There have been ongoing questions privately with regards to issuance of a 
e164.arpa domain. This is not against the BRs, but the definition of 
Reverse Zone Domain there is narrowed to ipv4/6.

SHA256: e0388e2582f2d657614b75dea820b3e865b55ac3060eb6e5918330773c2a98a3
Censys 
<https://platform.censys.io/certificates/e0388e2582f2d657614b75dea820b3e865b55ac3060eb6e5918330773c2a98a3>
 
crt.sh 
<http://crt.sh/?sha256=e0388e2582f2d657614b75dea820b3e865b55ac3060eb6e5918330773c2a98a3>

I have similar concerns as stated by Corey Bonnell 
<https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/LnOC7dpfQqQ/m/6IbkF9WDEgAJ>
 
in the Ballot discussion. The visible public discussion moves from 
forbidding all of .arpa to only rDNS, but there is no explanation for the 
narrow scope of ipv4/6.

For those unaware e164.arpa is a reverse lookup to a *telephone *in the 
same manner as ipv4/6 reverse lookups. I do not see why any of the 
validation concerns do not equally apply to this method.

What is everyone's opinion?

- Wayne

-- 
You received this message because you are subscribed to the Google Groups 
"[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/e2e3bafd-59c6-432f-b7fe-84c47b1c3f37n%40mozilla.org.

Reply via email to