social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
The difference between the two log lines above and the two below is a single named.conf configuration setting.
In spite of reading and re-reading the Bv9ARM I just didn't see it, until the reason dawned on me.
Tomorrow I'll re-read the documentation and possibly submit an addition to the documentation so others might benefit.
Edit: I re-read, the information is missing, I've written the text for the issue, but cannot stomach Gitlab right now. ;)
PowerDNS Recursor 5.3.11 and 5.4.7 Released
https://blog.powerdns.com/2026/10/01/powerdns-recursor-5.3.11-and-5.4.7-released
We’re in the home stretch for Cascade’s first production release. By now it’s a tradition to team up with our house designer, Richard de Ruijter, to design a logo. We’re excited to show it to you now — we hope you like it!
We’re in the home stretch for Cascade’s first production release. By now it’s a tradition to team up with our house designer, Richard de Ruijter, to design a logo. We’re excited to show it to you now — we hope you like it!
As my father (a Dutch man) used to enthusiastically say: "in kleur!"
For DNSSEC trainings I've had a DS submission tool with which students submit their DS to the parent. This was an awful mess of shell and perl, and this morning I rewrite it in Python, adding a touch of color with termcolor[1]
The program runs on my workstation as from here the RFC2136 update is performed, so only I see the color.
We released beta7 of our #DNSSEC signer Cascade, named “Gezellig”.
We can now read TSIG key data from a file, supporting the NSD, BIND, and Knot formats. There are various bug fixes and improvements for using Cascade with an HSM.
Starting today Cascade is being included in the AI-assisted security scanning that has been performed on most of our other #DNS, #BGP and #RPKI projects since last year. This means even the very first production release will be very solid.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta7
If you want to sign your #DNSSEC zones in #MLDSA44 with Knot, you will need to turn off semantic checks : "semantic-checks: off" in template (or zone) entry
I’m using code written by Shumon Huque and Paul Hoffman : https://github.com/shuque/adns_server
PowerDNS DNSdist 2.0.10 Released
https://blog.powerdns.com/2026/09/22/powerdns-dnsdist-2.0.10-released
Les pros de #DNSSEC, si vous vous ennuyez ce week-end, demandez-vous pourquoi a.ns.random.re n'est pas résolvable alors que b.ns.random.re l'est.
PowerDNS DNSdist 2.1.2 and 2.0.9 Released
https://blog.powerdns.com/2026/09/08/powerdns-dnsdist-2.1.2-and-2.0.9
PowerDNS Recursor 5.4.6 Released
https://blog.powerdns.com/2026/09/03/powerdns-recursor-5.4.6-released
RE: https://mastodns.net/@diffroot/117192372456995367
.ελ goes elliptic before .gr !
I guess ICS-FORTH is first testing on a smaller zone before switching their main #TLD to algo 13
First alpha release of PowerDNS Recursor 5.5.0
https://blog.powerdns.com/2026/08/13/first-alpha-release-of-powerdns-recursor-5.5.0
#RFC 10026 [and #BCP 246]: Operational Recommendations for #DNSSEC Delegation Signer (DS) Automation
https://www.rfc-editor.org/info/rfc10026/
Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.
Many thanks to the security researchers who responsibly reported these issues.
Release details: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
@bortzmeyer @oli @jpmens For context, we’re now in “signing co.uk on a regular laptop” territory, with more improvements to come. #DNS #DNSSEC
It's still Friday and we're still doing a Cascade release, so here's 0.1.0-beta5 'Got that holiday feeling'. 🏖️
In this release we're giving you more speed improvements by parallelizing sorting and more memory reduction by improving the handling of NSEC(3) in incremental signing. You can also track all of these improvements with newly introduced metrics.
Thanks again to @bortzmeyer, @oli and @jpmens and others for providing valuable feedback!
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta5
@bortzmeyer @shaft QOTD
> Yes, following DNS stuff on Mastodon is now part of maintaining DNS...
Petit jeu : qui est l'auteur ?
La réponse
https://mail-archive.com/dns-operations@lists.dns-oarc.net/msg09228.html
#dns #dnssec #ccTLD
Hier, l'Albanie a cassé #DNSSEC et la racine a retiré l'enregistrement DS depuis https://dnsviz.net/d/al/akgJew/dnssec/
Albania's .al was secured for a week or so. Wonder what happened. 🤔
DS added to root zone : https://mastodns.net/@diffroot/116812884301667310
DS removed : https://mastodns.net/@diffroot/116857712875727653
PowerDNS DNSdist 2.1.0 Released
https://blog.powerdns.com/2026/07/02/powerdns-dnsdist-2.1.0-released
PowerDNS Authoritative Server 5.1.3 Released
https://blog.powerdns.com/2026/05/30/powerdns-authoritative-server-5.1.3-released
PowerDNS DNSdist 1.9.15 and 2.0.7 Released (Security Release)
https://blog.powerdns.com/2026/06/25/powerdns-dnsdist-1.9.15-and-2.0.7-released-security-release
PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
(aka PowerDNS Authoritative Server 4.9.16, 5.0.6 and 5.1.2 released)
It’s Friday release day again with Cascade 0.1.0-beta2 'Donde comen dos, comen tres'. Thanks to the amazing feedback from @jpmens and @gryphius and hard work from the team, our DNSSEC signer has a bunch of fixes and improvements.
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-beta2
#DNSSEC
DENIC "Final Report: DNS Outage of 5 May 2026"
https://blog.denic.de/en/final-report-dns-outage-of-5-may-2026/
I'm still frustrated, not all questions are answered.
With Cascade 0.1.0 beta1 “Slàinte mhath” we begin our journey to the first production release of our #DNSSEC signing solution.
We rewritten our signer from the ground up using a state machine based architecture, ensuring that each zone pipeline is in a single consistent state at all times.
In addition to built-in pre-signing and pre-publication review hooks, there’s now incremental signing, TSIG support, downstream IXFR, zone persistence, metrics and much more. #DNS
PowerDNS Authoritative Server 5.1.1 Released
https://blog.powerdns.com/2026/06/08/powerdns-authoritative-server-5.1.1-released
@jpmens Ah yes, this link is a more accurate reflection of the past few days. 😄
TSIG is mentioned 6 times!
With eight issues and one pull request over the weekend, once again we're incredibly thankful for the effort @jpmens is putting into testing Cascade.
Luckily, none of the reports seem to be in the “everything is broken”-category! 😅
With the Cascade beta release, the project now also has a dedicated page on our website:
https://nlnetlabs.nl/projects/cascade/about/
Next up: a logo!
RFC 9975: Clarifications on CDS/CDNSKEY and CSYNC Consistency
Pour compléter un processus de sécurisation des noms de domaine avec #DNSSEC, il faut transmettre au domaine parent votre clé publique. Le faire manuellement via l'interface Web du BE n'est pas pratique donc il existe un moyen d'automatiser cela, les CDS/CDNSKEY. Mais attention à la sécurité ! Ce moyen n'est sûr que si on suit quelques précautions, décrites dans ce nouveau #RFC.