I'm a pretty strong believer in DNSSEC.what are your thoughts on dnssec?
I'm a pretty strong believer in DNSSEC.
.nl has one of the highest DNSSEC adoption rates among ccTLDs, and that's not entirely by accident. We've invested quite a bit over the years in making DNSSEC easy to deploy and in encouraging registrars to support it.
I think DNSSEC is an important building block for a more trustworthy DNS - although, of course, it's not a silver bullet.
DNSSEC is also much easier to deploy nowadays than it used to be. Good support in registrar dashboards and DNS software has made a big difference, taking away much of the complexity and making DNSSEC almost a matter of switching it on.
Plenty of things are going on, but perhaps the most notable thing at the moment is the upcoming KSK rollover in the root zone, scheduled for 11 October. This is particularly important for operators of DNSSEC-validating resolvers. The new key should be picked up automatically by modern software through RFC 5011, although it is still a good idea to double-check that the new trust anchor is actually present - especially when upgrading software or packages. The new key should already be included in recent software releases and package updates.What is changing with DNSSEC at the moment? I recently read something on Twitter on this (can't recall). Is anything important coming that people in the domain and hosting industry should know about?
The outage was caused by a software bug in DENIC's in-house software used for DNSSEC signing during a routine key rollover, resulting in massive validation failures by resolvers. So, ironically, DNSSEC did exactly what it was supposed to do: reject invalid signatures. This was a particularly unfortunate and highly unusual chain of events, rather than something inherent to DNSSEC itself.Also, was DNSSEC one of the reasons of recent denic downtime?
curious, how SIDN is protecting yourselves from similar possible issues? .. is it possible to protect yourself at all from software bugs? .. more quality control?The outage was caused by a software bug in DENIC's in-house software used for DNSSEC signing during a routine key rollover, resulting in massive validation failures by resolvers. So, ironically, DNSSEC did exactly what it was supposed to do: reject invalid signatures. This was a particularly unfortunate and highly unusual chain of events, rather than something inherent to DNSSEC itself.
We have plenty of checks and safeguards in place, but ultimately you can never be 100% sure. That's why we have backups, a lot of monitoring, and... good coffee.curious, how SIDN is protecting yourselves from similar possible issues? .. is it possible to protect yourself at all from software bugs? .. more quality control?
We have plenty of checks and safeguards in place, but ultimately you can never be 100% sure. That's why we have backups, a lot of monitoring, and... good coffee.![]()
We use essential cookies to make this site work, and optional cookies to enhance your experience.