thats not really the point of our critics. a) changes only be made by members????
as every DE-domainowner is our customer and we are responisble to him about the security of his domainname we must assure that changes are made in a verifyable and accountable way. It is important that there is a documented responsibility.
b) technical solution - RIPE's solutions are working really good, DENIC's past solutions are poor
no comment.
c) change in interfaces not acceptable
d) contact info's, especially phone and fax, are REALLY important for
changes in interfaces are sometimes necessary. But I am with you that this should happen very rarely and should be prepared very well and people should be informed very soon -- but we tried to make all this. the
hostmasters to inform each other about technical probs. If this could be against German's laws, just make these fields optional.
we are only allowed to publish these things if the custoumer have signed that he allows the publishing. Currently we think that from nearly none of the persons in the RIPE-DB this allowence is there. For the future we plan to let the people the choice to publish these data.
e) putting so named "non-operational data" or "test data" which is incomplete and partly incorrect in production systems (it IS in productionis - just do an whoi-query...) is not acceptable
sorry I don't understand these point. Maybe you can show me an example of these "test data".
f) plans making life for non-members harder -> DENIC tries to get more payin' members????
As we are working on a costrecovery base (non-profit) more members don't means automatically more income. But surely are we are interested in organisations taking the responsibitlity and sharing the risk to run the German Registry as a self regulating body for the benefits of the German Internet Community.
g) plans to charge for person: and role: records? h) to be continued...
Regards Sabine
pls see
Greetings from Germany
speaking for DENIC ;-). I will try to comment about the reasons why we have (or even must) done the migration.
First of all I want to try to summarize the problems we are faced in the past and then I will come to an explanation of the solution we choose.
There were a lot of discussions in the past about domain-objects in the RIPE-database and that they cause too much capacity for RIPE to maintain their database for this amount of objects.
There was a common understanding that RIPE is not a service provider for domainregistries like ccTLDs but there were indeed suggestions to offer or assist us in this kind of service.
There were a lot of pressure from our dataprotection office that due to our business we pubish data (or we urge provider to puplish data of
customers) which is not allowed to publish under German data protection laws. Mainly the existence of the inverse query feature and the
of data like phone-, faxnumbers and email addresses was critisized.
We have had also a lot of discussions about the issue with other ccTLDs and with people from the EU commission. The fundamental outcome of these discussion was that there is no real issue to export personal data from the coutries to acentral database and that this should therefore stopped very soon. If the data is stored locally everybody can impose individually there dataprotection laws. Nevertheless there should be a central entrypoint to look for domain-data and therefore we support the RIPE referal mechanism and are looking together with other ccTLDs and the db-wg from RIPE at solutions like using the SRV-RR for whois-queries (see rfc2782 for a documentation)
So as I pointed out above there was no other solution than to migrate
domainobjects to a DENIC based domainquery mechanism. People who followed the discussion know that DENIC is on there way out of RIPE. Actually it was a dicission made by the RIPE db-wg in Amsterdam (February?) that
should be no domainobject in the database after June 30th.
Why do we publish less data than RIPE does?
I have tried to explain it also above due to German dataprotection laws we are allowed to publish only "necessary data" without formal agreement with the applicant.
Whats necessary concerning a domainname?
We agreed with the people from the dataprotection office that there is no necessity to no more about a admin-c of the domain than his address because if you need for legal issues to come in contact with him thats
only thing you need.
Concerning the tech-c and the zone-c he finally agreed that there is a necessity due to technical urgencies to publish phone and email-addresses and so we will implement this very soon.
I hope I have help you a little bit in understanding our position. I am really sorry that due to this discussion I get the feeling that people felt we are doing things without thinking or good reasons or just to make them angry. I hope you see there are - as usual - two sides of a medal and you see know the other side a little bit better,
Regards Sabine
I'm sorry for that, received a mail in german and replied.... once again in english:
I'd like to see a common procedure against the behaviour od DENIC. There are lot's of problems with the DENIC's solution, and if you
the past working of DENIC, you would really wish that there are no domain or person or role-objects in a database controlled by them.... The current solution by RIPE (for the Handles) works great. Most of us developed tools, webinterfaces, mailrobos and so on to deal with the procedure of creating, updating and deleting RIPE-Handles. All of us could live with a change of the email-adress to send the requests to, but not with totally new formats and and totally different concepts. It would be a good idea for DENIC to take the (really great working) RIPE-solution. The manner aof DENICs working now is inacceptable. Anybody making whois-querys with one of the uncountable webinterfaces gets the cripled contact data displayed. How the not with blindness strucked of us have seen, there is lots of data missing in the persons:s and role:s-data: remarks, mnt-by, phone, fax, trouble, notify, changed and (for the role:s) admin-c and tech-c. On Example: in our role-handle (compare whois -h NOC54-RIPE against whois -h NOC54-RIPE) is described how to make updates and who to cantact for whatever. This info is now missing. Remember: this (in DENICs words "non-operational data" or "just a test") criple data is displayed whenever you query a german domain! The most people won't hav the idea to query for the domain and then for the person:s and role:s, and I'm sure that even no webinterface to whois does so. This means tons of senseless work for us! It is really inacceptable insolence by DENIC to take data out of the RIPE-Database, changing it and then publishing it! With RIPE this is inconceivablily, have a look at their policy. I'm not sure if this is not against german or europeen laws, but I'm not a lawyer. If I think of
future, all domain:s, person:s and role:s at DENICs database... beam me back a few years, please. Putting the domain:s in DENICs own database is acceptable. There is no really change for us (ok, I had to add two exra lines to our whois-webinterface's code...), because we register Domains through DENIC or resellers (most of us are not members of DENIC because this is really expensive, so we are depend on resellers). With person:s and role:s-objects, surely all of us are working directly with the RIPE-Database. It is inacccetable if changes will only be possible by DENIC's members. This means weeks or eve months of handwork for us. Then the resellers will complete their (mail-)interfaces for changing , and parallel tio doing lots of work by hand we have to completely redevelop our tools, webinterfaces, mailrobos and so on!!!
This can not be the way to our future.
Let's join to make DENIC know that this is inacceptable. Contact your DENIC reseller and tell them what you think about this. They control DENICs board...
Greetings from Germany
This is a list in English.
What did you write?
We are happy to announce that we have successfully completed the first phase of migrating .de domain objects and related objects to DENIC's own whois database. Now there are no .de domain objects in RIPE whois database except for the top level one.
Normal operation of our database has been resumed at 9:30am, Central European Summer Time.
If you have any question, please reply to
-- Filippo Portera
-- Robert Martin-Legene
