social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #dns

[?]Tobi » 🌐
@leftover@punkstodon.de

Wenn du selber Services im Homelab hostes möchtest du nicht immer http://ip:port im Browser eintragen oder?

hostname.internal mit SSL Warnung nerven auch.

"Your connection is not private"

Wie du SSL-Zertifikate im Homelab über DNS-01 Challenge und Adguard-Home als DNS-Server einrichtest zeige ich dir hier.

2tap2.be/lokal-dns/

Lets Encrypt Logo

Alt...Lets Encrypt Logo

    [?]Codimp » 🌐
    @codimp@social.lithio.fr

    Pour une présentation DNS, est-ce que vous avez des exemples récents de "soucis", genre panne car 2 serveurs DNS seulement dans le même AS/même baie/même bandeau électrique comme BNP Paribas en 2017 ?

    Ou d'autres exemples amusant sur du DNS

    Le retoot aide la pédagogie ^^

    #DNS

      1 ★ 0 ↺

      [?]oldsysops » 🌐
      @oldsysops@social.dk-libre.fr

      tiens j'ai un nom de domaine (perso) qui s'est fait pirater et qui pointe vers un ns2.emailverification.info/ns1.emailverification.info ...

      bizarre (heureusement pas en "prod")

      une recherche rapide m'indique que je suis pas le seul...

        [?]Cdrik ⏚🌻 » 🌐
        @Bristow_69@framapiaf.org

        Je ne comprends pas pourquoi le site web de cette initiative de fourniture de DNS européens (qui inclut un filtrage enfant + antipub) n'est toujours pas traduite en plusieurs langues européennes 🤔

        joindns4.eu/

        Les DNS Grand Public :

        - Protective 86.54.11.1
        - Protective + Child Protection 86.54.11.12
        - Protective + Ad Blocking 86.54.11.13
        - Protective + Child Protection + Ad Blocking 86.54.11.11
        - Unfiltered 86.54.11.100

        Logo de DNS4EU, le 4 est en jaune, les lettres en gris.

        Alt...Logo de DNS4EU, le 4 est en jaune, les lettres en gris.

          🗳
          Alexandre :freebsd: boosted

          [?]BastilleBSD :freebsd: » 🌐
          @BastilleBSD@fosstodon.org

          If you run your own local DNS servers at home, do you: (select all that apply)

          Comment with your preferred DNS stack and privacy friendly DNS providers.

          Forward to ISP's DNS servers.:0
          Forward to a DNS service (1.1.1.1, 9.9.9.9, etc).:6
          Recursively resolve from root servers directly.:7
          Encrypt my DNS using DoH, DoT, etc.:7

          Closes in 2:12:53:51

            AodeRelay boosted

            [?]Larvitz :fedora: » 🌐
            @Larvitz@burningboard.net

            I self-host the DNS for my domains for more than 20 years now.

            2026 now finally was the year, where I decomissioned the last BIND server and replaced it with a PowerDNS, containerized in Podman :podman: and a SQLite backend.

            I already migrated the hidden-primariy to PowerDNS in 2022 (because of the REST API, compatibility with Traefik, easier DNSSEC handling and the higher flexibility) and now my secondaries are also migrated.

            Nontheless, BIND was one of the most stable pieces of technology that I've ever used. But it also felt a bit unwieldy and old-fashined ins some ways.

              JP Mens boosted

              [?]NLnet Labs » 🌐
              @nlnetlabs@social.nlnetlabs.nl

              We released Unbound 1.25.1 just seven days ago and now look at the changelog today. ❤️‍🩹🔥

              github.com/NLnetLabs/unbound/b

                [?]Stéphane Bortzmeyer » 🌐
                @bortzmeyer@mastodon.gougere.fr

                @danyork Any city (not too small, however). can do anything.

                  [?]🫧 socialcoding.. » 🌐
                  @smallcircles@social.coop

                  @h4ckernews

                  Yes, gnutella. I remember.

                  > For most was a file transfer tool. This categorization misses a basic function of the . At its core, Gnutella is just a peer-to-peer engine for blobs.

                  > We could have used it as a poor man's system, or a global metadata lookup table for key/value pairs, or a matchmaking service for your Unreal Tournament league, but that never really happened. Gnutella was good at providing file downloads that matched search queries, and that is what history remembers it for.

                    [?]gregR ☯ » 🌐
                    @gregr@mamot.fr

                    QOTD
                    > Technitium DNS Server est un serveur DNS open source complet : autoritaire, récursif, et relais.
                    @bortzmeyer revenez vite de vacances !

                      🗳
                      mc.fly boosted

                      [?]mc.fly [he/him] » 🌐
                      @mcfly@milliways.social

                      So question:
                      "how many authoritative name servers don't support encryption?"

                      The internet claims that this is >95%.

                      My personal feeling is that this is lower but this might be my bubble, that we're the 5%.

                      What's your feeling?

                      Plz retoot for reach.

                      It is our bubble. We're the 5%, noone else cares:10
                      I think it is higher now - a bit, maybe 10% or so:5
                      It is significantly higher - more 25%:0
                      what the hell is DNS query encryption?:16

                      Closed

                        Remi Gacogne boosted

                        [?]NLnet Labs » 🌐
                        @nlnetlabs@social.nlnetlabs.nl

                        🚨 SECURITY RELEASE 🚨
                        Today we released Unbound 1.25.1, which consolidates security fixes for issues reported over a period of time.

                        There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608.

                        Please read the release notes carefully and plan to upgrade.

                        community.nlnetlabs.nl/t/unbou

                          AodeRelay boosted

                          [?]BastilleBSD :freebsd: » 🌐
                          @BastilleBSD@fosstodon.org

                          Pro tip: set `UseDNS no` in your sshd_config to disable reverse DNS lookups for every single ssh connection to your host.

                          It provides no filtering or validation purpose, afaik, and seems to only generate excess DNS traffic.

                          This lesson brought to you by the 66k DNS lookups in the past 24hrs from a single public facing forgejo jail.

                            [?]Stéphane Bortzmeyer » 🌐
                            @bortzmeyer@mastodon.gougere.fr

                            chinamobile.com has four name servers and they all have the same set of IP addresses.

                              [?]Stéphane Bortzmeyer » 🌐
                              @bortzmeyer@mastodon.gougere.fr

                              Nice and clever trick to recover some of the "anonymized" IP addresses in root name server traffic. ("Anonymization" is often a joke.)

                                [?]Stéphane Bortzmeyer » 🌐
                                @bortzmeyer@mastodon.gougere.fr

                                If your employer is an OARC member, you have access to the data collected by the root name servers. (Talk by Kazunori Fujiwara)

                                As always, working with data is complicated. For instance, some operators (A, B, D, F, H, I, J and L) blur the IP addresses, and it is not documented. (And they don't use the same algorithm.)

                                  [?]Stéphane Bortzmeyer » 🌐
                                  @bortzmeyer@mastodon.gougere.fr

                                  "Gonemaster - A Go implementation of Zonemaster" by Patrik Wallström

                                  Instead of using AI, let's use Go :-) Among the good things: native concurrency [I approve]

                                  codeberg.org/pawal/gonemaster

                                  🐪

                                    [?]NLnet Labs » 🌐
                                    @nlnetlabs@social.nlnetlabs.nl

                                    @ximon18 @dnsoarc after his talk on stage, Ximon will be at the demo table in the lunch area, where he can show all the other tricks Cascade has learned since OARC 45 in Stockholm.

                                    Also, make sure to bring your zone files so you can for example see how fast parallel signing by @bal4e really is.

                                      [?]Stéphane Bortzmeyer » 🌐
                                      @bortzmeyer@mastodon.gougere.fr

                                      "It's still broken."

                                        Fred de CLX boosted

                                        [?]Stéphane Bortzmeyer » 🌐
                                        @bortzmeyer@mastodon.gougere.fr

                                        The NS set and the associated glue MUST be consistent between parent and child domain. If they are not, the result will depend on wether the resolver is parent-centric or child-centric.

                                        (talk by Petr Špaček)

                                        At a time, it broke the .cd TLD.

                                          [?]Haack’s Networking » 🌐
                                          @oemb1905@gnulinux.social

                                          Webmin is hardened & clustered w/ three total nodes, ns1, ns2, and ns3 etc. I will eventually add clustered nodes on two other locations so records are still served when one cluster's host is down.

                                          tech.haacksnetworking.org/2025 feedback welcome.

                                          Added larger tmp directory & source-IPd vhost so webmin won't lock. Obv, make sure you use static, dedicated, & fully hardened external IPs for permitted list.

                                          haack's networking business logo

                                          Alt...haack's networking business logo

                                            [?]Stéphane Bortzmeyer » 🌐
                                            @bortzmeyer@mastodon.gougere.fr

                                            Funny that traffic analysis at Salesforce show still a lot of requests for obsolete types like A6, SPF, DLV.

                                              [?]Stéphane Bortzmeyer » 🌐
                                              @bortzmeyer@mastodon.gougere.fr

                                              Now, let's innovate: about DELEG, the future new system for delegation.

                                              "Authoritative Enrollment of DELEG" by Libor Peltan

                                                [?]Stéphane Bortzmeyer » 🌐
                                                @bortzmeyer@mastodon.gougere.fr

                                                root zone key rollover under way. (Planned for 11 october.)

                                                "Who in the room has root access to his resolver?" (Lot of hands, this is an OARC meeting.)

                                                  [?]Stéphane Bortzmeyer » 🌐
                                                  @bortzmeyer@mastodon.gougere.fr

                                                  Wonderful list of things that can go wrong (and therefore, will) in operations.

                                                  (Including an error done on friday afternoon and fixed, will you guess, on monday.)

                                                    Fred de CLX boosted

                                                    [?]Stéphane Bortzmeyer » 🌐
                                                    @bortzmeyer@mastodon.gougere.fr

                                                    DNessie, official mascot.

                                                    A cute Loch Ness monster standing in the front of the room.

                                                    Alt...A cute Loch Ness monster standing in the front of the room.

                                                      Fred de CLX boosted

                                                      [?]Stéphane Bortzmeyer » 🌐
                                                      @bortzmeyer@mastodon.gougere.fr

                                                      "Modeling DNS Queries and Caching to Evaluate the Merits of QNAME Minimization" by Casey Deccio

                                                      Great explanation of caching dynamics, by the way.

                                                        [?]Stéphane Bortzmeyer » 🌐
                                                        @bortzmeyer@mastodon.gougere.fr

                                                        Actually measuring the robustness of the Internet is hard. For instance, for resolvers (the current talk by Maynard Koch), good resolvers, actually used by people, are typically not publically reachable. The open resolvers which are easy to study are typically misconfigured and not actually used.

                                                          [?]Stéphane Bortzmeyer » 🌐
                                                          @bortzmeyer@mastodon.gougere.fr

                                                          [?]Stéphane Bortzmeyer » 🌐
                                                          @bortzmeyer@mastodon.gougere.fr

                                                          Did you know that OARC has its own fediverse instance?

                                                          Sticker with a mastodon and the domain name mastodns.net

                                                          Alt...Sticker with a mastodon and the domain name mastodns.net

                                                            [?]Stéphane Bortzmeyer » 🌐
                                                            @bortzmeyer@mastodon.gougere.fr

                                                            Good morning, Edinburgh! First day of the OARC workshop.

                                                            indico.dns-oarc.net/event/56/

                                                            An old stone building (the Writer's Museum).

                                                            Alt...An old stone building (the Writer's Museum).

                                                              AodeRelay boosted

                                                              [?]c-th :mastoblush: » 🌐
                                                              @c_th1@digitalcourage.social

                                                              Passwort - der Podcast von heise security: KI Fail, Copy Fail, S/MIME Fail

                                                              ( XXL Folge 2,4 Stunden, leider ohne Kapitelmarker und Folgennummer, aber interessant wie immer. :-* O:-) )

                                                              zieht weite Kreise und geht auch am nicht vorüber:

                                                              Die in ist technisch interessant, was Christopher und Sylvester allerdings an die Grenze ihres Wissens um -Innereien bringt. Darüber hinaus wirft Copy Fail diverse grundsätzliche Fragen zur von Linux und zur Handhabung von @Sicherheitslücken auf, die die Hosts diskutieren.

                                                              Außerdem geht in dieser Episode um eine löschwütige KI und natürlich um PKI, zumindest ein bisschen.

                                                              Webseite der Episode: passwort.podigee.io/57-ki-fail

                                                              Mediendatei: audio.podigee-cdn.net/2485319-

                                                              @christopherkunz
                                                              @syt

                                                              [?]nico » 🌐
                                                              @n@gotosocial.tourmentine.com

                                                              AodeRelay boosted

                                                              [?]BastilleBSD :freebsd: » 🌐
                                                              @BastilleBSD@fosstodon.org

                                                              Averaging 36.6% block rate on my DNS filtering service across all users.

                                                              In the age of enshittification it's not hard to believe that 1/3 of all DNS queries request adware, malware, trackers, and other crap you don't need.

                                                                [?]John Shaft » 🌐
                                                                @shaft@piaille.fr

                                                                Just realised that is Internet Standard (STD) 13.

                                                                In Western societies it means that DNS brings, obviously, good luck ☝️

                                                                rfc-editor.org/info/std13

                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                  Encore un correcteur trop zélé (c'est legarcon.net, pas legarçon.net)

                                                                    [?]John Shaft » 🌐
                                                                    @shaft@piaille.fr

                                                                    @jpmens As expected, it was not a problem. :)

                                                                      [?]nico » 🌐
                                                                      @n@gotosocial.tourmentine.com

                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                      @Steve12L@mamot.fr

                                                                      ⋅ DNS et certificats SSL : les deux clés d'Internet que l'Europe n'a jamais eu en main

                                                                      clubic.com/dossier-611791-dns-

                                                                        [?]John Shaft » 🌐
                                                                        @shaft@piaille.fr

                                                                        .de incident is a good reminder that resolver operators really should serve stale data ( 8767) when needed.

                                                                        It helps.

                                                                          [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                          @rysiek@mstdn.social

                                                                          DENIC wrote in their status message that "all DNSSEC-signed .de domains are currently affected in their reachability"
                                                                          status.denic.de/pages/incident

                                                                          But it wasn't just DNSSEC-signed domains! For example, bahn.de was down even though it is not DNSSEC-signed.

                                                                          It looks like for DNSSEC-signed zones the DS record in de. was incorrectly signed:
                                                                          dnsviz.net/d/nic.de/afpsNg/dns

                                                                          And for zones that were not signed, the NSEC3 records proving there is no DS record were incorrectly signed:
                                                                          dnsviz.net/d/bahn.de/afpnxQ/dn

                                                                            [?]John Shaft » 🌐
                                                                            @shaft@piaille.fr

                                                                            Please remember that is innocent until proven guilty. AFAIK DNS is working as expected in the case of .de outage

                                                                            'DNS is innocent' in caps against a yellow background

                                                                            Alt...'DNS is innocent' in caps against a yellow background

                                                                              [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                              @rysiek@mstdn.social

                                                                              Here's a thought:

                                                                              The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                                                                              :blobcatcoffee:

                                                                                [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                @rysiek@mstdn.social

                                                                                DENIC's status page:
                                                                                status.denic.de/

                                                                                Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                                                                DNSSEC disruption affecting .de domainsPartial Service Disruption

Incident Status

Partial Service Disruption

Components

DNS

Services

DNS Nameservice

May 5, 2026 23:28 CEST
May 5, 2026 21:28 UTC
INVESTIGATING

Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability.
The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.
Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available.
DENIC asks all affected parties for their understanding.
For further enquiries, DENIC can be contacted via the usual channels.

                                                                                Alt...DNSSEC disruption affecting .de domainsPartial Service Disruption Incident Status Partial Service Disruption Components DNS Services DNS Nameservice May 5, 2026 23:28 CEST May 5, 2026 21:28 UTC INVESTIGATING Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability. The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible. Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available. DENIC asks all affected parties for their understanding. For further enquiries, DENIC can be contacted via the usual channels.

                                                                                  [?]John Shaft » 🌐
                                                                                  @shaft@piaille.fr

                                                                                  Ok, is innocent. Most of the time. Curious to know what caused .de outage

                                                                                    [?]John Shaft » 🌐
                                                                                    @shaft@piaille.fr

                                                                                    Am I the only one having problems with ?

                                                                                    Unbound is throwing me a lot of DNSSEC bogus on some .de domains 🤔

                                                                                    $ dig welt.de
                                                                                    ...
                                                                                    ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 21366
                                                                                    ...
                                                                                    ; EDE: 6 (DNSSEC Bogus): (validation failure <welt.de. A IN>: signature crypto failed from 2a02:568:0:2::53 for DS welt.de. while building chain of trust)

                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                      @rysiek@mstdn.social

                                                                                      At this moment, please send to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

                                                                                        John Shaft boosted

                                                                                        [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                        @rysiek@mstdn.social

                                                                                        Edit: issue seems fixed.

                                                                                        Looks like DE ccTLD is unresolvable due to DNSSEC issue:
                                                                                        dnsviz.net/d/nic.de/afpsNg/dns

                                                                                        😬

                                                                                        🧵👇

                                                                                          [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                          @rysiek@mstdn.social

                                                                                          RE: mastodon.social/@jpmens/116522

                                                                                          IANA has a chance to do the funniest thing ever… :blobcatpeek:

                                                                                            [?]nico » 🌐
                                                                                            @n@gotosocial.tourmentine.com

                                                                                            [?]BastilleBSD :freebsd: » 🌐
                                                                                            @BastilleBSD@fosstodon.org

                                                                                            I am looking for a few more US-based early adopters to provide feedback on a protective DNS service offering aligned with NIST SP 800-81 Rev. 3 (March 2026).

                                                                                            csrc.nist.gov/pubs/sp/800/81/r

                                                                                            This service merges Zero Trust and DNS without requiring client-side agents. Supports mobile devices, browsers, server hardware & IoT.

                                                                                            If you're interested in providing feedback on this service as a free beta tester, email me at:

                                                                                            securednsbeta@techliterate.co

                                                                                              🗳

                                                                                              [?]Areskul » 🌐
                                                                                              @jean_dupont@mastodon.social

                                                                                              Can you reach crocuda.com ?
                                                                                              (it is only)

                                                                                              yes:57
                                                                                              no:11

                                                                                                [?]Arnaud Launay » 🌐
                                                                                                @asl@mastodon.launay.org

                                                                                                Ah, je viens donc de découvrir que drill a été "abandonné", que le nouvel outil s'appelle "dnsi" ... Et qu'il n'a pas l'air beaucoup plus développé non plus.
                                                                                                Faut en revenir à dig ?

                                                                                                  John Shaft boosted

                                                                                                  [?]NLnet Labs » 🌐
                                                                                                  @nlnetlabs@social.nlnetlabs.nl

                                                                                                  We released Unbound 1.25.0. This release of our resolver includes improvements and fixes resulting from reports by various security researchers.

                                                                                                  In the release notes, the word “thanks" appears 32 times. You can expect this trend to continue for the next couple of releases, at least.

                                                                                                  Lastly, please note the new signing key we're using since January ‘26.

                                                                                                  community.nlnetlabs.nl/t/unbou

                                                                                                    [?]Frederic Pasteleurs » 🌐
                                                                                                    @askarel@mastodon.social

                                                                                                    Petite question pour @bortzmeyer: quand on a plusieurs noms de domaines sur différents TLDs, est-ce qu'il y a un risque à tout garder chez le même registrar ou il est préférable d'en avoir plusieurs ? Si il est préférable d'en avoir plusieurs, quelle est la recommendation pour la distribution ?
                                                                                                    La question ne concerne pas la partie technique: juste la partie paperasse et la partie paiements.

                                                                                                      [?]Jonathan Kamens 86 47 » 🌐
                                                                                                      @jik@federate.social

                                                                                                      the consultant who maintains your company's sets up in Salesforce's sandbox environment and asks you to create the necessary records for it and doesn't understand why it's a problem that he used the same selectors (i.e., DNS record names) for the sandbox environment that are already being used in production.
                                                                                                      (I'm sure he has an expert-level proficiency in Salesforce, but maybe not so much in email security.)

                                                                                                        [?]nico » 🌐
                                                                                                        @n@gotosocial.tourmentine.com

                                                                                                        [?]Teddy / Domingo (🇨🇵/🇬🇧) » 🌐
                                                                                                        @TeddyTheBest@framapiaf.org

                                                                                                        Véritable pare-feu de l’Internet, est devenu en quelques années la référence pour reprendre le contrôle sur sa . Pourquoi délaisser les de votre au profit de ce fleuron français ? 
                                                                                                        goodtech.info/nextdns-guide-av

                                                                                                        Remi Gacogne boosted

                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                        Géopolitique du : quel est le point commun entre la Grèce et le Kirghizistan ? labs.ripe.net/author/yevheniya

                                                                                                        (Réponse : les deux ont au moins un serveur faisant autorité acceptant DoT - DNS sur TLS.)

                                                                                                          [?]NLnet Labs » 🌐
                                                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                                                          To his complete surprise, our colleague Jaap Akkerhuis was awarded Knight of the Order of the Dutch Lion earlier today for Exceptional Contribution to Society. Akkerhuis is a Dutch Internet pioneer, protocol designer and expert on the internet's naming system.

                                                                                                          More at blog.nlnetlabs.nl/dutch-intern

                                                                                                            [?]nico » 🌐
                                                                                                            @n@gotosocial.tourmentine.com

                                                                                                            [?]John Shaft » 🌐
                                                                                                            @shaft@piaille.fr

                                                                                                            RE: piaille.fr/@shaft/116455327800

                                                                                                            Procrastination over

                                                                                                            [?]John Shaft » 🌐
                                                                                                            @shaft@piaille.fr

                                                                                                            @DNSresolver azathoth.shaftinc.fr TXT

                                                                                                                mmu_man boosted

                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                Amusant, un nom de domaine écrit avec un point médian (ping @polylogue ).

                                                                                                                  [?]BlablaLinux » 🌐
                                                                                                                  @blablalinux@mastodon.blablalinux.be

                                                                                                                  🚀 passe à la vitesse !
                                                                                                                  C'est fait ! Mon instance PeerTube est désormais 100% boostée à l'Object Storage S3.

                                                                                                                  Le résultat ? Un stockage optimisé et un fonctionnement au top ! ⚡️

                                                                                                                  Le petit secret de l'installation : pour une rapidité maximale, les échanges entre PeerTube et mon instance ne sortent jamais de la maison. Grâce à une configuration aux petits oignons, tout le trafic reste sur le réseau local 🏠💻

                                                                                                                    [?]kriφm :unverified: ☮ ⏚🔻 » 🌐
                                                                                                                    @kriom@framapiaf.org

                                                                                                                    @mediapart @MarieTurcan
                                                                                                                    Bah coupons les accès a grok.com et x.com depuis les ça empêchera pas d'y accéder pour ceux qui savent contourner (VPN...) mais ça montrera qu'on agit.

                                                                                                                    Rappel que grok.com accessible sans contrôle d'accès te sortira du texte 18+++ si tu lui promptes : grok.com/?q=10+phrases+trash+e

                                                                                                                    Ce matin ça répond ça sur une IP non :
                                                                                                                    > Ce modèle est temporairement indisponible Veuillez essayer un modèle différent

                                                                                                                    Ça répond bien des dingueries sur une IP

                                                                                                                    JP Mens boosted

                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                    Le 18 avril, le nom de domaine eth.limo a été victime d'un détournement (une attaque où le méchant prend le contrôle du nom et change les informations).

                                                                                                                    bortzmeyer.org/eth-limo-detour

                                                                                                                      [?]Ludovic :Firefox: :FreeBSD: » 🌐
                                                                                                                      @usul@piaille.fr

                                                                                                                      Petite question nom de domaine, serait-il possible d'enregistrer un .fr mais dont le nom de domaine serait écrit en cyrilique?

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]💾kawummke.log » 🌐
                                                                                                                        @kawummke@social.anoxinon.de

                                                                                                                        Mein in diesem Monat ist ein wenig nerdi. Ich in meinem Netzwerk einen eigenen Resolver einzusetzen. läuft bereits seit Jahren zuverlässig auf meinem und soll nun mit ergänzt werden. Meine derzeitige Frage ist strategisch. Den PiHole erweitern oder Unbound in einem eigenen Container aufsetzen? Wie schauen die Entscheidungen im zu diese Frage aus?

                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                          Ça faisait longtemps qu'on n'avait pas eu un nouveau domaine de premier niveau dans le . mastodon.gougere.fr/@DNSresolv

                                                                                                                            [?]Physicman » 🌐
                                                                                                                            @physicman@famichiki.jp

                                                                                                                            Quick question for the technical people in Japan.

                                                                                                                            Do you have any good recommendation for a good (and preferably cheap) DNS hosting provider in Japan?

                                                                                                                            I have a couple of .net domains that I'd like to move.

                                                                                                                              [?]Physicman » 🌐
                                                                                                                              @physicman@famichiki.jp

                                                                                                                              I've been looking a bit around for DNS hosting in Japan...

                                                                                                                              Does anyone have any experience with Onamae.com?
                                                                                                                              They do seem pretty cheap (about 1500¥ for a .net if I understood correctly).

                                                                                                                              Are there any kind of cons?

                                                                                                                              What do people on use?

                                                                                                                                lux 🦊ΘΔ boosted

                                                                                                                                [?]NLnet Labs » 🌐
                                                                                                                                @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                RE: fosstodon.org/@iscdotorg/11641

                                                                                                                                In case you’re wondering: while not as extreme as illustrated by ISC (we don’t offer a bug bounty program), NLnet Labs suffers from a similar situation, in particular for Unbound.

                                                                                                                                Handling vulnerability reports, both valid ones and false positives, has now become a full time job for the entire Unbound team.

                                                                                                                                You can argue that it ultimately makes our resolver more secure, it also means we cannot work on building and releasing new features, like:

                                                                                                                                github.com/NLnetLabs/unbound/p

                                                                                                                                  [?]gregR ☯ » 🌐
                                                                                                                                  @gregr@mamot.fr

                                                                                                                                  A punchline by @mwl again :)
                                                                                                                                  sanity and self-respect - gregR ☯ - /usr/share/images
                                                                                                                                  images.gregr.fr/2023-04-06-san

                                                                                                                                    AodeRelay boosted

                                                                                                                                    [?]Valère » 🌐
                                                                                                                                    @valere@hostux.social

                                                                                                                                    Logiciel open source, prise en charge de DoH/DoT/DoQ, protections et architecture : j’ai documenté la stack de HostuxDNS ici :
                                                                                                                                    dns.hostux.net/stack.html

                                                                                                                                      [?]Teddy / Domingo (🇨🇵/🇬🇧) » 🌐
                                                                                                                                      @TeddyTheBest@framapiaf.org

                                                                                                                                      , , : ce rapport démonte la stratégie anti-piratage en . Depuis plus de quinze ans, l’Europe s’est engagée dans une lutte de plus en plus offensive contre les sites pirates.
                                                                                                                                      clubic.com/actualite-609094-ip

                                                                                                                                        Fred de CLX boosted

                                                                                                                                        [?]𝙹𝚘𝚎𝚕 𝙲𝚊𝚛𝚗𝚊𝚝 ♑ 🤪 » 🌐
                                                                                                                                        @joel@gts.tumfatig.net

                                                                                                                                        :runbsd: Now that the #arm64 boards are installed, it was time to use them as redundant #DHCP server and #DNS resolvers; using #dhcpd and #Unbound on both :openbsd: #OpenBSD and :freebsd: #FreeBSD.

                                                                                                                                        https://www.tumfatig.net/2026/redundant-dhcp-server-and-dns-resolver-using-openbsd-and-freebsd/

                                                                                                                                          [?]patpro » 🌐
                                                                                                                                          @patpro@social.patpro.net

                                                                                                                                          I had to use ktrace to find the culprit, but now the DNS requests count for a particular PTR record on my LAN is down from ~1133/hour to 2/hour.
                                                                                                                                          -> just a nice -n in syslogd params.
                                                                                                                                          Quite a win.
                                                                                                                                          #dns #ktrace #freebsd #syslog

                                                                                                                                            [?]nico » 🌐
                                                                                                                                            @n@gotosocial.tourmentine.com

                                                                                                                                            [?]Baptiste BCA » 🌐
                                                                                                                                            @bca@social.stackgui.de

                                                                                                                                            On m'a dit que c'était infernal d'héberger son propre serveur d'e-mail.
                                                                                                                                            Du coup j'en ai installé un 😅

                                                                                                                                            Je suis parti sur Stalwart, qui est plus léger que la stack mailcow pour un usage solo.

                                                                                                                                            - Toute la technique : Ok ✅️
                                                                                                                                            - DNS : Ok ✅️
                                                                                                                                            - Test blocklist IP -> 1 sur 60 : Ok ✅️
                                                                                                                                            - Domaine connu : Ok ✅️
                                                                                                                                            - IP additionnelle dédiée : Ok ✅️

                                                                                                                                            - Test sur une adresse Tuta : Reçu ✅️
                                                                                                                                            - Test sur une adresse Infomaniak : Reçu ✅️

                                                                                                                                            - Test sur une adresse Gmail : Spam ❌️
                                                                                                                                            - Test sur une adresse Hotmail : Spam ❌️

                                                                                                                                            😅

                                                                                                                                            Donc je comprends le terme "infernal".

                                                                                                                                            Il y a clairement un monopole de 3 géants (Google, Micorsoft, Apple), qui font la loi sur les e-mails.

                                                                                                                                            Manque de bol, c'est ce que les gens utilisent à 80% du temps.

                                                                                                                                            Je vais faire une vidéo détaillée sur le process.
                                                                                                                                            Et je comprends pourquoi même les plus courageux finissent pas laisser ça en SaaS.

                                                                                                                                            En attendant je vais "warm" mon adresse.

                                                                                                                                            Si vous avez des astuces ?

                                                                                                                                            #stalwart #mailcow #selfhostemail #dns #email

                                                                                                                                            @stalwartlabs

                                                                                                                                              [?]Teddy / Domingo (🇨🇵/🇬🇧) » 🌐
                                                                                                                                              @TeddyTheBest@framapiaf.org

                                                                                                                                              Une campagne d’ détourne des milliers de dans le monde. Le groupe de hackers pirate des routeurs vulnérables pour l'interception des flux 365. Cette opération d'espionnage utilise une manipulation du pour le vol de jetons d'authentification sans pénétration directe des serveurs de l'entreprise américaine
                                                                                                                                              clubic.com/actualite-608353-un

                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                AodeRelay boosted

                                                                                                                                                [?]Peter N. M. Hansteen » 🌐
                                                                                                                                                @pitrh@mastodon.social

                                                                                                                                                The domain .cn name scam is still ongoing, one more entry added to nxdomain.no/~peter/domainnames (this time addressed to a list owner address).

                                                                                                                                                Also see nxdomain.no/~peter/domain_name

                                                                                                                                                  [?]nico » 🌐
                                                                                                                                                  @n@gotosocial.tourmentine.com

                                                                                                                                                  [?]nico » 🌐
                                                                                                                                                  @n@gotosocial.tourmentine.com

                                                                                                                                                  AodeRelay boosted

                                                                                                                                                  [?]NLnet Labs » 🌐
                                                                                                                                                  @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                  The decision to move away from mailing lists was not taken lightly.

                                                                                                                                                  We made several tries in the past to find capable mailing list hosting providers and either they were not ticking all our boxes or we had to migrate back to our own self-hosting situation.

                                                                                                                                                  Since we are a small developer-focused team, any IT-like activities, in particular emergency ones, would take focus away from things that actually need priority: maintaining mission critical and software.

                                                                                                                                                    AodeRelay boosted

                                                                                                                                                    [?]NLnet Labs » 🌐
                                                                                                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                    @holsta Like that time we literally flipped the script on unbound.net 😅

                                                                                                                                                    punoqun.net/

                                                                                                                                                      AodeRelay boosted

                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                      Soon, will run out of letters for its various transports (DoC, DoH, DoQ, DoT…) rfc-editor.org/info/rfc9953

                                                                                                                                                        [?]John Shaft » 🌐
                                                                                                                                                        @shaft@piaille.fr

                                                                                                                                                        Time to update jokes!

                                                                                                                                                        ✋ What's up DoQ?
                                                                                                                                                        👉 What's up DoC?

                                                                                                                                                        DNS over CoAP (DoC) (publication date is March 2026, so not a joke)
                                                                                                                                                        rfc-editor.org/info/rfc9953

                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                          RFC 9953: DNS over the Constrained Application Protocol (DoC)

                                                                                                                                                          Le protocole est un protocole léger, conçu pour les objets connectés. Ce décrit comment faire du au-dessus de CoAP. Si votre brosse à dents a besoin de faire du DNS, c'est ce RFC qu'il faut lire.

                                                                                                                                                          @miri64

                                                                                                                                                          bortzmeyer.org/9953.html

                                                                                                                                                            [?]Arnaud Launay » 🌐
                                                                                                                                                            @asl@mastodon.launay.org

                                                                                                                                                            Quelle classe, cette mise à jour d'Ubuntu de 22 vers 24.04...

                                                                                                                                                            root@XXX:/etc# ls -l resolv.conf
                                                                                                                                                            lrwxrwxrwx 1 root root 39 mars 31 19:34 resolv.conf -> ../run/systemd/resolve/stub-resolv.conf

                                                                                                                                                            root@XXX:/etc# ls -l ../run/systemd/resolve/stub-resolv.conf
                                                                                                                                                            ls: impossible d'accéder à '../run/systemd/resolve/stub-resolv.conf': Aucun fichier ou dossier de ce nom

                                                                                                                                                            Ça marche forcément beaucoup, beaucoup moins bien.

                                                                                                                                                            C'est toujours de la faute du Cc: @bortzmeyer (vu que du coup, c'est de sa faute à lui, forcément)

                                                                                                                                                              [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                              @BastilleBSD@fosstodon.org

                                                                                                                                                              "At some point, a reasonable person asked "DNS resolves names to IP addresses, what else can it do?" The answer, apparently, is run DOOM."

                                                                                                                                                              github.com/resumex/doom-over-d

                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                J'avais écrit un article de râlerie contre cette idée fausse qu'il y aurait « propagation » dans le mais c'est seulement maintenant que je découvre que je ne suis pas le seul : e-ontap.com/dns/propagation/ha nslookup.io/learning/dns-propa

                                                                                                                                                                  Fred de CLX boosted

                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                  Formation d'administrateur demain. Si vous pouviez casser votre domaine, pour que je donne le déboguage en TP aux étudiants…

                                                                                                                                                                    [?]Paco Hope [He/Him] » 🌐
                                                                                                                                                                    @paco@infosec.exchange

                                                                                                                                                                    I just noticed this DNS graph. The web site I took over in 2019. It's the busiest web site I have. But I really think the huge upswing in traffic is related to bot scrapers. I have been struggling so hard just to make them go away. My bandwidth, compute, and web service are not for them. They are not welcome. They do not care.

                                                                                                                                                                    • January 2026: 2,237,399 queries
                                                                                                                                                                    • February 2026: 4,093,488 queries
                                                                                                                                                                    • March 2026: 8,893,458 queries (so far)

                                                                                                                                                                    Literally doubling month on month.

                                                                                                                                                                    Now, I recently made changes to the DNS for that zone. And I made some screw-ups when I did it. So, I temporarily¹ set the TTL on the NS records to 600 seconds. I kept screwing them up and needing to change them.

                                                                                                                                                                    Fixing the NS records this morning definitely had a benefit. Yesterday was 325,336 queries. Today was 254,492. So again, some of this is on me. But that whole 13-year DNS graph with a huge surge in the last 2 years is not all me. Stuff has changed.

                                                                                                                                                                    ¹ I remembered this morning when I was like "WTF do I have so much DNS traffic!?"

                                                                                                                                                                    A line graph depicting DNS queries from 2013 to 2026. Traffic starts to pick up in 2024 time frame, and then at the very end of the graph, this month of 2026, there's this massive spike to nearly 10M queries in a month.

                                                                                                                                                                    Alt...A line graph depicting DNS queries from 2013 to 2026. Traffic starts to pick up in 2024 time frame, and then at the very end of the graph, this month of 2026, there's this massive spike to nearly 10M queries in a month.

                                                                                                                                                                      Remi Gacogne boosted

                                                                                                                                                                      [?]NLnet Labs » 🌐
                                                                                                                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                      We're thrilled that Cascade is among the first projects supported by the Nominet DNS Fund.

                                                                                                                                                                      With Nominet's support, our new DNSSEC signing solution receives a massive push forward, allowing our team to focus on implementing speed improvements, a reduced memory footprint and essentials such as incremental signing.

                                                                                                                                                                      We'll be launching a beta in April, followed by an initial production release in June 2026.

                                                                                                                                                                      Read more: nominet.uk/news/nominet-suppor

                                                                                                                                                                      Nominet DNS Fund banner

                                                                                                                                                                      Alt...Nominet DNS Fund banner

                                                                                                                                                                        Taggart :ifin: boosted

                                                                                                                                                                        [?]B'ad Samurai :ifin: [he/him] » 🌐
                                                                                                                                                                        @badsamurai@infosec.exchange

                                                                                                                                                                        @porkbun RDAP is a pretty silly address and I appreciate that.

                                                                                                                                                                        You never see ‘.horse‘ in IOCs because it’s a $25 domain!

                                                                                                                                                                        {
"value": "https://cart-before.porkbun.horse/rdap/",
"rel": "about",
"href": "https://cart-before.porkbun.horse/rdap/",
"type": "application/rdap+json”
}

                                                                                                                                                                        Alt...{ "value": "https://cart-before.porkbun.horse/rdap/", "rel": "about", "href": "https://cart-before.porkbun.horse/rdap/", "type": "application/rdap+json” }

                                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                          Pro tip : quand tu configures un VPN, pense à changer de résolveur sinon, tu auras du mal à aller voir le site Web de Libération, avec l'adresse IP de Dropbox qu'a renvoyé le réseau d'accès.

                                                                                                                                                                            [?]Jan Schaumann » 🌐
                                                                                                                                                                            @jschauma@mstdn.social

                                                                                                                                                                            System Administration: Week 7: DNS, Part II

                                                                                                                                                                            In this video, we dissect DNS lookups performed on our EC2 instance, then discuss just how a caching resolver performs the lookup, moving from "magic happens here" to the below visualization.

                                                                                                                                                                            youtu.be/z55ULZcKP8A

                                                                                                                                                                              [?]Jan Schaumann » 🌐
                                                                                                                                                                              @jschauma@mstdn.social

                                                                                                                                                                              System Administration: Week 7: DNS, Part III

                                                                                                                                                                              In this video, we try to wrap up our discussion of the Domain Name System by addressing the nature of the root nameservers, looking at various different resource record types, observing reverse lookups, and thinking about how we can have assurance of authenticity and integrity of the DNS results returned to us via DNSSEC.

                                                                                                                                                                              youtu.be/XDJEJFVNoko

                                                                                                                                                                              World map showing the locations of the root servers.

                                                                                                                                                                              Alt...World map showing the locations of the root servers.

                                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                So, when an old resolver (not knowing DELEG) queries a new server for a domain which has only DELEG (and no NS records), what the answer should be? NXDOMAIN? SERVFAIL? Synthesis of some NS?

                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                  DELEG working group (changing completely the delegation). Last big issue: how should a new server reply to an old client, when the server has only DELEG records and no NS records?

                                                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                    Good morning, Shenzhen:! Seventh and last day of ietf.org/meeting/125/

                                                                                                                                                                                    Today, we are going to break/save/restore the with the new delegation system, DELEG. Also, security area general meeting.

                                                                                                                                                                                      [?]Hyde 📷 🖋 :debian: » 🌐
                                                                                                                                                                                      @hyde@lazybear.social

                                                                                                                                                                                      Any good in Europe?

                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                        Another funny question. After Cisco broke because Cloudflare changed the order of DNS records in the answer (which is perfectly legitimate), should we mandate a specific order in ?

                                                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                          Grosse discussion à la réunion IETF sur la censure via un résolveur menteur : comment indiquer à l'utilisateur (qui ne fait pas de requête DNS lui-même et ne connait pas dig) qu'il y a eu censure et pas panne ?

                                                                                                                                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                            After a lively discussion on solutions to depend less on the root (obviously no consensus, despite a tendency to deny there is a problem to solve), another hot question: DNS and the need to be transparent about it. datatracker.ietf.org/doc/draft

                                                                                                                                                                                            What to display to the end user? (Not anything got from the resolver: security issues.) Lumen Database entry?

                                                                                                                                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                              Now, dnsop working group (real-time transcript said "Dina Zop") because the loves you and we love it, too.

                                                                                                                                                                                              First, a lot of stuff about various ways to be less technically dependent on the root (local caching, local root as in RFC 8806, etc).

                                                                                                                                                                                              RFC 8806, the resolver behaves as if it were authoritative for the root. RootCache is more resolver-traditional.

                                                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                Expect a lot of AI in (there were many side meetings at about AI)

                                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                  Good morning, Shenzhen! Sixth day of ietf.org/meeting/125/

                                                                                                                                                                                                  Today, for me, dconn (helping endusers to configure domain-related services), dnsop (second meeting, all things ) and a talk about chinese involvment in standardization.

                                                                                                                                                                                                    [?]Entité terrestre auto-critique » 🌐
                                                                                                                                                                                                    @s4mdf0o1@piaille.fr

                                                                                                                                                                                                    Un ami me fait suivre :
                                                                                                                                                                                                    "
                                                                                                                                                                                                    Retour d'expérience : WireGuard + Livebox Orange = fuite DNS IPv6 silencieuse

                                                                                                                                                                                                    Même avec un DNS IPv4 alternatif correctement configuré (Aquilenet, FDN...), un serveur dns Orange continuait à apparaître.

                                                                                                                                                                                                    Cause : la Livebox injecte ses DNS via RDNSS dans ses Router Advertisements IPv6.
                                                                                                                                                                                                    NetworkManager les accepte en parallèle de notre config — sans prévenir.

                                                                                                                                                                                                    Le mécanisme : quand vous visitez un site, votre OS envoie deux requêtes DNS
                                                                                                                                                                                                    simultanément — une en IPv4, une en IPv6.
                                                                                                                                                                                                    "
                                                                                                                                                                                                    1/n

                                                                                                                                                                                                      [?]Entité terrestre auto-critique » 🌐
                                                                                                                                                                                                      @s4mdf0o1@piaille.fr

                                                                                                                                                                                                      Même avec DNS IPv4 → Aquilenet, la requête IPv6 partait chez Orange via le
                                                                                                                                                                                                      RDNSS annoncé dans les RA de la Livebox...

                                                                                                                                                                                                      Résultat : Orange loguait 50% de vos requêtes DNS malgré une config "correcte".

                                                                                                                                                                                                      Ce qui ne suffit pas :
                                                                                                                                                                                                      - Changer le DNS IPv6 dans NetworkManager → Livebox s'impose quand même en parallèle
                                                                                                                                                                                                      - sysctl accept_ra=0 seul → NetworkManager le réinitialise au nmcli connection up
                                                                                                                                                                                                      - ip -6 route del → routes réinjectées par le nmcli connection up suivant

                                                                                                                                                                                                      2/n

                                                                                                                                                                                                        [?]Entité terrestre auto-critique » 🌐
                                                                                                                                                                                                        @s4mdf0o1@piaille.fr

                                                                                                                                                                                                        La vraie solution :
                                                                                                                                                                                                        nmcli connection modify "VotreConnexion" ipv6.dns ""
                                                                                                                                                                                                        nmcli connection modify "VotreConnexion" ipv6.method "link-local"

                                                                                                                                                                                                        ipv6.method "link-local" dit à NetworkManager :
                                                                                                                                                                                                        "n'accepte AUCUNE configuration IPv6 venant de l'extérieur"

                                                                                                                                                                                                        La Livebox ne peut plus injecter ni routes ni DNS via ses RA.
                                                                                                                                                                                                        Tout l'IPv6 utile passe par le tunnel WireGuard uniquement.

                                                                                                                                                                                                        Testé sur Debian 12 + NetworkManager + Livebox 5 Orange.

                                                                                                                                                                                                        3/n

                                                                                                                                                                                                          Marcos Dione boosted

                                                                                                                                                                                                          [?]Entité terrestre auto-critique » 🌐
                                                                                                                                                                                                          @s4mdf0o1@piaille.fr

                                                                                                                                                                                                          Et voilà pourquoi :

                                                                                                                                                                                                          Orange a 60% de part de marché pour la fibre et haut débit.

                                                                                                                                                                                                          Il est légalement contraint d'héberger des sondes DPI
                                                                                                                                                                                                          (Deep Packet Inspection) sur son infrastructure, accessibles
                                                                                                                                                                                                          au GIC (Groupement Interministériel de Contrôle) sous tutelle
                                                                                                                                                                                                          de la DGSI.

                                                                                                                                                                                                          Chaque requête DNS non chiffrée transitant par la Livebox
                                                                                                                                                                                                          constitue une métadonnée — quel site, à quelle heure,
                                                                                                                                                                                                          depuis quelle IP — collectée en temps réel sans mandat
                                                                                                                                                                                                          individuel (loi renseignement 2015, étendue en 2021).

                                                                                                                                                                                                          documenté dans les
                                                                                                                                                                                                          rapports annuels de la CNCTR (Commission Nationale de
                                                                                                                                                                                                          Contrôle des Techniques de Renseignement).

                                                                                                                                                                                                          4

                                                                                                                                                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                            So, previously on post-quantum : not a lot of action. Standardized post-quantum cryptography algorithms like ML-DSA have keys and signatures which are way too long for the .

                                                                                                                                                                                                            mastodon.gougere.fr/@DNSresolv

                                                                                                                                                                                                            TLS can deal with it (they run on TCP or QUIC) but we cannot, with UDP. No obvious solution.

                                                                                                                                                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                              datatracker.ietf.org/doc/draft : "Protective" resolvers (also called lying resolvers or, more politically correct, "policy-aware resolvers") Everybody disagrees and wants to kill the draft.

                                                                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                dnsop working group at , for all those who love .

                                                                                                                                                                                                                (In another room at Shenzhen, the RFC editor is busy publishing new RFCs.)

                                                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                  Good morning, Shenzhen! This is the third day of ietf.org/meeting/125/ We are preparing the future Internet technical standards.

                                                                                                                                                                                                                  Today, for me, dnsop ( stuff), aipref (preferences for AI crawlers) and rpp (domain registration protocol).

                                                                                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                    Ah, a bit of : observation of infrastructure of attackers. Most of the time, it is short-lived but some are very long-lived, as shown by DNS responses analysis.

                                                                                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                      @bernardpo @whiteflag Et pour les requêtes dont parle l'article (suggérant soit dig dans un terminal, soit un service hébergé par un GAFA, en l'occurrence Cloudflare), vous pouvez aussi utiliser le fédivers en envoyant un nom de domaine à @DNSresolver

                                                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                        Agent naming with domain names (AI agents). By the .cn people. SVCB records in the _agents subdomain.

                                                                                                                                                                                                                          [?]John Shaft » 🌐
                                                                                                                                                                                                                          @shaft@piaille.fr

                                                                                                                                                                                                                          Avant d'installer un logiciel pour faire du sur votre machine, pensez à vérifier s'il est équipé d'un lecteur de CD ☝️

                                                                                                                                                                                                                            [?]gregR ☯ » 🌐
                                                                                                                                                                                                                            @gregr@mamot.fr

                                                                                                                                                                                                                            Échec et mat !

                                                                                                                                                                                                                            > Check Point ThreatCloud flags whole cloudfront.net... - Check Point CheckMates
                                                                                                                                                                                                                            > False positives can happen and do happen from time to time. Normally I would not create a CheckMates post for that.
                                                                                                                                                                                                                            community.checkpoint.com/t5/Ge

                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                              [?]NLnet Labs » 🌐
                                                                                                                                                                                                                              @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                                                                              Back in May 2019, we said goodbye to SVN and Bugzilla and migrated to Git and GitHub [1]. Since then, we accumulated 188 repositories. 🙀

                                                                                                                                                                                                                              We're now making a list to decide which ones we're moving to @Codeberg and which are going to archived and left behind.

                                                                                                                                                                                                                              While we're doing that, we signed NLnet Labs up as a Codeberg e.V. member!

                                                                                                                                                                                                                              [1] lists.nlnetlabs.nl/pipermail/u

                                                                                                                                                                                                                              Screenshot of the unbound-users mailing list announcement on the migration to GitHub in 2019.

                                                                                                                                                                                                                              Alt...Screenshot of the unbound-users mailing list announcement on the migration to GitHub in 2019.

                                                                                                                                                                                                                                [?]Hyde 📷 🖋 :debian: » 🌐
                                                                                                                                                                                                                                @hyde@lazybear.social

                                                                                                                                                                                                                                Who thought to move away from .com because of the US government right now? If you did, and you are in Europe, what would be you best option?

                                                                                                                                                                                                                                  JP Mens boosted

                                                                                                                                                                                                                                  [?]Jan Schaumann » 🌐
                                                                                                                                                                                                                                  @jschauma@mstdn.social

                                                                                                                                                                                                                                  System Administration: Week 7: DNS, Part I

                                                                                                                                                                                                                                  In this video, we are beginning our discussion of the . We go back to the early days of the internet when copying /etc/hosts from system to system was the way to resolve hosts...

                                                                                                                                                                                                                                  (Hosts file from 1983: rscott.org/OldInternetFiles/ho)

                                                                                                                                                                                                                                  ...and we cover the structure of the domain name space and the creation of the top-level domains.

                                                                                                                                                                                                                                  (Second-level domain inventory from 1987: rscott.org/OldInternetFiles/do)

                                                                                                                                                                                                                                  youtu.be/-bpIT7M9i00

                                                                                                                                                                                                                                    Fred de CLX boosted

                                                                                                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                    RFC 9848: Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings

                                                                                                                                                                                                                                    Le protocole (Encrypted Client Hello, normalisé dans le RFC 9849) permet de chiffrer la salutation (le ClientHello), notamment le nom du serveur auquel on se connecte. Mais pour cela, il faut la clé publique du serveur. Un des moyens de la récupérer est dans le , comme normalisé dans notre .

                                                                                                                                                                                                                                    bortzmeyer.org/9848.html

                                                                                                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                      [?]Marcel SIneM(S)US » 🌐
                                                                                                                                                                                                                                      @simsus@social.tchncs.de

                                                                                                                                                                                                                                      GuB boosted

                                                                                                                                                                                                                                      [?]NLnet Labs » 🌐
                                                                                                                                                                                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                                                                                      With memory prices skyrocketing we're happy to bring you some good news on the front.

                                                                                                                                                                                                                                      In version 4.14.0 of our authoritative nameserver NSD we vastly reduced the memory footprint by refactoring the RDATA storage, with gains up to 50%.

                                                                                                                                                                                                                                      Overall, relatively large -signed zones like .nl and .se benefit the most, but being able to bring the memory requirements to serve .com below 64GB is pretty awesome too.

                                                                                                                                                                                                                                      We're eager to hear the improvements you're seeing!

                                                                                                                                                                                                                                      blog.nlnetlabs.nl/smaller-fast

                                                                                                                                                                                                                                        JP Mens boosted

                                                                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                        "I think i should be able to come up with something that improves caching, reduces server load and eliminates some major security gaps while still keeping the decentralized aspect." (He talks about replacing the …)

                                                                                                                                                                                                                                        (This was in a comment to blog.apnic.net/2026/02/25/towa)

                                                                                                                                                                                                                                        Will he have more success than the guy who claimed he could rewrite curl in one week-end?

                                                                                                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                          @joel Disclaimer: I manage a public DNS resolver doh.bortzmeyer.fr/policy

                                                                                                                                                                                                                                          There are thousands of open resolvers (public = on purpose, open = often by accident) so it is quite ridiculous to try to address them one by one. As often, this is security theater (I receive some time stupid "security alerts" written by interns or LLMs). Was there more specific details? ("open relay" is typically used for SMTP, not DNS)

                                                                                                                                                                                                                                            [?]Alexandre :freebsd: » 🌐
                                                                                                                                                                                                                                            @alelab@mastodon.bsd.cafe

                                                                                                                                                                                                                                            @joel I am not a guy, but this topic is interesting me.
                                                                                                                                                                                                                                            I follow these two valuable people 🇫🇷@bortzmeyer and @shaft and they provide the same public DNS service you want to build. They share a lot of information on their respective blogs on their public DNS resolvers.
                                                                                                                                                                                                                                            I am pretty sure they already faced the same situation than your.

                                                                                                                                                                                                                                              Remi Gacogne boosted

                                                                                                                                                                                                                                              [?]mc.fly [he/him] » 🌐
                                                                                                                                                                                                                                              @mcfly@milliways.social

                                                                                                                                                                                                                                              It's always . Unless everyone assumes it is DNS then it's not.

                                                                                                                                                                                                                                                [?]Miek Gieben » 🌐
                                                                                                                                                                                                                                                @miekg@mastodon.nl

                                                                                                                                                                                                                                                well. I think I'm out of optimizations idea for codeberg.org/miekg/dns

                                                                                                                                                                                                                                                Happy to be pointed to bottlenecks, but I think _all_ the lowish hanging fruit is gone. Ballpark number: 2x faster than dnsv1

                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                  Let’s Encrypt Introduces DNS-PERSIST-01 for Persistent ACME DNS Validation

                                                                                                                                                                                                                                                  linuxiac.com/lets-encrypt-intr

                                                                                                                                                                                                                                                    Alexandre :freebsd: boosted

                                                                                                                                                                                                                                                    [?]vermaden » 🌐
                                                                                                                                                                                                                                                    @vermaden@mastodon.bsd.cafe

                                                                                                                                                                                                                                                    New 𝗙𝗿𝗲𝗲𝗕𝗦𝗗 𝗠𝗜𝗧 𝗞𝗲𝗿𝗯𝗲𝗿𝗼𝘀 𝗦𝗲𝗿𝘃𝗲𝗿 (FreeBSD MIT Kerberos Server) article on vermaden.wordpress.com blog.

                                                                                                                                                                                                                                                    vermaden.wordpress.com/2026/02