Update .ck -- adding sld records to instantiate wildcard, no policy change #1435
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of Organization
Reason for PSL Inclusion
DNS verification via dig
Run Syntax Checker (make test)
Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration, and we shall keep the _PSL txt record in place
Submitter affirms the following:
For Private section requests that are submitting entries for domains that match their organization website's primary domain:
(Link: about propogation/expectations)
Description of Organization
Organization Website:
Individual, not acting on behalf of employer.
DNS architect at GoDaddy, member of DNS-OARC, IETF contributor.
No connection to request per se.
Improving entry by instantiating second level domains covered by the wildcard.
No change in policy.
Reason for PSL Inclusion
Not my domain(s), but I am submitting a list of entries for the CCTLD 'ck' at the second level, to enumerate entries that would otherwise be covered by the single wildcard entry '.ck'.
The purpose is to enable anyone using the PSL to generate accurate RPZ zone files.
RPZ (response policy zone) files are ordinary zone files, and as such, do not support wildcard interior labels like 'foo..example.com'. Enumerating the matching actual entries allows this to instead be 'foo.bar.example.com', if the only actual wildcard match was 'bar'.
No policy change results from this PR. The existing matching of wildcard vs literal SLD has the same level rules.
This is one of several similar submissions, for other CCTLDs which currently have only wildcard SLDs listed.
DNS Verification via dig
Not responsible for the domain, so cannot add these TXT records.
However, here is dig output demonstrating that the specific second level domains exist (as ENTs):
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz biz.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25520
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;biz.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 180 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:07 PDT 2021
;; MSG SIZE rcvd: 92
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz co.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44284
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;co.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 181 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:07 PDT 2021
;; MSG SIZE rcvd: 91
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz edu.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24238
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;edu.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 189 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:07 PDT 2021
;; MSG SIZE rcvd: 92
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz gen.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36797
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;gen.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 183 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:08 PDT 2021
;; MSG SIZE rcvd: 92
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz net.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49411
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;net.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 180 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:08 PDT 2021
;; MSG SIZE rcvd: 88
; <<>> DiG 9.16.13 <<>> @downstage.mcs.vuw.ac.nz org.ck. NS
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35504
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;org.ck. IN NS
;; AUTHORITY SECTION:
ck. 86400 IN SOA parau.oyster.net.ck. soa.oyster.net.ck. 2021083000 14400 900 1728000 86400
;; Query time: 181 msec
;; SERVER: 130.195.6.10#53(130.195.6.10)
;; WHEN: Tue Sep 28 00:25:08 PDT 2021
;; MSG SIZE rcvd: 92
make test
Test has been run, all results are "pass".