govuk-infrastructure
govuk-infrastructure copied to clipboard
Put data.gov.uk on the Public Suffix List
What
Submit an amendment to the PSL for adding data.gov.uk to the private section. Work done so far:
- https://github.com/publicsuffix/list/pull/1956
- https://github.com/alphagov/govuk-dns-tf/compare/add-data-gov-uk-psl
Why
We manage the delegation of subdomains of data.gov.uk (e.g. guidance.data.gov.uk). Ordinarily, certificate authorities (CAs) require validation records to be added to the subdomain itself (DNS based verification), but because we haven't added data.gov.uk to the public suffix list yet, some CAs might require validation records to be added directly under data.gov.uk.
Reason for PSL Inclusion (taken from https://github.com/publicsuffix/list/pull/1512 )
We need these domains to be in the public suffix list as each subdomain is specific to one distinct UK Government related agency or group, meaning cookie isolation is required between all.
Some cloud providers also use the public suffix list to allow use of said domains on their platform. As each user agency or group of one of the sub domains is free to chose their provider, inclusion on the list will allow them to have a free choice of provider.
All of these domains are registered for over 2 years, they will exist for perpetuity as they exist to convey information to the public on behalf of the UK Government.
Original Trello card Apologies if I haven't followed a process for adding to this board but I wanted to update the relevant work trackers to reflect the decision on who is going to continue with this work.