Security and Stability Advisory Committee (SSAC)
本内容仅提供以下语言版本
- English
SAC126 | Executive Summary for DNSSEC Delegation Signer (DS) Record Automation
[PDF, 782.85 KB]
This report focuses on the management of Delegation Signer (DS) records as one of various obstacles to the deployment of Domain Name System Security Extensions (DNSSEC). DS records connect a child zone’s DNSSEC public key and signatures to the chain of trust provided by its parent zone (e.g., a zone corresponding to a top-level domain). DS record provisioning can be largely automated when the domain’s DNS service and the sponsoring registrar function are operated by the same supplier. Otherwise, the steps in the process for transferring DNSSEC key information to the parent are performed separately, often by a human (typically, the registrant). This non-automated “registrant-centric” method has several drawbacks, including the possibility for error, insufficient technical knowledge, and undue time burden, all of which may hinder DNSSEC deployment or, if domain owners successfully complete all necessary steps, result in failure nonetheless.
Since various options are available for performing DS provisioning, the SSAC discusses these various methods to help the domain name industry develop and use best practices for automated management of DS records.
Recommendations
- Recommendation 1: If a registry or a registrar wishes to implement DS automation for third-party DNSSEC operations, the current recommended interoperable mechanism is CDS/CDNSKEY (RFCs 7344, 9615).
- Recommendation 2: ICANN Org should support registries and registrars who want to implement DS automation using the mechanisms from Recommendation 1, such as by facilitating a Fast-Track RSEP.
- Recommendation 3: ICANN org should facilitate the development of operational guidance for registries and registrars around the implementation of DS automation, in particular the operational aspects outlined in section 4.4.

