<<<
Chronological Index
>>> <<<
Thread Index
>>>
TLDs should always be Delegation Only
- To: sac053-dotless-domains@xxxxxxxxx
- Subject: TLDs should always be Delegation Only
- From: Chuck Anderson <cra@xxxxxxx>
- Date: Sat, 22 Sep 2012 10:53:34 -0400
I agree with the conclusions of the SSAC Report on Dotless Domains,
and would like to see rules that require all TLDs to be so-called
"Delegation Only" where they only contain Resource Records related to
the structure of DNS, e.g. SOA, NS, and related DNSSEC records at the
zone apex. All other record types such as A, AAAA, MX, SRV, LOC,
etc. should not be allowed in TLDs as they would present a significant
risk to the security and stability of the DNS.
The security issues are an especially compelling reason to disallow
dotless domains. The implementation of the trusted Intranet zone of
Windows & the existing practice of issuing HTTPS certificates for
"local use" Common Names that don't contain a dot are especially
worrying, as their historical security assumptions would be subverted,
leading to serious security and privacy breaches.
Chuck Anderson
Network Engineer
Worcester Polytechnic Institute
<<<
Chronological Index
>>> <<<
Thread Index
>>>
|