social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
@shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)
#RFC 10026 [and #BCP 246]: Operational Recommendations for #DNSSEC Delegation Signer (DS) Automation
https://www.rfc-editor.org/info/rfc10026/
Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.
Many thanks to the security researchers who responsibly reported these issues.
Release details: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
@bortzmeyer @oli @jpmens For context, we’re now in “signing co.uk on a regular laptop” territory, with more improvements to come. #DNS #DNSSEC
It's still Friday and we're still doing a Cascade release, so here's 0.1.0-beta5 'Got that holiday feeling'. 🏖️
In this release we're giving you more speed improvements by parallelizing sorting and more memory reduction by improving the handling of NSEC(3) in incremental signing. You can also track all of these improvements with newly introduced metrics.
Thanks again to @bortzmeyer, @oli and @jpmens and others for providing valuable feedback!
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta5
@bortzmeyer @shaft QOTD
> Yes, following DNS stuff on Mastodon is now part of maintaining DNS...
Petit jeu : qui est l'auteur ?
La réponse
https://mail-archive.com/dns-operations@lists.dns-oarc.net/msg09228.html
#dns #dnssec #ccTLD
Hier, l'Albanie a cassé #DNSSEC et la racine a retiré l'enregistrement DS depuis https://dnsviz.net/d/al/akgJew/dnssec/
Albania's .al was secured for a week or so. Wonder what happened. 🤔
DS added to root zone : https://mastodns.net/@diffroot/116812884301667310
DS removed : https://mastodns.net/@diffroot/116857712875727653
It’s Friday release day again with Cascade 0.1.0-beta2 'Donde comen dos, comen tres'. Thanks to the amazing feedback from @jpmens and @gryphius and hard work from the team, our DNSSEC signer has a bunch of fixes and improvements.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta2
#DNSSEC
DENIC "Final Report: DNS Outage of 5 May 2026"
https://blog.denic.de/en/final-report-dns-outage-of-5-may-2026/
I'm still frustrated, not all questions are answered.
With Cascade 0.1.0 beta1 “Slàinte mhath” we begin our journey to the first production release of our #DNSSEC signing solution.
We rewritten our signer from the ground up using a state machine based architecture, ensuring that each zone pipeline is in a single consistent state at all times.
In addition to built-in pre-signing and pre-publication review hooks, there’s now incremental signing, TSIG support, downstream IXFR, zone persistence, metrics and much more. #DNS
@jpmens Ah yes, this link is a more accurate reflection of the past few days. 😄
TSIG is mentioned 6 times!
With eight issues and one pull request over the weekend, once again we're incredibly thankful for the effort @jpmens is putting into testing Cascade.
Luckily, none of the reports seem to be in the “everything is broken”-category! 😅
With the Cascade beta release, the project now also has a dedicated page on our website:
https://nlnetlabs.nl/projects/cascade/about/
Next up: a logo!
After releasing the Cascade beta, NLnet Labs HQ has a @jpmens vs. @bortzmeyer poll going.
Cascade 0.1.0 beta1 “Slàinte mhath” is out, so this is your opportunity to kick the tires and take it for a spin around your testing grounds!
As we gear up to the production release of our DNSSEC signer, we're eager to hear your feedback so we can incorporate it while we add improvements that we still have in the pipeline which we consider essential for production use.
Read all about it in our blog post!
https://blog.nlnetlabs.nl/cascade-beta1-release/
RFC 9975: Clarifications on CDS/CDNSKEY and CSYNC Consistency
Pour compléter un processus de sécurisation des noms de domaine avec #DNSSEC, il faut transmettre au domaine parent votre clé publique. Le faire manuellement via l'interface Web du BE n'est pas pratique donc il existe un moyen d'automatiser cela, les CDS/CDNSKEY. Mais attention à la sécurité ! Ce moyen n'est sûr que si on suit quelques précautions, décrites dans ce nouveau #RFC.
🚨 SECURITY RELEASE 🚨
Today we released Unbound 1.25.1, which consolidates security fixes for issues reported over a period of time.
There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608.
Please read the release notes carefully and plan to upgrade.
#DNS #DNSSEC #Mythos #LLM #OpenSource
https://community.nlnetlabs.nl/t/unbound-1-25-1-released/3392
@ximon18 @dnsoarc after his talk on stage, Ximon will be at the demo table in the lunch area, where he can show all the other tricks Cascade has learned since OARC 45 in Stockholm.
Also, make sure to bring your zone files so you can for example see how fast parallel #Dnssec signing by @bal4e really is. #DNS #LoveDNS #OpenSource
Am I the only one having #DNSSEC problems with #DENIC?
Unbound is throwing me a lot of DNSSEC bogus on some .de domains 🤔
$ dig welt.de
...
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 21366
...
; EDE: 6 (DNSSEC Bogus): (validation failure <welt.de. A IN>: signature crypto failed from 2a02:568:0:2::53 for DS welt.de. while building chain of trust)
Edit: issue seems fixed.
Looks like DE ccTLD is unresolvable due to DNSSEC issue:
https://dnsviz.net/d/nic.de/afpsNg/dnssec/
😬
🧵👇
RE: https://mastodon.social/@jpmens/116522310229612501
IANA has a chance to do the funniest thing ever…
@bortzmeyer après plusieurs timeout
Mais je suis en forêt avec un téléphone
C'est pas idéal pour déboguer :-) surtout #dnssec sur lequel je suis nul