Hi everyone,

To add to Jay's post, one other DPS item that we noted feed back from the community about, and are working on, was the Key Pair Generation section of the document.  It is our intention to improve that part of the DPS too and to also publish more technical details on the Key Pair Generation Procedure. This will be released as a separate document that will also include details of the scripts used. We are still working on testing the Key Pair Generation Procedure but hope to produce an outline of the technical details on the Key Pair Generation Procedure soon after the new version of the DPS is published.

Regards

Dave
On 24/06/2011, at 3:31 PM, Jay Daley wrote:

Hi all

Just to follow up on this - we aim to have a new version of our DPS ready to discuss by the end of next week.  To summarise discussions so far, it will have

- Document management (notifications are handled by the new list we set up).

- More details on site security using the most recent example from Dean as a guide.  That won't give the addresses of the sites but it will give their cities and suburbs.

- More details on our audit processes including what we audit and how frequently we audit.  We do want to commit to publishing the results but not until we have some processes in place around that, which may not be in time for the DPS or even the launch of DNSSEC.

- Different key sizes and M of N key splitting amongst NZRS staff and greater explanation of what that means for security of key backups.

- More details on the staff vetting.  This bit may be light to start with and change again later when we have received more detailed advice on what we can do in this regard.

regards
Jay

-- 
Jay Daley
Chief Executive
.nz Registry Services (New Zealand Domain Name Registry Limited)
desk: +64 4 931 6977
mobile: +64 21 678840

_______________________________________________
NZNOG mailing list
NZNOG@list.waikato.ac.nz
http://list.waikato.ac.nz/mailman/listinfo/nznog

-- 
Dave Baker
Chief Technology Officer
.nz Registry Services (New Zealand Domain Name Registry Limited)

e   dave@nzrs.net.nz
m   64 21 515 677
p   64 4 931 6978