Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
SSAC Report on Registrar Nameserver Management

DNSSEC Delegation Signer (DS) Record Automation (R1)


Date IssuedDocumentReference IDCurrent Phase

09 May   

SSAC Report on Registrar Nameserver Management DNSSEC Delegation Signer (DS) Record Automation (R1)SAC125SAC126

Phase 2 | Understand




Progress Bar Container
step2
Progress Bar - Hyperlink Step
titlePhase 1 Receive
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 2 Understand
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 3 Evaluate
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 4 Implement
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 5 Close
urlAdvice Process
Progress Bar - Hyperlink Step
titleClosed
urlAdvice Process



Description:

The SSAC recommends that the registry and registrar communities collaborate to develop and implement a comprehensive code of conduct to mitigate the risks associated with registrable sacrificial nameserversIf a registry or a registrar wishes to implement DS automation for third-party DNSSEC operations, the current recommended interoperable mechanism is CDS/CDNSKEY (RFCs 7344, 9615). This mechanism has limitations as described in this document but has been deployed and there is operational experience in using it.


STATUS UPDATES

DatePhaseTypeStatus Updates

May  

Phase 2Phase UpdateICANN received SAC125SAC126, acknowledged, and is currently reviewing.

May  

Phase 2Phase ChangeNow Phase 2: Understand

May  

Phase 1Phase UpdateICANN acknowledged receipt of Advice.

May  

Phase 1Phase ChangeNow in Phase 1: Acknowledge

09 May   

Phase 1Phase Update

SSAC published SAC125: SSAC Report on Registrar Nameserver ManagementSAC126: DNSSEC Delegation Signer (DS) Record Automation: https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-125126-0916-0508-2024-en.pdf.