Hello Everyone!

Post
I’m Marco, based in the Netherlands, and I work in the Internet/DNS space at SIDN Labs, the research group of the .nl domain registry.

I’ve been working with DNS for quite a while, mostly from the technical and infrastructure side, but I’ve recently become more interested in the domain industry and the things happening around buying, selling and discovering domain names.

One of the projects I’ve been working on recently is RFC 10023, which defines a simple DNS convention for signalling that a domain is for sale. I’m particularly interested in what this could mean for automated domain discovery, and I’m curious to hear how people in the domain community look at that.

Anyway, happy to be here and looking forward to learning from the discussions and meeting some of you!

Cheers,
Marco
 
Post
Welcome Marco!!! It is a true honor to have you here!!!

we are actually trying to build our own dns platform for HostMaria. The main push was to be able to enable DNSSEC by default :)
 
Post
what are your thoughts on dnssec?
I'm a pretty strong believer in DNSSEC.

.nl has one of the highest DNSSEC adoption rates among ccTLDs, and that's not entirely by accident. We've invested quite a bit over the years in making DNSSEC easy to deploy and in encouraging registrars to support it.

I think DNSSEC is an important building block for a more trustworthy DNS - although, of course, it's not a silver bullet.

DNSSEC is also much easier to deploy nowadays than it used to be. Good support in registrar dashboards and DNS software has made a big difference, taking away much of the complexity and making DNSSEC almost a matter of switching it on.
 
Post
I'm a pretty strong believer in DNSSEC.

.nl has one of the highest DNSSEC adoption rates among ccTLDs, and that's not entirely by accident. We've invested quite a bit over the years in making DNSSEC easy to deploy and in encouraging registrars to support it.

I think DNSSEC is an important building block for a more trustworthy DNS - although, of course, it's not a silver bullet.

DNSSEC is also much easier to deploy nowadays than it used to be. Good support in registrar dashboards and DNS software has made a big difference, taking away much of the complexity and making DNSSEC almost a matter of switching it on.

Awesome!! Finally we meet a person like you :) .. usually our industry reps can't care less about the DNSSEC. Well, for me, also, the main interest is to activate this so I (as a registrar) can register domains cheaper with my registries.

What is changing with DNSSEC at the moment? I recently read something on Twitter on this (can't recall). Is anything important coming that people in the domain and hosting industry should know about?
 
Post
What is changing with DNSSEC at the moment? I recently read something on Twitter on this (can't recall). Is anything important coming that people in the domain and hosting industry should know about?
Plenty of things are going on, but perhaps the most notable thing at the moment is the upcoming KSK rollover in the root zone, scheduled for 11 October. This is particularly important for operators of DNSSEC-validating resolvers. The new key should be picked up automatically by modern software through RFC 5011, although it is still a good idea to double-check that the new trust anchor is actually present - especially when upgrading software or packages. The new key should already be included in recent software releases and package updates.

Another notable development is that several older DNSSEC algorithms have been deprecated in recent years. Domains that are still signed using deprecated algorithms may no longer benefit from DNSSEC validation with modern software. They may continue to resolve, but effectively lose the protection DNSSEC is meant to provide. So the advice is simple: don't use deprecated algorithms, and make sure you're signing with currently supported ones.
 
Last edited:
Post
Also, was DNSSEC one of the reasons of recent denic downtime?
The outage was caused by a software bug in DENIC's in-house software used for DNSSEC signing during a routine key rollover, resulting in massive validation failures by resolvers. So, ironically, DNSSEC did exactly what it was supposed to do: reject invalid signatures. This was a particularly unfortunate and highly unusual chain of events, rather than something inherent to DNSSEC itself.
 
Post
The outage was caused by a software bug in DENIC's in-house software used for DNSSEC signing during a routine key rollover, resulting in massive validation failures by resolvers. So, ironically, DNSSEC did exactly what it was supposed to do: reject invalid signatures. This was a particularly unfortunate and highly unusual chain of events, rather than something inherent to DNSSEC itself.
curious, how SIDN is protecting yourselves from similar possible issues? .. is it possible to protect yourself at all from software bugs? .. more quality control?
 
Post
curious, how SIDN is protecting yourselves from similar possible issues? .. is it possible to protect yourself at all from software bugs? .. more quality control?
We have plenty of checks and safeguards in place, but ultimately you can never be 100% sure. That's why we have backups, a lot of monitoring, and... good coffee. :)
 
Post
We have plenty of checks and safeguards in place, but ultimately you can never be 100% sure. That's why we have backups, a lot of monitoring, and... good coffee. :)

have you ever rolled out a backup in SIDN history? :o .. I suppose with your scale - it is a monster task.. huhh
 

Thought for today (in Dutch)

Een sterke domeinnaam maakt een bedrijf niet goed, maar een goed bedrijf wordt er wel sterker van.
Back
Top