Keltounet,
@Keltounet@mastodon.social avatar

@bortzmeyer @jpmens hello friends, what the current/recommended key scheme for dnssec? still using rsa/nsec3 and I want to move to EC.

Might even move to knot.

cstrotm,
@cstrotm@mastodon.social avatar

@Keltounet @bortzmeyer @jpmens

I would recommend

ECDSAP256SHA256 with NSEC

unless there is a strong requirement to use NSEC3

Keltounet,
@Keltounet@mastodon.social avatar

@cstrotm @bortzmeyer @jpmens if NSEC is now the default, then that's what I have now :)

jpmens,
@jpmens@mastodon.social avatar

deleted_by_author

  • Loading...
  • Keltounet,
    @Keltounet@mastodon.social avatar

    @jpmens Yep, I made the old key inactive but it was still in the DS. Fixed.

    jpmens,
    @jpmens@mastodon.social avatar

    deleted_by_author

  • Loading...
  • Keltounet,
    @Keltounet@mastodon.social avatar

    @jpmens bind itself.

    Keltounet,
    @Keltounet@mastodon.social avatar
    jpmens,
    @jpmens@mastodon.social avatar

    deleted_by_author

  • Loading...
  • mwl,
    @mwl@io.mwl.io avatar

    @jpmens @Keltounet

    SERVFAIL on my resolver (BIND/dig).

    Adding +cd fixes it, so: DNSSEC fail. Sorry, Ollivier!

    Keltounet,
    @Keltounet@mastodon.social avatar

    @mwl @jpmens damn, I need to check then. Dnsviz does like too though.

    shaft,
    @shaft@piaille.fr avatar

    @Keltounet @bortzmeyer @jpmens Algorithm 13 (ECDSA-P256-SHA256) is recommended. Something like half of domains use it nowadays.

    jpmens,
    @jpmens@mastodon.social avatar

    deleted_by_author

  • Loading...
  • Keltounet,
    @Keltounet@mastodon.social avatar

    @jpmens @shaft @bortzmeyer is Ed25519 still considered too new or that there is no significant advantages over ecdsa?

    jpmens,
    @jpmens@mastodon.social avatar

    deleted_by_author

  • Loading...
  • shaft,
    @shaft@piaille.fr avatar

    @jpmens @Keltounet @bortzmeyer As of RFC 8624 (2019), ed25519 is only "RECOMMENDED" for signing (vs. "MUST" for algo 13) so yeah, some older stuff might not be happy with it :/

    Keltounet,
    @Keltounet@mastodon.social avatar
    Keltounet,
    @Keltounet@mastodon.social avatar

    @jpmens @shaft @bortzmeyer ZSK/KSK rollovers done on ns0, both in "13 2" now. knot will wait for later on ns0, ns1 is already running knot anyway. Funnily enough, I upgraded ns3 to FreeBSD 13.2 too :)

    jpmens,
    @jpmens@mastodon.social avatar

    deleted_by_author

  • Loading...
  • shaft,
    @shaft@piaille.fr avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • InstantRegret
  • slotface
  • osvaldo12
  • kavyap
  • khanakhh
  • Durango
  • megavids
  • everett
  • tacticalgear
  • modclub
  • normalnudes
  • ngwrru68w68
  • cisconetworking
  • tester
  • GTA5RPClips
  • Leos
  • anitta
  • provamag3
  • JUstTest
  • lostlight
  • All magazines