#dnssec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dnssec, aggregated by home.social.
-
@bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.
-
@shaft C'était pas dans le registre en juillet @bortzmeyer #IANA #DNSSEC
-
@shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)
-
Oops, we forgot to announce Cascade v0.1.0-beta6 'Leonard Shelby' last week!
This release contains a host of bug fixes, further improvements in memory usage, and a new feature: diff purging! Cascade can now trim diffs representing old versions of zones, so it takes up less space on disk.
As always, thanks to @bortzmeyer, @oli, @jpmens and others for providing valuable feedback throughout!
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta6 for more details.
-
ECH aktivieren: Encrypted Client Hello in nginx mit OpenSSL 4.0, sechs Domains und ein gemeinsamer Deckname
Der Servername im TLS-Handshake bleibt für jeden Netzwerkbeobachter sichtbar, selbst wenn DNS-Anfragen längst verschlüsselt laufen. Mit OpenSSL 4.0 und einem gemeinsamen Deckname über mehrere unabhängige Domains hinweg lässt sich das schließen, wenn eine Entscheidung nicht falsch getroffen wird: der öffentliche Name.https://www.kernel-error.de/2026/08/17/encrypted-client-hello-nginx-openssl-4-public-name/
-
Докрутил до более-менее рабочего состояния. Не падает при нагрузке, резолвит и домены без ipv6 ns-серверов.
Переключил трафик от небольшой сети ~100 пользователей через кэширующий dnsmasq - полёт нормальный.
-
Один DNS‑запрос породил 329 запросов. Я полез разбираться, куда они все ушли
Один DNS‑запрос. Пустой кеш. И 329 исходящих запросов вслед за ним. Сначала я решил, что где‑то неправильно понял цифры. Потом полез разбираться и выяснил, что recursive resolver внутри делает намного больше работы, чем видно по обычному dig . Разбираю, откуда берутся эти сотни запросов, при чём здесь CNAME, glue, DNSSEC, IPv6 PTR и почему разные версии BIND на одном и том же запросе могут отличаться почти в три раза.
https://habr.com/ru/articles/1070280/
#DNS #BIND #recursive_resolver #DNSSEC #IPv6 #PTR #cold_cache #CNAME #Wireshark #IETF
-
Špatná Správa!
Správa Železnic, státní organizace, opět rozbila svůj #DNSSEC. 🙄
https://dnsviz.net/d/www.spravazeleznic.cz/dnssec/ -
Keyoxide: den OpenPGP-Schlüssel an Online-Identitäten binden, vier grüne Haken und ein rotes Kreuz
Ein neuer GPG-Schlüssel wirft die Frage auf, woher irgendwer wissen soll, dass er mir gehört. Das Web of Trust ist tot, Identity Claims füllen die Lücke: Claims in der Selbstsignatur, Proofs an DNS, GitHub und Matrix. Mit vier grünen Haken, einem roten Kreuz und einem CORS-Bug.https://www.kernel-error.de/2026/08/02/keyoxide-openpgp-schluessel-an-online-identitaeten-binden/
-
-
A sad lesson from a few years of operating local #DNS resolvers in my infrastructure - #DNSSEC validation requires enormous resources to work reliably due to vast extra records it needs to pull from DNS for each validation and required computing power.
Forget about DNSSEC validation in
systemd-resolved,dnsmasqorunboundon home routers, it will just cause periodic and apparently unexplained delays and choke overall DNS resolution.On firewalls like #OPNsense it also would work only server-class devices, any of the desktop-class fanless hardware won’t work reliably for DNSSEC validation even if they can perfectly handle production-class proxy and firewall traffic.
Probably what only makes sense is a dedicated Unbound validation server, a separate container or jail but running within a proper hardware server with tons of memory and CPU. But then I found out that it’s much easier to use non-DNSSEC caching resolvers on perimeter devices that forward queries to Quad9 ECS resolvers[^1] which already do DNSSEC validation.
The only missing bit is that I think my local resolvers don’t forward the DO bit downstream, but that I need to still check.
[^1]: https://quad9.net/service/service-addresses-and-features/#ecssec
-
#RFC 10026 [and #BCP 246]: Operational Recommendations for #DNSSEC Delegation Signer (DS) Automation
https://www.rfc-editor.org/info/rfc10026/ -
Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.
Many thanks to the security researchers who responsibly reported these issues.
Release details: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-
@bortzmeyer @oli @jpmens For context, we’re now in “signing co.uk on a regular laptop” territory, with more improvements to come. #DNS #DNSSEC
-
It's still Friday and we're still doing a Cascade release, so here's 0.1.0-beta5 'Got that holiday feeling'. 🏖️
In this release we're giving you more speed improvements by parallelizing sorting and more memory reduction by improving the handling of NSEC(3) in incremental signing. You can also track all of these improvements with newly introduced metrics.
Thanks again to @bortzmeyer, @oli and @jpmens and others for providing valuable feedback!
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta5
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
@bortzmeyer @shaft QOTD
> Yes, following DNS stuff on Mastodon is now part of maintaining DNS...
Petit jeu : qui est l'auteur ?
La réponse
https://mail-archive.com/dns-operation[email protected]/msg09228.html
#dns #dnssec #ccTLD -
QOTD
> Yes, following DNS stuff on Mastodon is now part of maintaining DNS...https://mail-archive.com/dns-operation[email protected]/msg09228.html
#dns #dnssec