Suggestion: JUST talk about things like:
1. we have registry, registrar, registrant and DNS operator" 2. any of those might give the right to a third party to act on their behalf 3. we only know there are direct connections and knowledge between registry-registrar, registrar-registrant and registrant-dns operator What we MUST have is: - Enough data in the registry so that DS can be created that refer to key material used to sign the zone published by the dns operator Today we know that we have cases like: A. The DS is passed to the registry B. The DNSKEY is passed to the registry that create the DS C. The DNSKEY is fetched from the zone of the DNS operator and the DS is created We have the following plus and minuses: bla bla bla Patrik _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop