com>, "'regext-chairs@ietf.org'" <regext-chairs@ietf.org>, "'regext@ietf.org'" <regext@ietf.org>
Thread-Topic: [EXTERNAL] Alissa Cooper's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)
Thread-Index: AQHUKPPPzYT92l5niU+pYkgfm5Ig56Sqxkzg
Date: Wed, 01 Aug 2018 11:52:41 +0000
Message-ID: <f3f763fd36c3499093123cb19f881c9c@verisign.com>
References: <153305805904.3273.14937489699671784628.idtracker@ietfa.amsl.com>
In-Reply-To: <153305805904.3273.14937489699671784628.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/KqxiQhumLu2BqJN1-zDLQRjOBeE>
Subject: Re: [regext] Alissa Cooper's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Aug 2018 11:52:46 -0000

> -----Original Message-----
> From: Alissa Cooper <alissa@cooperw.in>
> Sent: Tuesday, July 31, 2018 1:28 PM
> To: The IESG <iesg@ietf.org>
> Cc: draft-ietf-regext-rdap-object-tag@ietf.org; Gould, James
> <jgould@verisign.com>; regext-chairs@ietf.org; Gould, James
> <jgould@verisign.com>; regext@ietf.org
> Subject: [EXTERNAL] Alissa Cooper's No Objection on draft-ietf-regext-
> rdap-object-tag-04: (with COMMENT)
> 
> Alissa Cooper has entered the following ballot position for
> draft-ietf-regext-rdap-object-tag-04: No Objection
> 
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
> 
> 
> Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
> 
> 
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-regext-rdap-object-tag/
> 
> 
> 
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
> 
> I'm not sure why anyone would do this, but I'll ask anyway: is there no
> concern about someone maliciously registering an identifier against an
> existing RDAP URL, given that the registry is specified to be FCFS? Let's
> say I have a grudge against MyLocalRIR and I go register "fubar" as the
> service provider name together with an existing mylocalrir.org RDAP URL.
> This maybe has little practical effect but surely MyLocalRIR would not be
> too happy with it.

Thanks for the review, Alyssa. Yes, this is possible. We could specify another registration policy; perhaps expert review? Even with that policy, though, the expert would have to be able to distinguish a "legitimate" operator from a fake, and that wouldn't always be an easy task and there would still be a risk of a fake getting through. Perhaps we could add text to advice IANA that fakes are possible and IANA should be able to respond to a change request from a "legitimate" operator with assistance from an expert reviewer. Another possibility could be FCFS with email contact information provided so that IANA can attempt to verify the request. Looking at RFC 82126 again, I see that "a minimal amount of clerical information" is required, so adding contact information would be a good change.

Scott