📜 ⬆️ ⬇️

ICANN plan: the corporation proposed a new model for managing root DNS servers

ICANN's Root Server Management Advisory Council (RSSAC) has proposed a new DNS root zone management model . It provides for a decrease in the number of active CAs and the introduction of five new responsible structures. In more detail we tell about model under a cat.


/ photo Oliver Dean CC

How the root DNS server system is managed


For a long time, the system consists of 13 root servers, which are managed by 12 companies on the basis of agreements with ICANN. Among these organizations there are both independent and state. All decisions regarding the work of the COP, these companies make their own. A good example of how the coordination of the root server system works can be found in the CTO article of the RIPE NCC Internet Registrar Andrei Robachevsky .
')
Under this scheme, everything has been stably functioning for many years. However, in RSSAC they want to make the work of root DNS servers more “transparent” and organized.

What is the essence of the RSSAC sentence


RSSAC representatives say they have been analyzing the work of root server operators for a long time. And they came to the conclusion that the actions of the operators are, in fact, uncontrollable and based on trust. Therefore, they proposed to introduce a new model, which, in their opinion, provides greater transparency and security.

The main idea is to create a single structure of five functional units to manage everything related to the COP:

  1. Secretariat (Secretariat Function - SF). This unit is a kind of interface that connects root server operators and the Internet community. It will act as a platform for discussing technical issues and solving administrative tasks.
  2. Strategy, Architecture, and Policies Division (Strategy, Architecture, and Policy Function - SAPF). Here they will monitor the work of root DNS servers, propose plans for the introduction of new elements of the architecture to enhance the security, performance and scalability of the global system.
  3. Division of Delegation of Authority (Designation and Removal Function - DRF). Will conduct audits and make recommendations on the appointment of the CC operators and the termination of their powers.
  4. Department of monitoring and evaluating the performance of operators (Performance Monitoring and Measurement Function - PMMF). This structure will collect metrics and technical data on how productively each operator and the system as a whole work.
  5. Financial Division (Financial Function - FF). The financial component of the entire system will be regulated here. The authors of the plan propose to create a fund with the help of which interested parties will be able to allocate funds for research and settlement of emergencies related to the operation of root DNS servers.

This is what the new scheme of the system work on the RSSAC idea looks like:


During the presentation of the model, representatives of RSSAC Tripti Sinha (Tripti Sinha) and Brad Verd (Brad Verd) noted that its implementation will reduce the number of root DNS servers - some of them will be combined (but which and how many are still unknown). However, as the COP will be less, the speakers did not specify. According to them, reducing the number of root DNS servers will help improve the quality of services provided and control over them.

Community opinions


One of the residents of The Register in his comments at the site expressed doubts about the correctness of the idea of ​​combining root DNS servers. In his opinion, it will be easier for hackers to carry out attacks, since consolidation will simplify the procedure for selecting a target for hacking.

Some recalled the recent situation with the WHOIS , when ICANN tried several times to bring the service to work in accordance with the GDPR and met with resistance from the community and registrars because they could not think through the implementation plan for the idea. Because of this story, users have stated that transferring control over root DNS servers to ICANN is not the best solution.

However, there were those who thought that the whole idea was not bad, since a clearer management structure should speed up the resolution of security problems.

We note that it is not yet clear whether this proposal will receive any approval from the official structures and governments, because the future fate of the project remains unknown.



PS Additional materials from the First Corporate IaaS Blog:




The main direction of our activity is the provision of cloud services:

Virtual Infrastructure (IaaS) | PCI DSS Hosting | Cloud FZ-152 | Rent 1C in the cloud

Source: https://habr.com/ru/post/417771/


All Articles