Overview
ISO/IEC 29168-2:2011 specifies procedures for the Object Identifier Resolution System (ORS) operational agency. It defines the mechanisms and criteria for selecting and approving the agency appointed as an ISO/IEC Registration Authority, the operational duties required to run the ORS, and ancillary topics such as DNSSEC (NSEC3) usage, domain transfer of .oid-res.org, and charging for services. The standard ensures consistent, secure DNS-based resolution and management of top-level OID nodes and supports navigation services defined in ISO/IEC 29168‑1.
Key topics and requirements
- Appointment and governance
- Formal appointment as an ISO/IEC Registration Authority.
- Nominations are accepted from ISO National Bodies or IEC National Committees.
- An Expert Group reviews nominees and recommends appointment to ISO/IEC JTC 1/SC 6.
- Minimum appointment term of three years with defined termination and transfer procedures.
- Operational responsibilities
- Provision of DNS zone files for specified OID nodes (see Clause 6) and the ORS root.
- Required DNS resource records: NS, DNAME, and NAPTR.
- Support for long arcs and addition of approved Unicode labels.
- Mandatory DNSSEC (NSEC3) support for relevant zone files.
- Support for navigation services such as COID, CINF, and RINF.
- Support levels and procedures
- Procedures for requesting ORS support for lower‑level OID nodes (class A/B/C provisions are referenced).
- Requirements for 24/7 operational availability, backup and recovery, data confidentiality, and non‑use of .oid-res.org for unrelated services.
- Domain transfer & charging
- Transfer of ownership of .oid-res.org to the appointed agency (free of charge) with potential fees related to DNSSEC key signing.
- Clause 8 addresses the basis for levying charges for different service classes.
Practical applications and who uses this standard
- Organizations that operate or plan to operate the ORS (ISO/IEC Registration Authorities and nominated agencies).
- DNS service providers and operators implementing secure OID resolution and DNSSEC (NSEC3).
- National standards bodies (ISO/IEC National Bodies), IT governance teams, and registry administrators managing OID namespace delegations.
- Implementers of OID-based services (e.g., COID/CINF/RINF consumers) that rely on authoritative, secure resolution of OID IRIs.
Related standards
- Rec. ITU‑T X.672 | ISO/IEC 29168‑1 - Object identifier resolution system (technical service description).
- Rec. ITU‑T X.660 series | ISO/IEC 9834 - Procedures for OSI Registration Authorities and object identifier management.
Keywords: ISO/IEC 29168-2:2011, ORS operational agency, object identifier, OID resolution system, DNSSEC NSEC3, .oid-res.org, DNS zone files, ISO/IEC Registration Authority.