social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #dnssec

[?]Stéphane Bortzmeyer » 🌐
@bortzmeyer@mastodon.gougere.fr

RFC 9824: Compact Denial of Existence in DNSSEC

Ce permet à un nom de domaine d'être à la fois existant et non-existant. Plus précisément, il permet de fournir une preuve cryptographique avec , prouvant que le nom existe (alors qu'il n'existe pas) mais n'a pas les données demandées. Cette technique est particulièrement adaptée au cas des signatures dynamiques, mais a l'inconvénient de « mentir ».

bortzmeyer.org/9824.html

    [?]Dryusdan » 🌐
    @Dryusdan@social.dryusdan.fr

    Partage, veille et lecture : A Minimum Complete Tutorial of DNSSEC https://metebalci.com/blog/a-minimum-complete-tutorial-of-dnssec/ A small but complete tutorial of how DNSSEC works. #dns #DNSSEC #Shaarli https://dryusdan.link/shaare/4Z7VtQ

      [?]Stéphane Bortzmeyer » 🌐
      @bortzmeyer@mastodon.gougere.fr

      @gregr Hmmm, DNSviz dnsviz.net/d/hlaor.realtor/aTE et Zonemaster zonemaster.fr/en/result/4a6779 ne voient pas de problème non plus. Il faut les accuser de laxisme ?

      [?]John Shaft » 🌐
      @shaft@piaille.fr

      TLDs using (algorithm 15) for :

      - .fj (Fiji)
      - .pg (Papua New Guinea)
      - .ml (Mali)

        opio ⏚ boosted

        [?]John Shaft » 🌐
        @shaft@piaille.fr

        RE: mastodns.net/@diffroot/1156577

        Mali going secure!

        Third TLD to use . Second one to publish its first DS directly with this algorithim

        \o/

        (poke @camille )

          [?]John Shaft » 🌐
          @shaft@piaille.fr

          Now that RFC 9905 has been published it's time to check if there are still TLDs using the deprecated algorithm 5 and 7 '.

          $ dig +tcp @\c.root-servers.net axfr . > root.zone
          $ grep -P 'IN\tDS' root.zone | grep ' 5 ' | wc -l
          0
          $ grep -P 'IN\tDS' root.zone | grep ' 7 ' | awk '{ print $1}' | sort -u | idn2 -d
          gd.
          kpn.
          la.
          samsung.
          삼성.
          پاکستان.
          ລາວ.

          Aaaaand... Still seven domains using RSASHA1-NSEC3-SHA1

            [?]Jan Wildeboer 😷:krulorange: » 🌐
            @jwildeboer@social.wildeboer.net

            Ultimately I'd prefer a more decentralised system with a "n out of m" architecture. With more than one root key holder, geographically and politically distributed, where you (as user) can declare which root keys you trust. But that is a more complicated discussion for another time. Having one Ceremony Room and the respective amount of key holders that are NOT under US jurisdiction seems to be an achievable and justified goal, in my personal opinion

            3/3

              [?]Jan Wildeboer 😷:krulorange: » 🌐
              @jwildeboer@social.wildeboer.net

              I very well remember the discussions on this question when DNSSEC was introduced back in the days. And while the current system has served us all well in the past years, this fundamental question remains. And now that we have a more complicated world, we should recognise that this is a centralised element that is under the sole jurisdiction of one country that has moved towards more exclusionary, maybe even discrimintaory policies.

              2/3

                AodeRelay boosted

                [?]Jan Wildeboer 😷:krulorange: » 🌐
                @jwildeboer@social.wildeboer.net

                I hope there are some discussions on either moving one of the Ceremony Rooms (AKA Key Management Facilities) to another region/country or maybe add one more outside of the US. Having the responsibility for the DNSSEC root key material in one single country under more and more untrustworthy leadership looks like a risk to me that should be addressed. My personal preference would be a Ceremony Room on UN properties in Geneva.

                1/3

                technotes.seastrom.com/2025/11

                Slide 15 of the slide deck A BRIEF PRIMER ON MANAGING THE KEYS TO THE INTERNET by DAVID HUBERMAN, ICANN’s OFFICE OF THE CTO, showing the location of the two ceremony rooms. One is in Culpeper, Virginia, teh  other one is in El Segundo, California. Slidedeck available at https://technotes.seastrom.com/assets/2025-11-23-passing-the-torch/2-David-Huberman_DNS-security-and-the-Root-DNSSEC-KSK-Ceremony.pdf

                Alt...Slide 15 of the slide deck A BRIEF PRIMER ON MANAGING THE KEYS TO THE INTERNET by DAVID HUBERMAN, ICANN’s OFFICE OF THE CTO, showing the location of the two ceremony rooms. One is in Culpeper, Virginia, teh other one is in El Segundo, California. Slidedeck available at https://technotes.seastrom.com/assets/2025-11-23-passing-the-torch/2-David-Huberman_DNS-security-and-the-Root-DNSSEC-KSK-Ceremony.pdf

                  AodeRelay boosted

                  [?]NLnet Labs » 🌐
                  @nlnetlabs@social.nlnetlabs.nl

                  Thanks to @jpmens we now have documentation for Cascade describing how to integrate with a Nitrokey NetHSM to store your DNSSEC keys.

                  Thanks a lot! 🧡

                  cascade.docs.nlnetlabs.nl/en/l

                    [?]John Shaft » 🌐
                    @shaft@piaille.fr

                    🫡

                    'Zohran' sign meme: DNSSEC for every domain

                    Alt...'Zohran' sign meme: DNSSEC for every domain

                      [?]Stéphane Bortzmeyer » 🌐
                      @bortzmeyer@mastodon.gougere.fr


                      Ce matin, si vous avez testé, un de mes domaines personnels, bortzmeyer.fr, présentait des problèmes . Que s'est-il passé ? Était-ce de ma faute ? Va t-on tous mourir ?

                      bortzmeyer.org/dnssec-panne-pe

                        Pep boosted

                        [?]Stéphane Bortzmeyer » 🌐
                        @bortzmeyer@mastodon.gougere.fr

                        Le rappel du jour que, si vous faites du , il n'est pas indispensable d'avoir ZSK et KSK. Une seule clé, c'est parfaitement possible et sûr. dnsviz.net/d/xn--potamochre-66

                          [?]NLnet Labs » 🌐
                          @nlnetlabs@social.nlnetlabs.nl

                          This week, @terts is working from France, doing field research for our signer.

                          A road sign in rural France saying “Cascade, Cimetières, Tour Bellana and Panorama”, with a separate sign saying “SNACK”.

                          Alt...A road sign in rural France saying “Cascade, Cimetières, Tour Bellana and Panorama”, with a separate sign saying “SNACK”.

                            e-Jim 🖧 boosted

                            [?]Stéphane Bortzmeyer » 🌐
                            @bortzmeyer@mastodon.gougere.fr

                            J'ai déjà parlé de , un logiciel de @nlnetlabs actuellement en développement, qui automatise un certain nombre de tâches nécessaires pour comme la re-signature ou le remplacement des clés. Le projet avance vite donc voyons quelques nouveaux essais.

                            bortzmeyer.org/cascade-deux.ht

                            @alexband

                              JP Mens boosted

                              [?]NLnet Labs » 🌐
                              @nlnetlabs@social.nlnetlabs.nl

                              Just before the weekend starts, we're happy to introduce Cascade 0.1.0-alpha3 'Rue des Cascades'. 🚏

                              This release of our stand-alone signer primarily expands the documentation, but also fixes a few important bugs.

                              Our plan is to do one or two more alpha releases and then focus on the road ahead toward betas and production.

                              Once again, many thanks to everyone who provided feedback, in particular @jpmens, @bortzmeyer and @oli. 🧡

                              github.com/NLnetLabs/cascade/r

                                [?]John Shaft » 🔓
                                @shaft@piaille.fr

                                Thanks to @diffroot, we can see that .pg wasn't using until last April. .pg is thus the 1st TLD to implement DNSSEC directly with ed25519

                                mastodns.net/@diffroot/1144008

                                  [?]John Shaft » 🌐
                                  @shaft@piaille.fr

                                  Yay, another using algorithm 15 (ed25519) for its KSK : .pg! (Papua New Guinea 🇵🇬)

                                  (Other one being .fj :) )

                                  piaille.fr/@shaft/115422575883

                                    AodeRelay boosted

                                    [?]NLnet Labs » 🌐
                                    @nlnetlabs@social.nlnetlabs.nl

                                    Unbound 1.24.1 is now available.

                                    This security release fixes CVE-2025-11411.

                                    Several multi-vendor cache poisoning vulnerabilities have been discovered in caching resolvers for non-DNSSEC protected data. Unbound is vulnerable for some of these cases that could lead to domain hijacking.

                                    Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect.

                                    nlnetlabs.nl/news/2025/Oct/22/

                                      JP Mens boosted

                                      [?]NLnet Labs » 🌐
                                      @nlnetlabs@social.nlnetlabs.nl

                                      🚀 Cascade v0.1.0-alpha2 'Cascader la Vertu' is now available!

                                      Over the last week we diligently processed your feedback to fix bugs, clarify error messages, add commands, improve performance, expand documentation and much, much more.

                                      Read the release notes for all the details!

                                      Note that you cannot simply upgrade from alpha1, read the installation docs for details.

                                      Many thanks to everyone who provided feedback, particularly @jpmens and @bortzmeyer. 🧡

                                      github.com/NLnetLabs/cascade/r

                                        [?]Stéphane Bortzmeyer » 🌐
                                        @bortzmeyer@mastodon.gougere.fr

                                        Plaignons toustes ensemble le nouveau Bureau d'Enregistrement de mes noms de domaine, que j'assomme avec plein de tickets.

                                        [?]Ludovic :Firefox: :FreeBSD: » 🌐
                                        @usul@piaille.fr

                                        In the recent ICANN Registrations Operation Workshop 30th September 2025, the
                                        following data was shared about DNSSEC Validation Rates

                                        - Region / Rate / Increase since 2023
                                        - Asia 32% +4%
                                        - Oceania 54% +11%
                                        - Africa 46% +15%
                                        - Americas 37% +4%
                                        - Europe 48% +8%

                                          [?]NLnet Labs » 🌐
                                          @nlnetlabs@social.nlnetlabs.nl

                                          The community is amazing because people like @bortzmeyer will take your alpha software, turn it inside out, blog about it in French and then give you meticulous feedback on your work.

                                          As a result, a stand-out feature of Cascade—the Review Hooks—have now made it into the documentation using an example provided by Stéphane: using `validns` to validate the unsigned zone, and `dnssec-verify` to validate the signed zone.

                                          cascade.docs.nlnetlabs.nl/en/l

                                          Docs with 🧡 by @themozzie

                                          A bash script that shows how Cascade’s review hooks can use validns to validate the unsigned zone, and dnssec-verify to validate the signed zone.

                                          Alt...A bash script that shows how Cascade’s review hooks can use validns to validate the unsigned zone, and dnssec-verify to validate the signed zone.

                                            [?]NLnet Labs » 🌐
                                            @nlnetlabs@social.nlnetlabs.nl

                                            We're incredibly grateful for the feedback we're receiving on the first alpha release of Cascade. Please keep an eye on the issues that were created so far, and the milestone we set for the next release:

                                            github.com/NLnetLabs/cascade/m

                                            We aiming for the end of this week for alpha2.Meanwhile, the documentation is growing every day.

                                              JP Mens boosted

                                              [?]Stéphane Bortzmeyer » 🌐
                                              @bortzmeyer@mastodon.gougere.fr

                                              Annoncé officiellement le 7 octobre, est le successeur d'. Ce programme sert à gérer automatiquement les opérations répétitives liées à comme la re-signature ou le remplacement d'une clé. Premiers essais : bortzmeyer.org/cascade-debut.h

                                                [?]NLnet Labs » 🌐
                                                @nlnetlabs@social.nlnetlabs.nl

                                                Because @jpmens is absolutely awesome, we now have Cascade documentation for integrating with the Smartcard-HSM.

                                                cascade.docs.nlnetlabs.nl/en/l

                                                  [?]NLnet Labs » 🌐
                                                  @nlnetlabs@social.nlnetlabs.nl

                                                  In case you missed Verisign's presentation on Post-Quantum Diversity for at yesterday, it mentions the use of Jannik Peters’ master's thesis for the University of Amsterdam.

                                                  Jannik has since joined NLnet Labs full-time and is both on the Cascade team *and* gave you support for AF_XDP sockets in NSD.

                                                  We feel so blessed to have so much bright young talent on the team now.

                                                    [?]NLnet Labs » 🌐
                                                    @nlnetlabs@social.nlnetlabs.nl

                                                    Cascade feedback is already rolling in!

                                                    github.com/NLnetLabs/cascade/i

                                                    Thank you, this is what makes the DNS community great.

                                                      [?]NLnet Labs » 🌐
                                                      @nlnetlabs@social.nlnetlabs.nl

                                                      @jpmens @bortzmeyer @oli You're all just in time to watch Arya’s demo. This in itself is a fantastic achievement.

                                                        JP Mens boosted

                                                        [?]NLnet Labs » 🌐
                                                        @nlnetlabs@social.nlnetlabs.nl

                                                        Live from DNS-OARC 45, happy Cascade launch day everyone! 🚀

                                                        There are now alpha packages available for Debian, Ubuntu, RHEL and derivatives.

                                                        If you can’t wait for Arya’s presentation and demo at 16:35 CEST, you can already try to follow our installation and quick start guide in the documentation.

                                                        cascade.docs.nlnetlabs.nl/

                                                        Who will be the first person to show the log output of a zone signed with Cascade — will it be @jpmens, @bortzmeyer or a surprise challenger?

                                                        The result of `sudo apt install cascade` on a Debian Trixie VM.

                                                        Alt...The result of `sudo apt install cascade` on a Debian Trixie VM.

                                                          [?]Peregrine Fleuré Tremayne » 🌐
                                                          @pft@infosec.exchange

                                                          @RadND @oemb1905 nope. An OV (or any web ) cert must first confirm domain ownership and without that verification is not very reliable.

                                                            [?]Pineking Thintree » 🌐
                                                            @RadND@gnulinux.social

                                                            @oemb1905 So as a consumer, with I can assurance a given domain is belong to a specific owner?
                                                            I just realized an OV ssl certificate can do the same thing.

                                                              [?]Stéphane Bortzmeyer » 🔓
                                                              @bortzmeyer@mastodon.gougere.fr

                                                              Déjà, le domaine utilisé pour les travaux pratiques fonctionne. dnsviz.net/d/courbu.re/aN4hFw/

                                                                [?]John Shaft » 🌐
                                                                @shaft@piaille.fr

                                                                [?]John Shaft » 🌐
                                                                @shaft@piaille.fr

                                                                One more straw on the camel's back! Yay! \o/

                                                                Compact Denial of Existence in is finally published as RFC 9824

                                                                Introducing a new EDNS header flag: CO (Compact Answers OK). As it's the first time a new one is added, it will surely run smoothly with stupid middleboxes \o/

                                                                It additionnaly adds more traditionnal stuff: a new RR (NXNAME) and a new EDE (Invalid Query Type)

                                                                rfc-editor.org/info/rfc9824

                                                                  0 ★ 3 ↺
                                                                  victor héry boosted

                                                                  [?]oldsysops » 🌐
                                                                  @oldsysops@social.dk-libre.fr

                                                                  Have a question on DNSSEC KEY rollover (and bind).
                                                                  If i set up inline-signing and dnssec-policy on a zone, the key will rollover automatically ?
                                                                  I've just to put the DS record once, and it will rotate without an issue ?


                                                                    [?]NLnet Labs » 🌐
                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                    @bortzmeyer @benno @alexband We love your enthusiasm, but right now we're putting together all the components that make up Cascade. By the time @dnsoarc 45 comes around, we'll have a package for you that you can just run.

                                                                    We've got the scaffolding for the installation documentation sitting in a Pull Request here: cascade-signer--41.org.readthe

                                                                      AodeRelay boosted

                                                                      [?]NLnet Labs » 🌐
                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                      Tuesday, we dropped our report with insights from 16 top-level domain operators.

                                                                      Yesterday, we launched Cascade — NLnet Labs’ Rust-built successor to OpenDNSSEC, shaped by what keeps TLDs up at night.

                                                                      Today, we’re kicking off a series of ultrashort videos where @benno and @alexband break down what makes Cascade different.

                                                                      First up: the #1 request from the community — observability, please.

                                                                      We heard you.

                                                                      🎥. youtu.be/CgmVjLv-fy4

                                                                        Alexandre :freebsd: boosted

                                                                        [?]NLnet Labs » 🌐
                                                                        @nlnetlabs@social.nlnetlabs.nl

                                                                        🚨 Announcing Cascade — DNSSEC signing, rebuilt from the ground up.

                                                                        With 25 years of experience, we set the standard with signing that delivers under pressure.
                                                                        Cascade is how we carry the legacy forward.

                                                                        Explore Cascade at blog.nlnetlabs.nl/cascade/

                                                                        Unbox with us.
                                                                        Cascade debuts live October 7 @ @dnsoarc 45, Stockholm.
                                                                        We’ll show you what’s under the hood — and why this changes everything.

                                                                        A huge thanks to the DNS community for making Cascade possible!

                                                                          AodeRelay boosted

                                                                          [?]NLnet Labs » 🌐
                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                          Tomorrow we drop details on the DNSSEC signer we built.
                                                                          Today, we're dropping the pretence.

                                                                          Before we wrote a line of code, we asked 16 TLDs:
                                                                          "What keeps you up at night?"

                                                                          We expected shop talk.
                                                                          We got meaningful discussions that taught us DNSSEC in 2025 isn’t just a tech issue.
                                                                          It’s a control issue.
                                                                          And the fear of losing it is real.

                                                                          👉 Read the full report: blog.nlnetlabs.nl/dnssec-opera

                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                            Pecha-Kucha (funny talk) of Barbara Jantzen at the last meeting, about . Next time you have a DNSSEC issue, watch the video. youtube.com/watch?v=7mQ5x7Jpj4

                                                                            (For my French-speaking followers: good level of englsh required.)

                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                              A error I had never seen in the wild before. Discrepancy between the "original TTL" field of the signature and the real original TTL.

                                                                              dnsviz.net/d/culture.gouv.fr/a

                                                                              (Look hard, it happens only with one of the three NSEC3 records.)

                                                                                [?]NLnet Labs » 🌐
                                                                                @nlnetlabs@social.nlnetlabs.nl

                                                                                The industry loves to boast about “five nines” availability — 99.999%. That sounds impressive: just five minutes of downtime a year.

                                                                                But isn’t like most industries. Read more about today’s TLD challenges in our blog post The Illusion of Five Nines. blog.nlnetlabs.nl/the-illusion

                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                  But I find strange that is not mentioned when the author speaks about checking the content of the root zone.
                                                                                  ZONEMD, which is mentioned, works only if the client downloads the entire root zone, something that the typical resolver does not do.

                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                    Changer de BE (Bureau d'Enregistrement), cela implique quoi en pratique ? Un récit très détaillé et très bien vu d'un titulaire qui veut échapper aux augmentations de tarif de Gandi shaarli.guiguishow.info/?hCft1