chez  ·   jad   ·  tsurc   ·  cat   ·  tarquin  ·  cryptoboy Weird People    
journal.terryfroy.com
PhotosWritings
 
admin

post to journal
edit journal entry

archives

june 2004
july 2004
august 2004
september 2004
october 2004
december 2004
  january 2005
february 2005
may 2005
june 2005
november 2005
  january 2006
february 2006
april 2006
may 2006
july 2006
august 2006
september 2006
october 2006
november 2006
  february 2007
april 2007
may 2007
june 2007
july 2007
august 2007
september 2007
october 2007
november 2007
december 2007
  january 2008
march 2008
april 2008
july 2008
november 2008
december 2008
  march 2009
july 2009
august 2009
september 2009
october 2009
november 2009
december 2009
  january 2010
march 2010
may 2010
august 2010
november 2010
  march 2013

contact me

e-mail [pgp key]
homepage
icq

daily news

bbc radio 1
bbc news worldwide

fun stuff

ntk
fuckedcompany.com
bofh archives
the onion

internet oracles

google [usenet]

pc entertainment

c64 radio
project ay
world of spectrum
mame [unix] [wip]
id software
unreal tournament

network stuff

iana
6bone
rfc editor
arin whois
apnic whois
ripe whois

essential software

fedora core
courier mta
pureftpd
user mode linux

seo fun

uk tv abroad
live uk tv
website design lincolnshire
sticky labels

 
Monday, November 8, 2010

DNSSEC Continuous Validation
(posted at 10:29AM GMT)

It feels like an age has passed since I last posted anything to my ever-so-neglected part of the Internet :-(

I have been quite busy sorting out some upgrades to our ADSL services with the hope that we should be providing some FTTC-based offerings in the very near future; enjoyed diagnosing an MTU issue with BT Wholesale concerning one of our uplinks, why oh why do suppliers state that our end must be able to support an MTU of 1600 and then proceed to configure their end with an MTU of 1500 (stock Ethernet setting) ?

Whenever we set up a link between our network and another, I always insist on providing them with a copy of our switchport/router interface config and requesting that they provide us with the same for their end.

It eases link setup/future troubleshooting plus it gives each admin some comfort that the other admin has set up their end correctly.

Apparently, BT Wholesale don't do this quoting that their config is 'confidential'.

How can making the hard-coded MTU, duplex and speed settings of an interface available to an admin whose network directly connects to said interface be a breach of 'confidentiality' ?

*shakes head in disbelief*

In other news, I spent a pleasant morning in sunny Amsterdam on Monday in the offices of the RIPE NCC discussing a variety of DNS-related things with the resident DNS Services Manager and the hardened IT Manager (who has been doing the job for sixteen years and looks very well for it too!).

I always welcome the opportunity to talk 'shop' with folk outside of my own circle of colleagues/friends in the industry; especially when one of those has superuser access to k.root-servers.net ;-)

While I can't go into too much about what was discussed, I enjoyed my visit immensely and the subject matter which was covered but did manage to take the opportunity to see a few of the tourist attractions around the RIPE NCC offices with Dam Square offering some lovely examples of Dutch architecture.

One of the topics which we covered was DNSSEC continuous validation; essentially, the RIPE NCC had an issue with zones being signed with already-expired signatures that turned out to be a software bug with their signers but would have been caught if they had been checking the signatures on zones prior to publication or were continually verifying the DNSSEC 'trustability' of their zones.

The reason I mention this here is that as DNSSEC is something which is being actively rolled out and the RIPE NCC folks have been doing DNSSEC since 2005, it seems prudent to point out that if this can happen to them, it can happen to anyone else and has spurred me into passing all signed zone data through ldns-verify-zone prior to publication along with all of the other (in)sanity checks we have on our provisioning platform.

The main question though is, "How far should continuous validation really be taken ?":

  1. Check signatures are valid after zone has been signed but prior to publication ?
  2. Perform regular AXFRs of the zones in question and check the signatures/expiry times of each resource record ?

To me, the first option is acceptable but then again, our nameservers see in the regions of tens of queries per second whereas the parts of the in-addr.arpa tree which are delegated to the RIPE NCC will be seeing many many thousands of queries per second in relation to rDNS lookups... if we break DNSSEC on our nameservers, it might result in a single support ticket from our own monitoring boxes telling us to pull our fingers out and fix it plus maybe a couple from some of our more tech-savvy users.

If the same issue hits the RIPE NCC or any other TLD/popular domain, it has far worse consequences due to the dependency which the Internet has on the root and the in-addr.arpa tree.

The second option is more appealing for the RIPE NCC due to the fact that their DNS is more mission-critical than ours (ours is still mission-critical but if ours breaks, we don't have a large part of the Internet shouting at us to fix it) and it is easier to continually validate the small number of zones which the RIPE NCC hosts as opposed to us validating 25,000+ zones on a high-frequency basis.

Nevertheless, I am certain that DNSSEC will continue being a source of fun and games for us and the RIPE NCC alike :-P

 
slashdot

China Hosts First Fully Autonomous AI Robot Football Match

Google Buys 200 Megawatts of Fusion Energy That Doesn't Even Exist Yet

NASA To Stream Rocket Launches and Spacewalks On Netflix

Norwegian Lotto Mistakenly Told Thousands They Were Filthy Rich After Math Error

Windows User Base Shrinks By 400 Million In Three Years

Oracle Inks Cloud Deal Worth $30 Billion a Year

Tumblr's Move To WordPress and Fediverse Integration Is 'On Hold'

CarFax For Used PCs: Hewlett Packard Wants To Give Laptops New Life

Freelancers Using AI Tools Earn 40% More Per Hour Than Peers, Study Says

Apple Loses Bid To Dismiss US Smartphone Monopoly Case

Senate GOP Budget Bill Has Little-Noticed Provision That Could Hurt Your Wi-Fi

Apple Weighs Using Anthropic or OpenAI To Power Siri in Major Reversal

VP.net Promises "Cryptographically Verifiable Privacy"

WordPress CEO Regrets 'Belongs to Me' Comment Amid Ongoing WP Engine Legal Battle

In China, Coins and Banknotes Have All But Disappeared

the register

Oracle just signed one mystery customer that will double its cloud revenue in 2028

US shuts down a string of North Korean IT worker scams

Want a job? Just put 'AI skills' on your resume

AIs have a favorite number, and it's not 42

Google to buy power from fusion energy startup Commonwealth - if they can ever make it work

British IT worker sentenced to seven months after trashing company network

Norwegian lotto mistakenly told thousands they were filthy rich after math error

Scattered Spider crime spree takes flight as focus turns to aviation sector

Northrop Grumman shows SpaceX doesn't have a monopoly on explosions

Mitch Kapor finally completes MIT master's degree after 45-year detour

VMware must support crucial Dutch govt agency as it migrates off the platform, judge rules

Sinaloa drug cartel hired a cybersnoop to identify and kill FBI informants

Microsoft's next Windows 11 update is more 'enablement' than upgrade

Arm muscles into server market – but can't wrestle control from x86 just yet

Deutsche Bahn train hits 405 km/h without falling to bits

Cloud lobby warns EU: Clamp down on water rules and we'll evaporate

Your browser has ad tech's fingerprints all over it, but there's a clean-up squad in town

Junior sysadmin’s first lines of code set off alarms. His next lot crashed the company

Don't pay for AI support failures, says Gradient Labs CEO

DoJ clears HPE to buy Juniper if it sells Instant On Wi-Fi and licenses some code

China claims breakthroughs in classical and quantum computers

Canada orders Chinese CCTV biz Hikvision to quit the country ASAP

It's 2025 and almost half of you are still paying ransomware operators

AI agents get office tasks wrong around 70% of the time, and a lot of them aren't AI at all

Ex-NATO hacker: 'In the cyber world, there's no such thing as a ceasefire'

How to get free software from yesteryear's IT crowd – trick code into thinking it's running on a rival PC

Anthropic chucks chump change at studies on job-killing tech

Crims are posing as insurance companies to steal health records and payment info

Supremes uphold Texas law that forces age-check before viewing adult material

How Broadcom is quietly plotting a takeover of the AI infrastructure market

Uncle Sam wants you – to use memory-safe programming languages

Fed chair Powell says AI is coming for your job

Palantir jumps aboard tech-nuclear bandwagon with software deal

Mars Reconnaissance Orbiter learns new trick at the age of 19: ‘very large rolls’

Cisco punts network-security integration as key for agentic AI

Aloha, you’ve been pwned: Hawaiian Airlines discloses ‘cybersecurity event’

US Department of Defense will stop sending critical hurricane satellite data

So you CAN turn an entire car into a video game controller

Before the megabit: A trip through vintage datacenter networking

Data spill in aisle 5: Grocery giant Ahold Delhaize says 2.2M affected after cyberattack

There's no international protocol on what to do if an asteroid strikes Earth

The network is indeed trying to become the computer

The year of the European Union Linux desktop may finally arrive

Fresh UK postcode tool points out best mobile network in your area

Don't shoot me, I'm only the system administrator!

HPE customers on agentic AI: No, you go first

Starlink helps eight more nations pass 50 percent IPv6 adoption

Australia not banning kids from YouTube – they’ll just have to use mum and dad’s logins

More trouble for authors as Meta wins Llama drama AI scraping case

Back in black: Microsoft Blue Screen of Death is going dark

 

Linux

Apache

PHP