WCAANWilling Citizens' Authority
for Assigned Names

The independent root

The root is an edited, signed zone.

WCAAN authorizes its contents. Tan's Network assembles the approved data, signs the resulting zone, and serves it to resolvers.

Composition and publication

1AssembleConventional delegations, selected compatible additions, and WCAAN decisions form the proposed zone
2ValidateAuthority, DNS data, expected prior state, and rollback state are checked
3SignThe complete zone is signed as one publication unit
4ServeAuthoritative servers publish the resulting serial

The operator must not apply an approved change to an unexpected prior state. If the live zone has changed since authorization, the instruction is refused and returned for reconciliation. This prevents a valid patch from producing an unapproved result when applied to the wrong base.

An emergency change may proceed before ordinary notice where delay would cause significant technical failure or downtime. It still requires authenticated authority, an exact temporary state, and an applicable rollback. Extraordinary does not mean unrecorded.

Current WCAAN delegations

Member delegation.cet

Registry policy and operation are held by CETNIC.

Active
Member delegation.cet.is

Registry policy and operation are held by CETNIC. The namespace is loaned by Tan's Network.

Active
Authority registry.wcaan

Registry authority remains with WCAAN. Public registration data is provided through RDAP and registry changes use EPP.

Active

The machine-readable delegation register is authoritative for the public classification recorded by this site. A missing historical decision reference means that no such reference has yet been established in the current public record. It does not invite us to invent one.

Delegation requirements

Authority

The filer must establish its right to bind the registry authority or affected member NIC.

Canonical names

Root data uses lower-case DNS A-labels and absolute names with a final dot. Display forms may also show the corresponding Unicode name.

Authoritative service

Nameservers and required glue must form a reachable, non-lame delegation without circular dependencies.

Exact state

The request must distinguish the current state, intended state, transition sequence, and safe rollback state.

Continuity

Transfers and material changes must identify how registrants, resolution, and public registry services continue during the change.

Evidence

Claims about authority, testing, readiness, or recovery must identify the evidence on which WCAAN may rely.

DNSSEC and trust material

Every WCAAN-managed root publication is signed. A secure child delegation must provide DS material that matches a published child DNSKEY and the intended rollover state. The filing must state the key tag, algorithm, digest type, digest, publication window, observation method, and rollback condition.

A rollover is evaluated as a sequence, not merely as two sets of keys. The proposed timing must leave enough overlap for caches and validators. Removing the final DS record changes the delegation from secure to insecure and therefore requires an explicit statement that this is the intended policy result.

WCAAN validates the proposed chain before issuing an implementation instruction. Tan's Network validates the built zone before publication and reports the resulting serial or refusal. Neither check proves that every recursive resolver has refreshed. Evidence must state what was actually observed.

Current publication evidence

This website is not connected to the root publication system. It therefore cannot honestly turn unknown operational state into a reassuring green badge.

Root serialUnavailable

No authenticated status feed is connected to this website.

Not asserted
Signing freshnessUnavailable

The website does not receive signer telemetry or an authenticated signature-age report.

Not asserted
Resolver reachabilityUnavailable

No public probe result is authenticated as WCAAN publication evidence.

Not asserted