Ben,

It doesn’t have to do with session lifetimes, but more about leveraging HTTP 
Gateways as an option for easier deployment with less custom development in the 
Cloud.  EoT has served the registry industry well for 20+ years and we’re 
looking to bring additional transport options for registries with EoH 
(draft-ietf-regext-epp-https) and EoQ (draft-ietf-regext-epp-quic) that have 
been implemented and are pluggable with EoT.  Extensibility of transports was 
envisioned when EPP was created in RFC 5730 that we’re looking to realize now.  
We consider EoH to be easier to deploy in the Cloud, thus the reference to more 
Cloud-friendly and we consider EoQ as an option to provide additional security 
and potentially performance improvements over EoT.

Thanks,

--

JG

[cid87442*[email protected]]

James Gould
Fellow Engineer
[email protected]<applewebdata://13890C55-AAE8-4BF3-A6CE-B4BA42740803/[email protected]>

703-948-3271
12061 Bluemont Way
Reston, VA 20190

Verisign.com<http://verisigninc.com/>

From: Ben Schwartz <[email protected]>
Date: Thursday, February 19, 2026 at 3:01 PM
To: James Gould <[email protected]>, "[email protected]" <[email protected]>, 
"[email protected]" <[email protected]>, "[email protected]" 
<[email protected]>, "[email protected]" <[email protected]>
Cc: "[email protected]" <[email protected]>, 
"[email protected]" 
<[email protected]>, "[email protected]" <[email protected]>
Subject: [EXTERNAL] Re: [regext] Re: draft-ietf-regext-epp-https-02 early 
Httpdir review


Caution: This email originated from outside the organization. Do not click 
links or open attachments unless you recognize the sender and know the content 
is safe.

Thanks, James.  This implementation strategy leaves me puzzled as to the 
motivating advantage of this design vs. EPP-over-TCP.  In either protocol, it 
seems that each session is handled entirely by a single backend host, so each 
session's lifetime is limited by the uptime of that host.

Is the design principally motivated by concerns about TCP connections being 
interrupted by connectivity issues closer to the client?  Or perhaps by a 
desire for access to DoS defense capabilities that are available in HTTP 
gateways but not in TCP load balancers?

--Ben Schwartz
________________________________
From: Gould, James <[email protected]>
Sent: Thursday, February 19, 2026 2:53 PM
To: Ben Schwartz <[email protected]>; [email protected] <[email protected]>; 
[email protected] <[email protected]>; [email protected] 
<[email protected]>; [email protected] <[email protected]>
Cc: [email protected] <[email protected]>; 
[email protected] 
<[email protected]>; [email protected] <[email protected]>
Subject: Re: [regext] Re: draft-ietf-regext-epp-https-02 early Httpdir review

Ben, The EPP session is terminated, and the client will establish a new EPP 
session. This happens today with EoT, where the clients will auto-reconnect. 
EPP is an idempotent, so a client can reconnect and resubmit the request. -- JG 
James Gould

Ben,



The EPP session is terminated, and the client will establish a new EPP session. 
 This happens today with EoT, where the clients will auto-reconnect.  EPP is an 
idempotent, so a client can reconnect and resubmit the request.



--



JG

[cid87442*[email protected]]

James Gould
Fellow Engineer
[email protected]

703-948-3271
12061 Bluemont Way
Reston, VA 20190

Verisign.com<https://secure-web.cisco.com/1CPTtLl89iRFAr-q5RNbooFdvbRhbH9TjArSNKq7nk5rMizZS6p1QVbn3XQRYYpHGKHABeJ7gPVps0TBI7_YW6hvJL3zJbcqyp5W_fQR9_VeV89vs-XZCgZB3HheSp0PXeEZAxHiz42xxIsle-U4kzXb-Fh5a0uGJHY7U9P3XCllCC6MqjBoJkyRsWnPAvBeysTNCoyvycb9vbdQ1IuASuD2MD0RaB7OWc8DzYP04pfBXs_fABZ1ycNDRc-GDDtFvcfRDNOjt2n__WCvIBYMGP_QKC0M5yQ5nJWmOwUJojP4/https%3A%2F%2Furldefense.com%2Fv3%2F__http%3A%2F%2Fverisigninc.com%2F__%3B%21%21Bt8RZUm9aw%2158QcFLMbpRmn2UyvjuttyfMdLY_f6GEzRcKRlx-FWb7qnH3r8z1Fp6IaRM_xm8iym48XjZQGaFxMwjXotYTu7hm80qo%24>



From: Ben Schwartz <[email protected]>
Date: Thursday, February 19, 2026 at 2:50 PM
To: James Gould <[email protected]>, "[email protected]" <[email protected]>, 
"[email protected]" <[email protected]>, "[email protected]" 
<[email protected]>, James Gould <[email protected]>, "[email protected]" 
<[email protected]>
Cc: "[email protected]" <[email protected]>, 
"[email protected]" 
<[email protected]>, "[email protected]" <[email protected]>
Subject: [EXTERNAL] Re: [regext] Re: draft-ietf-regext-epp-https-02 early 
Httpdir review



Caution: This email originated from outside the organization. Do not click 
links or open attachments unless you recognize the sender and know the content 
is safe.


For clarity, are you referring to "sticky HTTP sessions" as identified by 
session cookie, like [1]?



In this implementation style, what happens to active sessions when the assigned 
backend host is decommissioned or restarted?



--Ben Schwartz



[1] 
https://developers.cloudflare.com/load-balancing/understand-basics/session-affinity/#cookie<https://secure-web.cisco.com/1N01oc0WxOHh3sBhGS8MDrsT9hZ8XxlJKh1wB0nLS_Ig_96q0yszpCiN7efm-cW_RgQsLHOIdTSZrAwi9k__YOVTTK6TwsVxaf0tbMxOO38pvlwtWhgAWR6xLcuTGUK_K5vebYfITFFBJ6hwTp1kiA2rkOoYIZz5e8Z-02WjtZibKCr5oGF6iHewEtyVzuh30y59x9urzXY605atZIEjHFrSmbqxmWxToMNo-Y8x1qn-wHWeoLSXGGqfQbLakRGL0_6-bVp3r15wgotGfdSmXo93W3S802ZezqfK6CaBJfTY/https%3A%2F%2Furldefense.com%2Fv3%2F__https%3A%2F%2Fsecure-web.cisco.com%2F1Rk5-rXY-lwsUIUsrqMEGRdlHU16lOV6f-hRsK0PA9jLcqykeDOpWiBEruxwlDmN50UzoS1PNpr9vYNe_gFPyaDUryhg2JGJNfKUxE6o1CCDq780uex1YdOj32P6x8SPh2W9sq1REpwQx1HhaNMj0mMzXgBky8UDKFFed-pYRI40LJ8E9GVHt6lSk-X2bVJ-4g0V6b_GJhY9gvMiWvFscfXMZ7WHYx3dR1l8vt9zzVYKkX8KEO_qsRq7nkNUBc4iy_SgHXExrDhAxctdrAyjgdCNW8BiubgPkVmDDUPAPkTM%2Fhttps%2A3A%2A2F%2A2Fdevelopers.cloudflare.com%2A2Fload-balancing%2A2Funderstand-basics%2A2Fsession-affinity%2A2F%2A23cookie__%3BJSUlJSUlJSU%21%21Bt8RZUm9aw%2158QcFLMbpRmn2UyvjuttyfMdLY_f6GEzRcKRlx-FWb7qnH3r8z1Fp6IaRM_xm8iym48XjZQGaFxMwjXotYTuHl7UJ04%24>



________________________________

From: Gould, James <[email protected]>
Sent: Thursday, February 19, 2026 2:39 PM
To: [email protected] <[email protected]>; [email protected] 
<[email protected]>; Ben Schwartz <[email protected]>; [email protected] 
<[email protected]>; [email protected] <[email protected]>; 
[email protected] <[email protected]>
Cc: [email protected] <[email protected]>; 
[email protected] 
<[email protected]>; [email protected] <[email protected]>
Subject: Re: [regext] Re: draft-ietf-regext-epp-https-02 early Httpdir review




Andy,

Cloud HTTP gateways do support sticky HTTP sessions, which is what is used by 
draft-ietf-regext-epp-https.  With draft-ietf-regext-epp-https (EoH) there will 
be no need for a registry to build customer EoT gateways.

--

JG



James Gould
Fellow Engineer
[email protected] 
<applewebdata://13890C55-AAE8-4BF3-A6CE-B4BA42740803/[email protected]>

703-948-3271
12061 Bluemont Way
Reston, VA 20190

Verisign.com 
<https://urldefense.com/v3/__http://verisigninc.com/__;!!Bt8RZUm9aw!6I7U3WeXxoJ1-1H9FhV7rSddOKpsUUYE5r5HyVyqFvW_kf7WruW5ag5ZehSILvWRpdh4MLUlIAVy716i6bsgbcKWi2A$
 >




On 2/19/26, 2:17 PM, "Andy Newton" <[email protected] <mailto:[email protected]>> wrote:


Caution: This email originated from outside the organization. Do not click 
links or open attachments unless you recognize the sender and know the content 
is safe.




On 2/19/26 11:32 AM, Gould, James wrote:
> 3. The goal of draft-ietf-regext-epp-https is to provide a more 
> Cloud-friendly EPP transport, which means that Domain Name Registries (DNRs) 
> can be deployed in the public cloud without having to create custom EPP over 
> TCP (EoT) gateways. Use of the CONNECT HTTP method does not meet this goal.


I am befuddled by the "cloud-friendly" marketing as well. There are currently 
several RSPs who operate EPP using cloud providers, and many cloud providers 
have network load balancers that do TLS termination. From what I can tell, this 
draft doesn't work well with cloud-based web-application firewalls as each EPP 
operation uses the same path (or did I miss something), requiring custom 
parsing of the EPP XML bodies to do any app-layer routing.


Can you point to the specific technical challenge this is referencing?


Mario's message seemed to indicate that the desired connection model was about 
using reverse proxies which can be done on-prem or in a cloud. From that, I 
believe the issue he is solving is the lack of graceful session closure by the 
server in EPP. I am only guessing, but that seems like it could be solved with 
a simple EPP extension.


-andy, as an observer

_______________________________________________
regext mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to