Page History
DNSSEC Delegation Signer (DS) Record Automation (R1)
Date Issued | Document | Reference ID | Current Phase |
---|---|---|---|
09 May | SSAC Report on Registrar Nameserver Management DNSSEC Delegation Signer (DS) Record Automation (R1) | SAC125SAC126 | Phase 2 | Understand |
Description:
The SSAC recommends that the registry and registrar communities collaborate to develop and implement a comprehensive code of conduct to mitigate the risks associated with registrable sacrificial nameserversIf a registry or a registrar wishes to implement DS automation for third-party DNSSEC operations, the current recommended interoperable mechanism is CDS/CDNSKEY (RFCs 7344, 9615). This mechanism has limitations as described in this document but has been deployed and there is operational experience in using it.
STATUS UPDATES
Date | Phase | Type | Status Updates |
---|---|---|---|
May | Phase 2 | Phase Update | ICANN received SAC125SAC126, acknowledged, and is currently reviewing. |
May | Phase 2 | Phase Change | Now Phase 2: Understand |
May | Phase 1 | Phase Update | ICANN acknowledged receipt of Advice. |
May | Phase 1 | Phase Change | Now in Phase 1: Acknowledge |
09 May | Phase 1 | Phase Update | SSAC published SAC125: SSAC Report on Registrar Nameserver ManagementSAC126: DNSSEC Delegation Signer (DS) Record Automation: https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-125126-0916-0508-2024-en.pdf. |