[Dnssec-deployment] Publishing DS records in WHOIS

Jim Reid jim at rfc1035.com
Fri Jul 30 04:10:27 EDT 2010


On 29 Jul 2010, at 23:52, Jay Daley wrote:

> Does anyone have any view on whether registries should publish DS  
> records in their WHOIS?

It's a very bad idea. And probably worse than useless. It will create  
confusion because there would be >1 place at the registry to find DS  
records, even if they are fed from the same back-end database. Looking  
for DS records in whois would be foolish if they're already in the DNS  
where they'll presumably be covered by an RRSIG?

whois is orthogonal to DNS and should remain that way. As a general  
rule, registries don't publish whois data in the DNS, so why put DNS  
data in whois?


More information about the Dnssec-deployment mailing list