DNSSEC and Provisioning in ENUM: Future Directions and Best Practices
E N D
Presentation Transcript
ENUM WG • Possible Future Directions • DNSSEC • Provisioning • NAPTR management/DNS content control • Name server setup
DNSSEC issues for ENUM • NOT DNSSEC protocol goop! • NOT Political stuff like who “owns” a key • Best common practices for stuff like: • Signing policies • Key lengths, signature expiry times • Howto for key rollover and/or key management • Scaling: optimal size for signing • Signed and unsigned parts of the tree? • What does this mean for ENUM clients?
Provisioning Issues • Likely telco involvement in registrations • e.g. Number cancellation or portability • Telco says “this number is not valid anymore” • May be helpful to have a standard way for a telco to express this • EPP Schema? • Information flow • To registry? To Registrar? To Registrant? • Some or all of these?
DNS Content Management • Fine-grained control of NAPTR order & preference fields • BCP on how applications should update the DNS? • Is it OK to mess with order & preference of existing NAPTRs? • What should DNS provider to if it encounters a conflict?
Name Server Setup • Have an explicit document from the WG recommending how name servers for ENUM should be set up? • Redundancy, no SPoFs • Recursion disabled • Minimal services on name servers • Essentially smashing RFC2870 & RFC2182