
JUST talk about things like:

1. we have registry, registrar, registrant and DNS operator"

2. any of those might give the right to a third party to act on their behalf

3. we only know there are direct connections and knowledge between 
registry-registrar, registrar-registrant and registrant-dns operator

What we MUST have is:

- Enough data in the registry so that DS can be created that refer to key 
material used to sign the zone published by the dns operator

Today we know that we have cases like:

A. The DS is passed to the registry

B. The DNSKEY is passed to the registry that create the DS

C. The DNSKEY is fetched from the zone of the DNS operator and the DS is created

We have the following plus and minuses:

bla bla bla


DNSOP mailing list

Reply via email to