GOpenCDR mirror operator terms
What you agree to when you enrol a mirror: enforce the IANA rule, never alter a zone, pass conformance, accept suspension, and use zone files only for serving.
What these terms cover
These terms apply when you enrol a mirror with GOpenCDR: a public or private resolver, an authoritative secondary or a full zone mirror that you run with the GOpenCDR mirror agent. You accept them when you enrol, in addition to the GOpenCDR terms and the acceptable use policy.
They cover the open community tier, which any mirror that passes conformance can join. The certified tier, which puts a mirror in GOpenCDR's default pool, needs a separate signed operator agreement and a data processing agreement, with yearly audits and unannounced spot checks.
The five rules
1. IANA always wins
Never answer for a name that exists in the IANA root with anything but the IANA answer. The mirror agent enforces this: it verifies the IANA root itself, refuses to overlay any name in it whatever a bundle says, and withdraws an overlay TLD the moment it appears there. Do not disable, patch around or override that behaviour, and do not serve GOpenCDR zones from a resolver the agent does not manage.
2. Never alter a zone
Serve only zone versions the agent has verified, with their ZONEMD and their DNSSEC chain intact, exactly as published. Do not add, remove or change records, do not rewrite NXDOMAIN, do not inject answers, do not strip DNSSEC, and do not send EDNS Client Subnet upstream. A validating resolver must validate GOpenCDR names against the anchors the agent installs.
3. Pass conformance
A mirror is admitted to a tier, and stays there, only while it passes the automated conformance suite: it validates DNSSEC, serves only verified zone versions, enforces the IANA rule, applies a withdrawal within one hour and serves the current serial within 15 minutes. GOpenCDR probes it continuously. A mirror that fails leaves its tier automatically and returns once it passes again.
A public resolver must also run behind response rate limiting, with minimal ANY answers (RFC 8482), DNS cookies and caps on amplification, and apply source address validation where the network allows it. An open resolver without these is an amplifier aimed at somebody else.
4. Accept suspension
We may suspend your enrolment at once and without prior notice where your mirror fails conformance, breaks these terms, serves wrong data, is compromised or is used for abuse, or where a court, an authority or a collision with the IANA namespace requires it. Suspension revokes the agent's credentials and its access to zone files. We tell you why, and you may ask for a review as the GOpenCDR terms describe. Suspension is not a penalty. It protects everyone who depends on the namespace.
5. Zone files only for serving
TLD zone files are served to enrolled mirrors so that they can answer queries. Use them for that and for verifying them, and for nothing else. Do not publish them, pass them on, sell them, mine them, market to the registrants in them or build lists of registrations from them. When your enrolment ends, delete every copy.
The root zone is public, and this rule does not cover it. A TLD may make its own zone public, or restrict it to certified mirrors.
The agent
We grant you a free, non-exclusive, non-transferable licence to install and run the mirror agent, and the configuration it renders, on systems you control, for as long as your mirror is enrolled and only to operate it. The agent is proprietary. Do not modify it, redistribute it or reverse engineer it beyond what Sections 69d and 69e of the German Copyright Act allow. The licence ends with your enrolment.
Enrolment uses a single-use token. After that, the agent signs every request with its own key; each signature covers the request body, expires within a minute and is accepted once. Keep the key and the token secret, run a current signed release of the agent, which checks the signature of every update before installing it, and tell us at once if a key may be exposed.
The agent reports which zone versions and serials it serves, the results of its own checks, its version and its health. It sends nothing about the people who use your mirror.
The people who use your mirror
You operate your mirror, and you are the controller for anything it records about its users. Publish your own privacy information if the mirror is open to the public. To be admitted to the default pool, a mirror keeps no log that links queries to client addresses for longer than 24 hours, and then only for debugging, and reports only aggregate statistics with minimum counts. We recommend the same for every mirror.
What we hold about you as a mirror operator is described in the privacy notice.
Names and badges
While your mirror is enrolled and passes conformance, you may say that it serves GOpenCDR and show the badge of its tier. Do not suggest that you are GOpenCDR or Gelhaus Solutions, or that a mirror outside the default pool is part of it.
Ending an enrolment
You may retire your mirror at any time from the portal. We may end an enrolment on any ground for suspension, or where GOpenCDR changes or ends the programme. When an enrolment ends, the agent's credentials are revoked, the licence ends and every copy of a TLD zone must be deleted.
Everything else
Enrolment is free. No warranty and no service level apply, in either direction, and liability is as the general terms of service set it out: for what is given away, it is limited to intent and gross negligence (Section 521 BGB). These terms may change through the process in the general terms; an enrolled operator is told of a material change at least six weeks before it takes effect.