social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #dnssec

[?]John Shaft »
@shaft@piaille.fr

🫡

'Zohran' sign meme: DNSSEC for every domain

Alt...'Zohran' sign meme: DNSSEC for every domain

    [?]JP Mens »
    @jpmens@mastodon.social

    The case of the missing WALLET

    What I make sound like an adventure story is not something I am making fun of; having a domain kaputted by something like this sucks big time.

    lists.opendnssec.org/pipermail

    The full story, by @bortzmeyer, in French at bortzmeyer.org/dnssec-panne-pe

      [?]Stéphane Bortzmeyer »
      @bortzmeyer@mastodon.gougere.fr


      Ce matin, si vous avez testé, un de mes domaines personnels, bortzmeyer.fr, présentait des problèmes . Que s'est-il passé ? Était-ce de ma faute ? Va t-on tous mourir ?

      bortzmeyer.org/dnssec-panne-pe

        [?]Daniel ".koolfy" Faucon »
        @koolfy@social.bim.land

        Refaire tout son setup réseau en ipv6 et en profiter pour déménager son authorité DNS chez soi, chercher comment activer avec et...

        Retomber sur un article de @lord datant de 2018 et détaillant exactement ce que je cherchais :D

        lord.re/posts/129-dnssec-chez-

          [?]JP Mens »
          @jpmens@mastodon.social

          My goto example for a zone signed with a flags=256 CSK only, .co.uk, appears to be going ZSK/KSK as was whispered to me some weeks ago in jpmens.net/2025/05/19/migratin

          (Note to self: need bigger phone)

          dnsviz.net/d/co.uk/dnssec/

            Pep boosted

            [?]Stéphane Bortzmeyer »
            @bortzmeyer@mastodon.gougere.fr

            Le rappel du jour que, si vous faites du , il n'est pas indispensable d'avoir ZSK et KSK. Une seule clé, c'est parfaitement possible et sûr. dnsviz.net/d/xn--potamochre-66

              [?]NLnet Labs »
              @nlnetlabs@social.nlnetlabs.nl

              This week, @terts is working from France, doing field research for our signer.

              A road sign in rural France saying “Cascade, Cimetières, Tour Bellana and Panorama”, with a separate sign saying “SNACK”.

              Alt...A road sign in rural France saying “Cascade, Cimetières, Tour Bellana and Panorama”, with a separate sign saying “SNACK”.

                e-Jim 🖧 boosted

                [?]Stéphane Bortzmeyer »
                @bortzmeyer@mastodon.gougere.fr

                J'ai déjà parlé de , un logiciel de @nlnetlabs actuellement en développement, qui automatise un certain nombre de tâches nécessaires pour comme la re-signature ou le remplacement des clés. Le projet avance vite donc voyons quelques nouveaux essais.

                bortzmeyer.org/cascade-deux.ht

                @alexband

                  [?]Alex Band »
                  @alexband@hachyderm.io

                  Looking forward to present @nlnetlabs’ research on TLD operations in the and Security Workshop at , starting today at 13:15 hrs UTC.

                  Title slide reading “DNSSEC in 2026: What keeps TLDs up at night”

                  Alt...Title slide reading “DNSSEC in 2026: What keeps TLDs up at night”

                    John Shaft boosted

                    [?]Alex Band »
                    @alexband@hachyderm.io

                    My blurred background was somehow disabled so everyone could enjoy "sleeping cat in front of piano"-view. 😅

                    A red cat sleeping on the piano bench in front of a black piano.

                    Alt...A red cat sleeping on the piano bench in front of a black piano.

                      JP Mens boosted

                      [?]NLnet Labs »
                      @nlnetlabs@social.nlnetlabs.nl

                      Just before the weekend starts, we're happy to introduce Cascade 0.1.0-alpha3 'Rue des Cascades'. 🚏

                      This release of our stand-alone signer primarily expands the documentation, but also fixes a few important bugs.

                      Our plan is to do one or two more alpha releases and then focus on the road ahead toward betas and production.

                      Once again, many thanks to everyone who provided feedback, in particular @jpmens, @bortzmeyer and @oli. 🧡

                      github.com/NLnetLabs/cascade/r

                        [?]Alex Band »
                        @alexband@hachyderm.io

                        @bortzmeyer @jpmens @themozzie @terts @bal4e Our original plan was to gather all fixes and improvements we have merged in Cascade 0.1.0-alpha3 today, but we feel it better to first fully understand and resolve issue #252 before proceeding.

                        We intend to get Cascade to an alpha stage where it does all the basic operations correctly in a predictable manner. Then we'll pause the alphas, while we plan and execute the path towards beta and production releases.

                          [?]John Shaft »
                          @shaft@piaille.fr

                          Thanks to @diffroot, we can see that .pg wasn't using until last April. .pg is thus the 1st TLD to implement DNSSEC directly with ed25519

                          mastodns.net/@diffroot/1144008

                            [?]John Shaft »
                            @shaft@piaille.fr

                            Yay, another using algorithm 15 (ed25519) for its KSK : .pg! (Papua New Guinea 🇵🇬)

                            (Other one being .fj :) )

                            piaille.fr/@shaft/115422575883

                              AodeRelay boosted

                              [?]NLnet Labs »
                              @nlnetlabs@social.nlnetlabs.nl

                              Unbound 1.24.1 is now available.

                              This security release fixes CVE-2025-11411.

                              Several multi-vendor cache poisoning vulnerabilities have been discovered in caching resolvers for non-DNSSEC protected data. Unbound is vulnerable for some of these cases that could lead to domain hijacking.

                              Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect.

                              nlnetlabs.nl/news/2025/Oct/22/

                                JP Mens boosted

                                [?]NLnet Labs »
                                @nlnetlabs@social.nlnetlabs.nl

                                🚀 Cascade v0.1.0-alpha2 'Cascader la Vertu' is now available!

                                Over the last week we diligently processed your feedback to fix bugs, clarify error messages, add commands, improve performance, expand documentation and much, much more.

                                Read the release notes for all the details!

                                Note that you cannot simply upgrade from alpha1, read the installation docs for details.

                                Many thanks to everyone who provided feedback, particularly @jpmens and @bortzmeyer. 🧡

                                github.com/NLnetLabs/cascade/r

                                  [?]ChaCha20Poly1305 »
                                  @camille@mastodon.libre-entreprise.com

                                  @bortzmeyer y'a @lebureau_coop qui est au poil pour le . J'ai même pas eu le temps de contrôler que tout marchait.

                                    [?]Stéphane Bortzmeyer »
                                    @bortzmeyer@mastodon.gougere.fr

                                    Plaignons toustes ensemble le nouveau Bureau d'Enregistrement de mes noms de domaine, que j'assomme avec plein de tickets.

                                    [?]Ludovic :Firefox: :FreeBSD: »
                                    @usul@piaille.fr

                                    In the recent ICANN Registrations Operation Workshop 30th September 2025, the
                                    following data was shared about DNSSEC Validation Rates

                                    - Region / Rate / Increase since 2023
                                    - Asia 32% +4%
                                    - Oceania 54% +11%
                                    - Africa 46% +15%
                                    - Americas 37% +4%
                                    - Europe 48% +8%

                                      [?]NLnet Labs »
                                      @nlnetlabs@social.nlnetlabs.nl

                                      The community is amazing because people like @bortzmeyer will take your alpha software, turn it inside out, blog about it in French and then give you meticulous feedback on your work.

                                      As a result, a stand-out feature of Cascade—the Review Hooks—have now made it into the documentation using an example provided by Stéphane: using `validns` to validate the unsigned zone, and `dnssec-verify` to validate the signed zone.

                                      cascade.docs.nlnetlabs.nl/en/l

                                      Docs with 🧡 by @themozzie

                                      A bash script that shows how Cascade’s review hooks can use validns to validate the unsigned zone, and dnssec-verify to validate the signed zone.

                                      Alt...A bash script that shows how Cascade’s review hooks can use validns to validate the unsigned zone, and dnssec-verify to validate the signed zone.

                                        [?]Alex Band »
                                        @alexband@hachyderm.io

                                        Thank you @paulehoffman and Fujiwara-san for RFC 9499 “DNS Terminology”.

                                        I’ve used it as the basis for a glossary in the documentation of @nlnetlabs’ new DNSSEC signer, Cascade.

                                        It's incredibly helpful when creating a comprehensive user guide to have all these terms available as a reference. 🙏

                                        cascade.docs.nlnetlabs.nl/en/l

                                          [?]NLnet Labs »
                                          @nlnetlabs@social.nlnetlabs.nl

                                          We're incredibly grateful for the feedback we're receiving on the first alpha release of Cascade. Please keep an eye on the issues that were created so far, and the milestone we set for the next release:

                                          github.com/NLnetLabs/cascade/m

                                          We aiming for the end of this week for alpha2.Meanwhile, the documentation is growing every day.

                                            [?]Alex Band »
                                            @alexband@hachyderm.io

                                            @bortzmeyer @jpmens Your stance on compiling alphas and betas gets a lot of respect from the @nlnetlabs dev team!

                                            With regards to the comments about Cascade waiting to display the DS record, this is not by design. We currently lack commands to get the DS (and DNSKEY, CDS, CDNSKEY) records out of keyset and show them to the user. We’ll add this in an upcoming release.

                                            Here's what we have lined up so far, with more to come:
                                            github.com/NLnetLabs/cascade/m

                                              [?]Alex Band »
                                              @alexband@hachyderm.io

                                              @bortzmeyer @jpmens Thanks a lot for sharing your experiences with Cascade.

                                              We have a couple of questions. First is why you compiled the Rust code yourself, instead of using a Deb/RPM package. Is that a matter of preference or do you use a platform we don’t offer packages for?

                                                JP Mens boosted

                                                [?]Stéphane Bortzmeyer »
                                                @bortzmeyer@mastodon.gougere.fr

                                                Annoncé officiellement le 7 octobre, est le successeur d'. Ce programme sert à gérer automatiquement les opérations répétitives liées à comme la re-signature ou le remplacement d'une clé. Premiers essais : bortzmeyer.org/cascade-debut.h

                                                  JP Mens boosted

                                                  [?]Alex Band »
                                                  @alexband@hachyderm.io

                                                  I'm honored to have been elected as Board Member at @dnsoarc.

                                                    [?]NLnet Labs »
                                                    @nlnetlabs@social.nlnetlabs.nl

                                                    Because @jpmens is absolutely awesome, we now have Cascade documentation for integrating with the Smartcard-HSM.

                                                    cascade.docs.nlnetlabs.nl/en/l

                                                      [?]NLnet Labs »
                                                      @nlnetlabs@social.nlnetlabs.nl

                                                      In case you missed Verisign's presentation on Post-Quantum Diversity for at yesterday, it mentions the use of Jannik Peters’ master's thesis for the University of Amsterdam.

                                                      Jannik has since joined NLnet Labs full-time and is both on the Cascade team *and* gave you support for AF_XDP sockets in NSD.

                                                      We feel so blessed to have so much bright young talent on the team now.

                                                        [?]NLnet Labs »
                                                        @nlnetlabs@social.nlnetlabs.nl

                                                        Cascade feedback is already rolling in!

                                                        github.com/NLnetLabs/cascade/i

                                                        Thank you, this is what makes the DNS community great.

                                                          [?]NLnet Labs »
                                                          @nlnetlabs@social.nlnetlabs.nl

                                                          @jpmens @bortzmeyer @oli You're all just in time to watch Arya’s demo. This in itself is a fantastic achievement.

                                                            JP Mens boosted

                                                            [?]NLnet Labs »
                                                            @nlnetlabs@social.nlnetlabs.nl

                                                            Live from DNS-OARC 45, happy Cascade launch day everyone! 🚀

                                                            There are now alpha packages available for Debian, Ubuntu, RHEL and derivatives.

                                                            If you can’t wait for Arya’s presentation and demo at 16:35 CEST, you can already try to follow our installation and quick start guide in the documentation.

                                                            cascade.docs.nlnetlabs.nl/

                                                            Who will be the first person to show the log output of a zone signed with Cascade — will it be @jpmens, @bortzmeyer or a surprise challenger?

                                                            The result of `sudo apt install cascade` on a Debian Trixie VM.

                                                            Alt...The result of `sudo apt install cascade` on a Debian Trixie VM.

                                                              [?]Stéphane Bortzmeyer »
                                                              @bortzmeyer@mastodon.gougere.fr

                                                              Déjà, le domaine utilisé pour les travaux pratiques fonctionne. dnsviz.net/d/courbu.re/aN4hFw/

                                                                [?]Alex Band »
                                                                @alexband@hachyderm.io

                                                                @beasts @onepict Thanks for joining the panel! These kinds of funds are an absolute life saver for the community.

                                                                Maintaining our existing product portfolio is relatively sustainable for a like ours, but doing something new to stay current and relevant, like we're now doing with our signer Cascade, is incredibly difficult.

                                                                  [?]Afnic »
                                                                  @afnic@mastodon.social

                                                                  📢 J-1 avant le webinaire sur le protocole DNSSEC

                                                                  🤔 Vous voulez savoir comment déployer DNSSEC et vous protéger contre le détournement des réponses DNS ?

                                                                  📅 Jeudi 25 septembre, de 14h à 15h, participez à notre webinaire gratuit organisé par l'Afnic et animé par Stéphane Bortzmeyer, Michaël Timbert et Lotfi Benyelles.

                                                                  🔗 Pour vous inscrire : webikeo.fr/landing/protocole-d

                                                                  Webinaire Protocole DNSSEC Comment le déployer et prévenir le détournement des réponses DNS ? Jeudi 25 septembre 14h - 15h

                                                                  Alt...Webinaire Protocole DNSSEC Comment le déployer et prévenir le détournement des réponses DNS ? Jeudi 25 septembre 14h - 15h

                                                                    [?]Alex Band »
                                                                    @alexband@hachyderm.io

                                                                    @bortzmeyer @benno @alexband You'll be happy to hear we were able to remove 18 direct dependencies, so building Cascade with `cargo` went from 343 to 304 crates.

                                                                    github.com/NLnetLabs/cascade/p

                                                                      [?]John Shaft »
                                                                      @shaft@piaille.fr

                                                                      [?]John Shaft »
                                                                      @shaft@piaille.fr

                                                                      One more straw on the camel's back! Yay! \o/

                                                                      Compact Denial of Existence in is finally published as RFC 9824

                                                                      Introducing a new EDNS header flag: CO (Compact Answers OK). As it's the first time a new one is added, it will surely run smoothly with stupid middleboxes \o/

                                                                      It additionnaly adds more traditionnal stuff: a new RR (NXNAME) and a new EDE (Invalid Query Type)

                                                                      rfc-editor.org/info/rfc9824

                                                                        0 ★ 3 ↺
                                                                        victor héry boosted

                                                                        [?]oldsysops »
                                                                        @oldsysops@social.dk-libre.fr

                                                                        Have a question on DNSSEC KEY rollover (and bind).
                                                                        If i set up inline-signing and dnssec-policy on a zone, the key will rollover automatically ?
                                                                        I've just to put the DS record once, and it will rotate without an issue ?


                                                                          [?]Alex Band »
                                                                          @alexband@hachyderm.io

                                                                          @bortzmeyer @nlnetlabs @benno Maybe wait talking about it on TV until you can show a DNSViz result of a domain signed by Cascade?

                                                                            [?]Alex Band »
                                                                            @alexband@hachyderm.io

                                                                            @bortzmeyer @nlnetlabs @benno @dnsoarc We'll do a live demo on stage at OARC45—what could possibly go wrong? 😉

                                                                            So after that, we look forward to you running Cascade through its paces and give us your honest feedback.

                                                                            That should put us in a position to cross all the t's and dot all the i's before the first production release, towards the end of the year.

                                                                              [?]NLnet Labs »
                                                                              @nlnetlabs@social.nlnetlabs.nl

                                                                              @bortzmeyer @benno @alexband We love your enthusiasm, but right now we're putting together all the components that make up Cascade. By the time @dnsoarc 45 comes around, we'll have a package for you that you can just run.

                                                                              We've got the scaffolding for the installation documentation sitting in a Pull Request here: cascade-signer--41.org.readthe

                                                                                [?]ChaCha20Poly1305 »
                                                                                @camille@mastodon.libre-entreprise.com

                                                                                Il semblerait que active « filterwin2k » silencieusement quand « dnssec » est activé, ce qui filtre les SRV et les TLSA. Bref j’ai viré dnsmasq pour le et l’ai remplacé par

                                                                                CC @bortzmeyer @shaft

                                                                                  AodeRelay boosted

                                                                                  [?]NLnet Labs »
                                                                                  @nlnetlabs@social.nlnetlabs.nl

                                                                                  Tuesday, we dropped our report with insights from 16 top-level domain operators.

                                                                                  Yesterday, we launched Cascade — NLnet Labs’ Rust-built successor to OpenDNSSEC, shaped by what keeps TLDs up at night.

                                                                                  Today, we’re kicking off a series of ultrashort videos where @benno and @alexband break down what makes Cascade different.

                                                                                  First up: the #1 request from the community — observability, please.

                                                                                  We heard you.

                                                                                  🎥. youtu.be/CgmVjLv-fy4

                                                                                    Alexandre :freebsd: boosted

                                                                                    [?]NLnet Labs »
                                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                                    🚨 Announcing Cascade — DNSSEC signing, rebuilt from the ground up.

                                                                                    With 25 years of experience, we set the standard with signing that delivers under pressure.
                                                                                    Cascade is how we carry the legacy forward.

                                                                                    Explore Cascade at blog.nlnetlabs.nl/cascade/

                                                                                    Unbox with us.
                                                                                    Cascade debuts live October 7 @ @dnsoarc 45, Stockholm.
                                                                                    We’ll show you what’s under the hood — and why this changes everything.

                                                                                    A huge thanks to the DNS community for making Cascade possible!

                                                                                      AodeRelay boosted

                                                                                      [?]NLnet Labs »
                                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                                      Tomorrow we drop details on the DNSSEC signer we built.
                                                                                      Today, we're dropping the pretence.

                                                                                      Before we wrote a line of code, we asked 16 TLDs:
                                                                                      "What keeps you up at night?"

                                                                                      We expected shop talk.
                                                                                      We got meaningful discussions that taught us DNSSEC in 2025 isn’t just a tech issue.
                                                                                      It’s a control issue.
                                                                                      And the fear of losing it is real.

                                                                                      👉 Read the full report: blog.nlnetlabs.nl/dnssec-opera

                                                                                        [?]Stéphane Bortzmeyer »
                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                        Pecha-Kucha (funny talk) of Barbara Jantzen at the last meeting, about . Next time you have a DNSSEC issue, watch the video. youtube.com/watch?v=7mQ5x7Jpj4

                                                                                        (For my French-speaking followers: good level of englsh required.)

                                                                                          [?]Stéphane Bortzmeyer »
                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                          A error I had never seen in the wild before. Discrepancy between the "original TTL" field of the signature and the real original TTL.

                                                                                          dnsviz.net/d/culture.gouv.fr/a

                                                                                          (Look hard, it happens only with one of the three NSEC3 records.)

                                                                                            [?]NLnet Labs »
                                                                                            @nlnetlabs@social.nlnetlabs.nl

                                                                                            The industry loves to boast about “five nines” availability — 99.999%. That sounds impressive: just five minutes of downtime a year.

                                                                                            But isn’t like most industries. Read more about today’s TLD challenges in our blog post The Illusion of Five Nines. blog.nlnetlabs.nl/the-illusion

                                                                                              [?]Stéphane Bortzmeyer »
                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                              But I find strange that is not mentioned when the author speaks about checking the content of the root zone.
                                                                                              ZONEMD, which is mentioned, works only if the client downloads the entire root zone, something that the typical resolver does not do.

                                                                                                opio ⏚ boosted

                                                                                                [?]Afnic »
                                                                                                @afnic@mastodon.social

                                                                                                🤔 Comment déployer DNSSEC et se prévenir du détournement des réponses DNS ?

                                                                                                📅 Webinaire gratuit organisé par l'Afnic le jeudi 25 septembre avec Stéphane Bortzmeyer, Michaël Timbert et Lotfi Benyelles de 14h à 15h.

                                                                                                ➡️ Toutes les infos pour vous inscrire : webikeo.fr/landing/protocole-d

                                                                                                Webinaire Protocole DNSSEC Comment le déployer et prévenir le détournement des réponses DNS ? Jeudi 25 septembre 14h-15h

                                                                                                Alt...Webinaire Protocole DNSSEC Comment le déployer et prévenir le détournement des réponses DNS ? Jeudi 25 septembre 14h-15h

                                                                                                  🗳
                                                                                                  John Shaft boosted

                                                                                                  [?]ChaCha20Poly1305 »
                                                                                                  @camille@mastodon.libre-entreprise.com

                                                                                                  En France, voir en Europe, est-ce que vous seriez d’accord pour rendre obligatoire l’ et le (pour les opérateurs/registrars/zones/routeurs/smartphones/serveurs/services…). Merci de repartager.

                                                                                                  Oui:44
                                                                                                  Non:14

                                                                                                  Closed

                                                                                                    🗳

                                                                                                    [?]ChaCha20Poly1305 »
                                                                                                    @camille@mastodon.libre-entreprise.com

                                                                                                    For people using for their zone, what do you use for signing ? Please re-share. For other choices, you can comment and you can ask me to check your domain name in private message.

                                                                                                    RSA with SHA1 ⚠️ Weak !:1
                                                                                                    RSA with SHA256 or SHA512 ✅:8
                                                                                                    ECDSA with SHA256 or SHA384 ✅✨:46
                                                                                                    ED25519 or ED448✅✨:22

                                                                                                    Closed

                                                                                                      [?]Stéphane Bortzmeyer »
                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                      I missed the info but Microsoft is deploying to many Outlook / Hotmail systems:

                                                                                                      framagit.org/-/snippets/7528

                                                                                                        [?]Stéphane Bortzmeyer »
                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                        Changer de BE (Bureau d'Enregistrement), cela implique quoi en pratique ? Un récit très détaillé et très bien vu d'un titulaire qui veut échapper aux augmentations de tarif de Gandi shaarli.guiguishow.info/?hCft1