Security and Stability Advisory Committee (SSAC)
SAC070 | Executive Summary for SSAC Advisory on the Use of Static TLD / Suffix Lists
[PDF, 954.72 KB]
This advisory addresses the security and stability needs surrounding the growing use of public suffix lists (PSLs) on the Internet.
Though there is no uniform consensus definition of what is a public suffix, here public suffix is defined as “a domain under which multiple parties that are unaffiliated with the owner of the Public Suffix domain may register subdomains. Well-known examples include .org, .co.uk, .com.au or .k12.pa.us. PSLs are static lists that help define these suffixes, supporting applications like web browsers in identifying security boundaries.
One core issue raised is the scalability and accuracy of PSLs, particularly as the number of new top-level domains (TLDs) expands. The PSL maintained by Mozilla Foundation is the most well-known, but managing and updating PSLs on this scale introduces challenges in data authenticity, timeliness, and potential errors. Without standardization, the reliance on static PSLs can lead to inconsistencies, impacting security, privacy, and usability. For instance, cookies in web browsers may be inadvertently exposed if the browser incorrectly identifies the suffix boundary, and the potential exists where users that have software using different versions from each other might result in fragmented user experience or inconsistency from each other.
Recommendations
- Recommendation 1: Recognizing alternatives to the PSL have been discussed (see Appendix A), the SSAC recommends the IETF and the applications community consider them for further specification and possible standardization through the IETF process.
- Recommendation 2: The IETF should develop a consensus definition of “public suffix” and other associated terminology (e.g. “private suffix”).
- Recommendation 3: To close the knowledge gap between registries and popular PSL maintainers, ICANN and the Mozilla Foundation should collaboratively create informational material that can be given to TLD registry operators about the Mozilla PSL.
- Recommendation 4: The Internet community should standardize the current approach to PSLs. Specifically:
- Recommendation 4a: ICANN, as part of its initiatives on universal acceptance, should encourage the software development community (including the open source community) to develop and distribute programming and operating system libraries implementing robust (i.e. authenticated, timely, secure, accountable) distribution mechanisms for PSLs. These libraries should be written across all common platforms and operating systems in a way as to ensure consistent and standard interpretation of a given PSL across all platforms.
- Recommendation 4b: Application developers should use a canonical file format and modern authentication protocols as specifications to this work.
- Recommendation 4c: Application developers should also replace proprietary PSLs with well-known and widely accepted PSL implementations such as the Mozilla PSL and the proposed IANA PSL (Recommendation 5).
- Recommendation 5: IANA should host a PSL containing information about the domains within the registries with which IANA has direct communication. Such a PSL would be authoritative for those domains.
- Recommendation 6: ICANN should explicitly include use and actions related to a PSL as part of the work related to universal acceptance

