Presentation is loading. Please wait.

Presentation is loading. Please wait.

Improving DNS contents in the RRR world Ólafur Guðmundsson Steve Crocker 2012 Oct.

Similar presentations


Presentation on theme: "Improving DNS contents in the RRR world Ólafur Guðmundsson Steve Crocker 2012 Oct."— Presentation transcript:

1 Improving DNS contents in the RRR world Ólafur Guðmundsson Steve Crocker ogud@shinkuro.comogud@shinkuro.com steve@shinkuro.comsteve@shinkuro.com 2012 Oct 171ogud@shinkuro.com

2 DNS view of the RRR world Registrant Registrar Registry Parent DNS servers Child DNS servers DNS operator DNS resolvers 2012 Oct 172ogud@shinkuro.com

3 Relationship combinations: DNS information flow Registrant operates DNS ◦ Uses registration interface to change DNS information. Registrar operates DNS ◦ Registrar updates Registry directly External party operates DNS ◦ DNS operator asks registrant to make changes  (DNS operator never has access to registrant’s account ) 2012 Oct 173ogud@shinkuro.com

4 Current Situation: Observed problems External DNS operator has hard time to change DNS records (NS and DS) in registry. Technical Consequences: ◦ Moving name servers is hard  Name server list goes partially stale  Each name server may have many names ◦ DNSSEC Key change fails 2012 Oct 174ogud@shinkuro.com

5 Contacts vs Roles vs Accounts ICANN registration requires 3 contacts, administrative, technical, billing Commonly for each registration there is one account at registration  anyone with access to account can do everything, update, pay, transfer etc. 2012 Oct 175ogud@shinkuro.com

6 Administrative Solution: Sub accounts The ability to delegate roles to other accounts ◦ DNS operator is technical  update DNS ◦ Billing is gets bills  can pay bills ◦ Administrative can perform all operations,  only one able to do transfer 2012 Oct 176ogud@shinkuro.com

7 Technical Alternative: Registrar automates upload of DNS information With DNSSEC the contents of NS and DNSKEY sets can be authenticated and used for updated registry information ◦ NS + RRSIG(NS)  NS in registry ◦ DNSKEY + RRSIG(DNSKEY)  DS in registry  Possible: CDS + RRSIG(DNSKEY)  DS in registry Registrars can either perform this on schedule or when Registrant or DNS Operator requests via automated registration interface 2012 Oct 177ogud@shinkuro.com

8 Thank you 2012 Oct 178ogud@shinkuro.com


Download ppt "Improving DNS contents in the RRR world Ólafur Guðmundsson Steve Crocker 2012 Oct."

Similar presentations


Ads by Google