edugain-discuss - Re: [eduGAIN-discuss] Assessment of Malaysia/SIFULAN for eduGAIN membership

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

Re: [eduGAIN-discuss] Assessment of Malaysia/SIFULAN for eduGAIN membership

  • From: Peter Schober <peter.schober AT>
  • To: edugain-discuss AT
  • Subject: Re: [eduGAIN-discuss] Assessment of Malaysia/SIFULAN for eduGAIN membership
  • Date: Fri, 1 Jun 2018 11:53:02 +0200
* Rhys Smith <Rhys.Smith AT> [2018-06-01 11:43]:
> Section 5.1 - establishing the right to use a domain name via registration
> information in DNS.

That's an old (meanwhile fixed?) bug in the MRPS template, s/DNS/WHOIS/

> This is not an issue with this specific edugain application, but one
> all of us are going to have to deal with - with GDPR coming into
> force, the information available to us through WHOIS is (can be)
> severely restricted, so we either have to insist that every
> potential member increases the visability of the details of their
> entries in WHOIS, or we’ll need to start doing more programmatic
> proof of control of a domain (e.g. add a TXT record for us, etc)
> alongside our traditional manual WHOIS checks.

Since most/all of us will only ever be dealing with *organisations* --
not indvidual natural persons -- as domain/namespace owners there
should be no reason for WHOIS info to be redacted. GDPR does not
protect company info, only natural persons'.

But of course ignorance, overraction and stupidity have killed other
good things, so it might well be the case that WHOIS will become much
less usage in the future for all the wrong reasons.

Nick recently posted their policy document which moves InC to a purely
"domain control validation" schema. TBH I'm not prepared to go there
just yet (equating "I can manipulate this DNS domain" with "I am
rightfully making use of this namespace").


