PowerDNS, to random
@PowerDNS@fosstodon.org avatar
shaft, to random
@shaft@piaille.fr avatar

Lol, KPN (looks like a Dutch ISP) switched from old algorithm 7 to old algorithm 7 🙃

Algorithm 7 (RSASHA1-NSEC3-SHA1) is not recommended for #DNSSEC signing (RFC 8624, section 3.1). It's place is in a museum

https://mastodns.net/@diffroot/112560492075070043

jpmens, to random
@jpmens@mastodon.social avatar

Twelve years ago I was invited to present on #DNSSEC in Moscow. Quite the show actually: we had simulataneous translators (think: EU parliament) who translated my English to Russian and back for questions from the audience.

Imagine my surprise when I met @krisbuytaert there: he too had been invited to give a talk.

The stay was great: it allowed me to brush up on my Russian: I learned how to pronounce 'nyet'.

#historicNotHystericToot #springCleaning

krisbuytaert,
@krisbuytaert@mastodon.social avatar

@jpmens look what I found ;)

ascherbaum,
@ascherbaum@mastodon.social avatar

@jpmens @krisbuytaert Moscow is a nice city, all in all. Shame we won't go there for a long time.

As of now I rather see this UA conference happening which was canceled in 2020 :-(

PowerDNS, to random
@PowerDNS@fosstodon.org avatar
jpmens, (edited ) to random
@jpmens@mastodon.social avatar

"Because of the lack of clear signals of general adoption of DNSSEC over three decades, is it time to acknowledge that DNSSEC is just not going anywhere? Is it time to call it a day for DNSSEC and just move on?"

https://blog.apnic.net/2024/05/28/calling-time-on-dnssec/

davidnewman,
@davidnewman@mastodon.social avatar

@gjherbiet @jpmens @bortzmeyer @icing Been awhile since I looked, but do either Bind or NSD have built-in automated key rotation?

There are add-on scripts to do this, and it’s not that hard to roll your own. But until automated key rollover is built in to major authoritative servers then IMO DNSSEC will remain stuck in neutral.

jpmens,
@jpmens@mastodon.social avatar

@davidnewman @gjherbiet @bortzmeyer @icing

NSD has never signed so 'no' there.

BIND and Knot-DNS have KASP.

Tutanota, to privacy
@Tutanota@mastodon.social avatar

Protecting your doesn't stop with our world's first post-quantum email . ⚛️🔒

Tuta uses and to keep you secure. 💪

To learn more 👉👉👉 https://tuta.com/blog/tutanota-uses-dane-on-top-of-ssl-pfs

Tutanota,
@Tutanota@mastodon.social avatar

@iuvi Hi there, you can create accounts and access them through Tor! We even created a tutorial on YT which is available here: https://youtu.be/oXv3llPIfvo

iuvi,
@iuvi@mastodon.social avatar

@Tutanota sweeeeeet! Sorry for that, not long time ago it was not possible, but now i'm glad to know !

LGS, to random
@LGS@friendsofdesoto.social avatar
bert_hubert, to random
@bert_hubert@fosstodon.org avatar

This is quite rare - the C root-servers are out of sync with the rest of the world by 3 days. Since that time there have been no changes in the root zone, except for DNSSEC signature updates. It appears all C instances (operated by #cogent) are serving an outdated zone. For now this has no operational impact, but that might change #DNSSEC

woody,

@bert_hubert

Cogent is in the midst of three different peering disputes, with Tata, NTT, and HE, so their connectivity is pretty limited at the moment. Most people cannot reach https://http://c.root-servers.org for instance.

There's been a lot of conversation in different channels about whether this is sufficient to call their competency to run a root into question.

bortzmeyer,
@bortzmeyer@mastodon.gougere.fr avatar

@bert_hubert Cogent's [lack of] information on its site:

kubikpixel, to internet German
@kubikpixel@chaos.social avatar

»Cloudflare-Alternative:
19 Cloudflare-Alternativen im Überblick«

Hat jemensch von euch Erfahrung mit eines diesen Alternativen oder gar sogar mit einer nicht aufgeführten? Wenn ja, welches könnt ihr aus welchen Argumente und Gründen empfehlen?
(Ich zweifle immer noch welches am "sichersten" und "daten sparsam" ist)

🌐 https://letsbecrazy.de/cloudflare-alternative/


#cloudflare #internet #websicherheit #dns #webdev #dnssec #alternative #frage #it

markusr,
@markusr@mastodon.social avatar

@kubikpixel https://www.keycdn.com/ hatte ich mal verwendet, ist aber schon sicher 5 Jahre her. Hat gut funktioniert. Kommt aber halt immer drauf an, was man will und benötigt. Alternative wäre ein VarnishCache, falls es nur um Caching geht.

kubikpixel,
@kubikpixel@chaos.social avatar

@markusr danke sehe ich mir mal genauer an, davon gehört/gelesen hatte ich schon aber nie verwendet 👍

PowerDNS, to random
@PowerDNS@fosstodon.org avatar
bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Point positif pour la sécurité nationale : 15 des 1031 domaines de gouv.fr sont désormais signés avec #DNSSEC, dont celui de Dati, crucial pour la nation https://botsin.space/@DNSresolver/112438440953456482

(Notez que son copain Le Maire signe mais ne publie pas de DS pour finances.gouv.fr.)

bortzmeyer,
@bortzmeyer@mastodon.gougere.fr avatar

@shaft 85+ caractères et 11 composants ! J'appelle le Guinness.

shaft,
@shaft@piaille.fr avatar

@bortzmeyer Point positif, c'est du nuage français. (De chez Ubika, basé à Meudon : https://www.ubikasec.com/ )

PowerDNS, to random
@PowerDNS@fosstodon.org avatar
jpmens, to random
@jpmens@mastodon.social avatar

Authenticated #DNSSEC Bootstrapping in Knot DNS

"DNSSEC Bootstrapping allows the child zone operator to publish a signed copy of the child’s CDS/CDNSKEY records under a different name that has an existing chain of trust."

https://en.blog.nic.cz/2024/05/10/authenticated-dnssec-bootstrapping-in-knot-dns/

huguei, to random

We have new KSK for the root!
Today a mega ceremony was held where new HSMs were introduced and a new root key was generated in them. This key will be pre-publicated at the end of this year, and the rollover will be at the end of 2026. It'll be the third in the history of the DNS. The first was in 2010 and the second in 2017. #dns #dnssec

A TV screenshot of two HSMs
A person holding a box with cryptographic keys inside.

PowerDNS, to random
@PowerDNS@fosstodon.org avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • thenastyranch
  • magazineikmin
  • mdbf
  • GTA5RPClips
  • everett
  • rosin
  • Youngstown
  • tacticalgear
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • khanakhh
  • megavids
  • tester
  • ethstaker
  • cubers
  • osvaldo12
  • cisconetworking
  • Durango
  • InstantRegret
  • normalnudes
  • Leos
  • modclub
  • anitta
  • provamag3
  • lostlight
  • All magazines