social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #dnssec

[?]JP Mens » 🌐
@jpmens@mastodon.social

The difference between the two log lines above and the two below is a single named.conf configuration setting.

In spite of reading and re-reading the Bv9ARM I just didn't see it, until the reason dawned on me.

Tomorrow I'll re-read the documentation and possibly submit an addition to the documentation so others might benefit.

Edit: I re-read, the information is missing, I've written the text for the issue, but cannot stomach Gitlab right now. ;)

    Remi Gacogne boosted

    [?]PowerDNS » 🌐
    @PowerDNS@fosstodon.org

    JP Mens boosted

    [?]NLnet Labs » 🌐
    @nlnetlabs@social.nlnetlabs.nl

    We’re in the home stretch for Cascade’s first production release. By now it’s a tradition to team up with our house designer, Richard de Ruijter, to design a logo. We’re excited to show it to you now — we hope you like it!

      JP Mens boosted

      [?]NLnet Labs » 🌐
      @nlnetlabs@social.nlnetlabs.nl

      We’re in the home stretch for Cascade’s first production release. By now it’s a tradition to team up with our house designer, Richard de Ruijter, to design a logo. We’re excited to show it to you now — we hope you like it!

        [?]JP Mens » 🌐
        @jpmens@mastodon.social

        As my father (a Dutch man) used to enthusiastically say: "in kleur!"

        For DNSSEC trainings I've had a DS submission tool with which students submit their DS to the parent. This was an awful mess of shell and perl, and this morning I rewrite it in Python, adding a touch of color with termcolor[1]

        The program runs on my workstation as from here the RFC2136 update is performed, so only I see the color.

        [1] pypi.org/project/termcolor/

        screenshot of a failed DNS update (NOTZONE) showing rcode in red

        Alt...screenshot of a failed DNS update (NOTZONE) showing rcode in red

          [?]ChaCha20Poly1305 » 🌐
          @camille@mastodon.libre-entreprise.com

          en : J’ai un ratio 4 pour 2,5 (+60%) en cache par rapport à avant 😅. Je parle du cache du résolveur (je ne graphe pas la mémoire des DNS faisant autorité (mais je devrais 😁)

            [?]Stéphane Bortzmeyer » 🌐
            @bortzmeyer@mastodon.gougere.fr

            @camille La sécurité, c'est pas écologique.

              [?]NLnet Labs » 🌐
              @nlnetlabs@social.nlnetlabs.nl

              We released beta7 of our signer Cascade, named “Gezellig”.

              We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.

              Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other , and projects since last year. This means even the very first production release will be very solid.

              github.com/NLnetLabs/cascade/r

                [?]ChaCha20Poly1305 » 🌐
                @camille@mastodon.libre-entreprise.com

                If you want to sign your zones in with Knot, you will need to turn off semantic checks : "semantic-checks: off" in template (or zone) entry

                I’m using code written by Shumon Huque and Paul Hoffman : github.com/shuque/adns_server

                  John Shaft boosted

                  [?]ChaCha20Poly1305 » 🌐
                  @camille@mastodon.libre-entreprise.com

                  des.services zone : 200 Ko → 5 Mo

                    [?]ChaCha20Poly1305 » 🌐
                    @camille@mastodon.libre-entreprise.com

                    des.services both signed in and 😊

                      [?]ChaCha20Poly1305 » 🌐
                      @camille@mastodon.libre-entreprise.com

                      Bon bah signer des giga-octets de zones en + , c’est un peu pénible (surtout l’implémentation MLDSA44 qui marche pas encore bien)

                        nicolas boosted

                        [?]PowerDNS » 🌐
                        @PowerDNS@fosstodon.org

                        [?]niconiconi » 🌐
                        @niconiconi@mk.absturztau.be

                        Just found a massive footgun if your hostname contains a . (dot), e.g. if you use FQDN directly as /etc/hostname, your gTLD may accidentally become a DNS search domain used by libc. Anyone can register a domain name under your gTLD to bypass DNSSEC.

                        cat rootfs_extra/etc/resolv.conf 
# Use unbound to resolve DNS locally.
#
# Note: since systemd-networkd is used, DNS must be set correctly
# in /etc/systemd/network/default.network. This is only a fallback.
nameserver 127.0.0.1
nameserver ::1

# Use the DNS root as the "local" domain name. Without this setting,
# glibc may derive the "local" search domain from the machine's hostname.
# For example, if the machine's hostname is a FQDN such as example.club,
# dnssec-failed.org falls back to dnssec-failed.org.club, which is a
# valid domain, allowing DNSSEC bypass!
domain .

                        Alt...cat rootfs_extra/etc/resolv.conf # Use unbound to resolve DNS locally. # # Note: since systemd-networkd is used, DNS must be set correctly # in /etc/systemd/network/default.network. This is only a fallback. nameserver 127.0.0.1 nameserver ::1 # Use the DNS root as the "local" domain name. Without this setting, # glibc may derive the "local" search domain from the machine's hostname. # For example, if the machine's hostname is a FQDN such as example.club, # dnssec-failed.org falls back to dnssec-failed.org.club, which is a # valid domain, allowing DNSSEC bypass! domain .

                          Fred de CLX boosted

                          [?]Stéphane Bortzmeyer » 🌐
                          @bortzmeyer@mastodon.gougere.fr

                          Les pros de , si vous vous ennuyez ce week-end, demandez-vous pourquoi a.ns.random.re n'est pas résolvable alors que b.ns.random.re l'est.

                            [?]John Shaft » 🌐
                            @shaft@piaille.fr

                            JP Mens boosted

                            [?]PowerDNS » 🌐
                            @PowerDNS@fosstodon.org

                            Remi Gacogne boosted

                            [?]PowerDNS » 🌐
                            @PowerDNS@fosstodon.org

                            [?]John Shaft » 🌐
                            @shaft@piaille.fr

                            RE: mastodns.net/@diffroot/1171923

                            .ελ goes elliptic before .gr !

                            I guess ICS-FORTH is first testing on a smaller zone before switching their main to algo 13

                              JP Mens boosted

                              [?]PowerDNS » 🌐
                              @PowerDNS@fosstodon.org

                              Erwan 🚄 boosted

                              [?]John Shaft » 🌐
                              @shaft@piaille.fr

                              10026 [and 246]: Operational Recommendations for Delegation Signer (DS) Automation
                              rfc-editor.org/info/rfc10026/

                                AodeRelay boosted

                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                @hugovalters@mastodon.social

                                CVE-2026-55973 - Buffer Overflow in NLnet Labs Unbound 1.23.0-1.25.1. EDNS Report-Channel option mishandling leads to memory corruption. CVSS 7.5. No patch yet. Disable dns-error-reporting immediately.

                                valtersit.com/cve/CVE-2026-559

                                  AodeRelay boosted

                                  [?]NLnet Labs » 🌐
                                  @nlnetlabs@social.nlnetlabs.nl

                                  Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.

                                  Many thanks to the security researchers who responsibly reported these issues.

                                  Release details: community.nlnetlabs.nl/t/unbou

                                    [?]NLnet Labs » 🌐
                                    @nlnetlabs@social.nlnetlabs.nl

                                    @bortzmeyer @oli @jpmens For context, we’re now in “signing co.uk on a regular laptop” territory, with more improvements to come.

                                      JP Mens boosted

                                      [?]NLnet Labs » 🌐
                                      @nlnetlabs@social.nlnetlabs.nl

                                      It's still Friday and we're still doing a Cascade release, so here's 0.1.0-beta5 'Got that holiday feeling'. 🏖️

                                      In this release we're giving you more speed improvements by parallelizing sorting and more memory reduction by improving the handling of NSEC(3) in incremental signing. You can also track all of these improvements with newly introduced metrics.

                                      Thanks again to @bortzmeyer, @oli and @jpmens and others for providing valuable feedback!

                                      github.com/NLnetLabs/cascade/r

                                        [?]gregR ☯ » 🌐
                                        @gregr@mamot.fr

                                        @bortzmeyer @shaft QOTD
                                        > Yes, following DNS stuff on Mastodon is now part of maintaining DNS...
                                        Petit jeu : qui est l'auteur ?
                                        La réponse
                                        mail-archive.com/dns-operation

                                          [?]Stéphane Bortzmeyer » 🌐
                                          @bortzmeyer@mastodon.gougere.fr

                                          Hier, l'Albanie a cassé et la racine a retiré l'enregistrement DS depuis dnsviz.net/d/al/akgJew/dnssec/

                                            [?]John Shaft » 🌐
                                            @shaft@piaille.fr

                                            Albania's .al was secured for a week or so. Wonder what happened. 🤔

                                            DS added to root zone : mastodns.net/@diffroot/1168128
                                            DS removed : mastodns.net/@diffroot/1168577

                                              Remi Gacogne boosted

                                              [?]PowerDNS » 🌐
                                              @PowerDNS@fosstodon.org

                                              JP Mens boosted

                                              [?]PowerDNS » 🌐
                                              @PowerDNS@fosstodon.org

                                              [?]John Shaft » 🌐
                                              @shaft@piaille.fr

                                              JP Mens boosted

                                              [?]PowerDNS » 🌐
                                              @PowerDNS@fosstodon.org

                                              JP Mens boosted

                                              [?]PowerDNS » 🌐
                                              @PowerDNS@fosstodon.org

                                              PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
                                              (aka PowerDNS Authoritative Server 4.9.16, 5.0.6 and 5.1.2 released)

                                              blog.powerdns.com/2026/06/25/p

                                                [?]NLnet Labs » 🌐
                                                @nlnetlabs@social.nlnetlabs.nl

                                                It’s Friday release day again with Cascade 0.1.0-beta2 'Donde comen dos, comen tres'. Thanks to the amazing feedback from @jpmens and @gryphius and hard work from the team, our DNSSEC signer has a bunch of fixes and improvements.

                                                github.com/NLnetLabs/cascade/r

                                                  AodeRelay boosted

                                                  [?]Stéphane Bortzmeyer » 🌐
                                                  @bortzmeyer@mastodon.gougere.fr


                                                  DENIC "Final Report: DNS Outage of 5 May 2026"
                                                  blog.denic.de/en/final-report-

                                                  I'm still frustrated, not all questions are answered.

                                                    JP Mens boosted

                                                    [?]NLnet Labs » 🌐
                                                    @nlnetlabs@social.nlnetlabs.nl

                                                    With Cascade 0.1.0 beta1 “Slàinte mhath” we begin our journey to the first production release of our signing solution.

                                                    We rewritten our signer from the ground up using a state machine based architecture, ensuring that each zone pipeline is in a single consistent state at all times.

                                                    In addition to built-in pre-signing and pre-publication review hooks, there’s now incremental signing, TSIG support, downstream IXFR, zone persistence, metrics and much more.

                                                    blog.nlnetlabs.nl/cascade-beta

                                                      JP Mens boosted

                                                      [?]PowerDNS » 🌐
                                                      @PowerDNS@fosstodon.org

                                                      [?]NLnet Labs » 🌐
                                                      @nlnetlabs@social.nlnetlabs.nl

                                                      @jpmens Ah yes, this link is a more accurate reflection of the past few days. 😄

                                                      github.com/NLnetLabs/cascade/i

                                                      TSIG is mentioned 6 times!

                                                        [?]NLnet Labs » 🌐
                                                        @nlnetlabs@social.nlnetlabs.nl

                                                        With eight issues and one pull request over the weekend, once again we're incredibly thankful for the effort @jpmens is putting into testing Cascade.

                                                        Luckily, none of the reports seem to be in the “everything is broken”-category! 😅

                                                        github.com/NLnetLabs/cascade/i

                                                          John Shaft boosted

                                                          [?]NLnet Labs » 🌐
                                                          @nlnetlabs@social.nlnetlabs.nl

                                                          With the Cascade beta release, the project now also has a dedicated page on our website:

                                                          nlnetlabs.nl/projects/cascade/

                                                          Next up: a logo!

                                                            [?]Stéphane Bortzmeyer » 🌐
                                                            @bortzmeyer@mastodon.gougere.fr

                                                            RFC 9975: Clarifications on CDS/CDNSKEY and CSYNC Consistency

                                                            Pour compléter un processus de sécurisation des noms de domaine avec , il faut transmettre au domaine parent votre clé publique. Le faire manuellement via l'interface Web du BE n'est pas pratique donc il existe un moyen d'automatiser cela, les CDS/CDNSKEY. Mais attention à la sécurité ! Ce moyen n'est sûr que si on suit quelques précautions, décrites dans ce nouveau .

                                                            bortzmeyer.org/9975.html