TLDDNSSEC
What DNSSEC material the registry accepts for a domain under this TLD. model names the RFC 5910 data interface: ds_data takes DS records (ds_records on a DNSSEC change), key_data takes DNSKEY records (key_records), none takes neither. digest_types and algorithms are the IANA numbers the registry accepts on a record it is sent; digest_types is empty under key_data, where the registry computes the digest itself. ds_dnskey reports whether a DS record may carry the DNSKEY it was derived from. max_records is the most records the registry accepts on one domain, or 0 where it has stated no limit.
- objectType: string
Resource type identifier
- modelType: policy.SecDNSModelenum
RFC 5910 data interface the registry runs.
values- none =
Sec D N S Model None - ds
_data = Sec D N S Model D S Data - key
_data = Sec D N S Model Key Data
- none =
- digestType: array of integer
_types IANA DS digest types accepted on a DS record, ascending. Empty unless model is ds_data.
- algorithmsType: array of integer
IANA DNSSEC algorithm numbers accepted on a DS or DNSKEY record, ascending. Empty when model is none.
- dsType: boolean
_dnskey Whether a DS record may carry the DNSKEY it was derived from. Only ever true under ds_data.
- maxType: integer
_records Most DS or DNSKEY records the registry accepts on one domain. 0 means it has stated no limit.