[dns-operations] Verisign won't delete obsolete glue records?

Hugo Salgado hsalgado at nic.cl
Thu Mar 4 17:36:30 UTC 2021


On 11:38 04/03, Andrew Sullivan wrote:
> 
> The disadvantage of a nameserver-attribute arrangement is that, if the
> domain in question gets deleted, there isn't really a way within EPP
> to refuse that, because there's no necessary relationship between the
> nameserver attributes (they're just attributes, after all) and the
> domain object that is being removed.  So there's a greater opportunity
> to create lame delegations.

And I can't see how that could be a disadvantage, especially
knowing the problems with orphan glues in the NS-object model.
Artificially maintaining a name that has been deleted seems
worse to me.

We at .CL use NS-attributes, and in the case you describe we
take care of deactivating NS in every domain if it went out of zone.

At the end, the user that delegates its NS to other name needs
to take care of that relation. They can always create subdomain
names and going glue if the target IP still answers.

Best,

Hugo

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20210304/31a1aa80/attachment.sig>


More information about the dns-operations mailing list