Dear TPR WG Members,

 

Please find below the notes and action items from today’s meeting.

 

The next TPR WG meeting will be on Tuesday, 03 May 2022 at 16:00 UTC.


Best regards,

 

Emily, Julie, Berry, and Caitlin 

 

 

Action Items:

 

Discussion of Outstanding Items on TAC:

 

1. Recommendation 7 (TAC Security) Jim Galvin to suggest revisions to Sarah Wyld’s suggested text for WG members to review.

2.. Additional Candidate Recommendation xx under CQ b1 -- Staff to delete the recommendation.

3. Formerly Recommendation 6, now Recommendation 9: SME input on Recommendation 6.2: Jim Galvin to suggest some functional language for WG review.

4. Recommendation 13 --- Jim Galvin and Rick Wilhelm to consult with the RySG and either provide suggested alternative language or a rationale for why this recommendation should not be included.

 

Previous Action Items:

 

1. WG members are encouraged to review the overview of proposed response to Charter Question h2 (see page 13 and 14 here [docs.google.com]) and provide comments and/or suggestions.

2. WG members are encouraged to review the overview of proposed responses to EPDP Phase 1, Recommendation 27 “Wave 1” Report items (see document here [docs.google.com]) and add comments in the column “Additional Notes/Discussion”.

3. Staff to suggest a definition along the lines of Designated Agent as referenced in the COR.  Could say, “Working Group understands the Designated Representative to mean an individual or entity that the Registered Name Holder explicitly authorizes to obtain the TAC on their behalf.”

 

Notes:

 

Transfer Policy Review Phase 1 - Meeting #44

Tuesday, 26 April 2022 at 16:00 UTC

Proposed Agenda

 

1. Roll Call & SOI updates

 

2. Welcome & Chair updates

3. Upcoming milestones and deliverables for Initial Report:

 

Initial Report Delivery 15 June 2022:

 

Key Dates:

 

Upcoming Working Group Meetings:

3 May 2022

NACK

10 May 2022

Post-registration and post-transfer locks; Additional security measures

17 May 2022

Review of outstanding items

24 May 2022

Review of outstanding items

31 May 2022

Review of outstanding items

7 June 2022

Review of outstanding items

13 June 2022

ICANN74 session – Introduction to Change of Registrant (COR) - Phase 1(b)

 

Highlights:

4. Discussion of Outstanding Items on TAC (see summary in tab 1 here [docs.google.com] and working document pages 15-19 here [docs.google.com])

 

Row 11 -- Formerly Recommendation 3, now Recommendation 7 -- From Sarah Wyld, suggested text for Recommendation 7 (TAC Security) – See recent email:

 

Here is the current shared draft text [docs.google.com]

The Working Group recommends that ICANN org establish minimum requirements for the composition of the TAC (for example, minimum length, syntax, or entropy value) based on current applicable technical security standards. ICANN org may change these requirements in response to new or updated standards, but any changes to the requirements must go in effect with sufficient notification and time for contracted parties  to implement the necessary updates.

 

Here is my suggested updated version:

The Working Group recommends that Registrars and Registry Operators follow best practices for the composition of the TAC (for example, minimum length, syntax, or entropy value) based on current applicable technical security standards such as RFC9154 or subsequent or similar RFCs. These best practices may be updated in response to new or updated standards as appropriate.

 

Discussion:

ACTION ITEMS: Recommendation 7 (TAC Security) Jim Galvin to suggest revisions to Sarah Wyld’s suggested text for WG members to review.

 

Row 12 -- Additional Candidate Recommendation xx under CQ b1: If a Gaining Registrar requests a transfer and an inter-registrar transfer lock is in place, the transfer must not proceed.

ACTION ITEM: Additional Candidate Recommendation xx under CQ b1 -- Staff to delete the recommendation.

 

Row 13 -- Response to CQ b2: Compliance input: For Contractual Compliance to be able to enforce the requirements, all requirements must be clearly enumerated and described within the text of the policy.

Row 14 -- SME input on Recommendation 6.2: The Registry MUST securely store the TAC per the requirements specified in recommendation 3.  Recommendation text: “When the Registrar of Record sets the TAC at the Registry, the Registry MUST securely store the TAC using a one-way hash that protects the TAC from disclosure.”

ACTION ITEM:  Formerly Recommendation 6, now Recommendation 9: SME input on Recommendation 6.2: Jim Galvin to suggest some functional language for WG review.

 

Row 15 -- input on Recommendation 6.3: Compliance recommends detailing how this information must be provided and that the provision of this information must be documented.  Recommendation text: “When the Registrar of Record provides the TAC to the RNH or their designated representative, the Registrar of Record MUST also provide information about when the TAC will expire.”

Row 16 -- SME input on Recommendation 6.3: Consider developing standard easy to understand language for registrants around this additional info about when the TAC will expire, etc.

Row 17 -- Formerly Recommendation 9, now Recommendation 11: Compliance input: If this is an obligation to be added to the Transfer Policy for registries, Compliance recommends that the text in the policy explains what “clear” means (what actions this entails) so that Compliance is able to enforce it against registries where applicable. Recommendation text: “The working group recommends that the TAC MUST be “one-time use.” In other words, it MUST be used no more than once per domain name. The Registry Operator MUST clear the TAC as part of completing the successful transfer request.”

Row 18 -- Formerly Recommendation 11, now Recommendation 13: SME input on Recommendation 11.1: Suggestion to use hours instead of calendar days to avoid confusion.  Recommendation text:

 

13.1: A standard Time to Live (TTL)  for the TAC MUST be 14 calendar days from the time it is set at the Registry, enforced by the Registries. 

13.2: The Registrar of Record MAY set the TAC to null:

·         At any time in response to a request from the RNH.

·         After a period of less than 14 days by agreement by the Registrar of Record and the RNH.

ACTION ITEM: Recommendation 13 --- Jim Galvin and Rick Wilhelm to consult with the RySG and either provide suggested alternative language or a rationale for why this recommendation should not be included.

 

5. AOB