chez  ·   jad   ·  tsurc   ·  cat   ·  tarquin  ·  cryptoboy Weird People    
journal.terryfroy.com
PhotosWritings
 
admin

post to journal
edit journal entry

archives

june 2004
july 2004
august 2004
september 2004
october 2004
december 2004
  january 2005
february 2005
may 2005
june 2005
november 2005
  january 2006
february 2006
april 2006
may 2006
july 2006
august 2006
september 2006
october 2006
november 2006
  february 2007
april 2007
may 2007
june 2007
july 2007
august 2007
september 2007
october 2007
november 2007
december 2007
  january 2008
march 2008
april 2008
july 2008
november 2008
december 2008
  march 2009
july 2009
august 2009
september 2009
october 2009
november 2009
december 2009
  january 2010
march 2010
may 2010
august 2010
november 2010
  march 2013

contact me

e-mail [pgp key]
homepage
icq

daily news

bbc radio 1
bbc news worldwide

fun stuff

ntk
fuckedcompany.com
bofh archives
the onion

internet oracles

google [usenet]

pc entertainment

c64 radio
project ay
world of spectrum
mame [unix] [wip]
id software
unreal tournament

network stuff

iana
6bone
rfc editor
arin whois
apnic whois
ripe whois

essential software

fedora core
courier mta
pureftpd
user mode linux

seo fun

uk tv abroad
live uk tv
website design lincolnshire
sticky labels

 
Monday, November 8, 2010

DNSSEC Continuous Validation
(posted at 10:29AM GMT)

It feels like an age has passed since I last posted anything to my ever-so-neglected part of the Internet :-(

I have been quite busy sorting out some upgrades to our ADSL services with the hope that we should be providing some FTTC-based offerings in the very near future; enjoyed diagnosing an MTU issue with BT Wholesale concerning one of our uplinks, why oh why do suppliers state that our end must be able to support an MTU of 1600 and then proceed to configure their end with an MTU of 1500 (stock Ethernet setting) ?

Whenever we set up a link between our network and another, I always insist on providing them with a copy of our switchport/router interface config and requesting that they provide us with the same for their end.

It eases link setup/future troubleshooting plus it gives each admin some comfort that the other admin has set up their end correctly.

Apparently, BT Wholesale don't do this quoting that their config is 'confidential'.

How can making the hard-coded MTU, duplex and speed settings of an interface available to an admin whose network directly connects to said interface be a breach of 'confidentiality' ?

*shakes head in disbelief*

In other news, I spent a pleasant morning in sunny Amsterdam on Monday in the offices of the RIPE NCC discussing a variety of DNS-related things with the resident DNS Services Manager and the hardened IT Manager (who has been doing the job for sixteen years and looks very well for it too!).

I always welcome the opportunity to talk 'shop' with folk outside of my own circle of colleagues/friends in the industry; especially when one of those has superuser access to k.root-servers.net ;-)

While I can't go into too much about what was discussed, I enjoyed my visit immensely and the subject matter which was covered but did manage to take the opportunity to see a few of the tourist attractions around the RIPE NCC offices with Dam Square offering some lovely examples of Dutch architecture.

One of the topics which we covered was DNSSEC continuous validation; essentially, the RIPE NCC had an issue with zones being signed with already-expired signatures that turned out to be a software bug with their signers but would have been caught if they had been checking the signatures on zones prior to publication or were continually verifying the DNSSEC 'trustability' of their zones.

The reason I mention this here is that as DNSSEC is something which is being actively rolled out and the RIPE NCC folks have been doing DNSSEC since 2005, it seems prudent to point out that if this can happen to them, it can happen to anyone else and has spurred me into passing all signed zone data through ldns-verify-zone prior to publication along with all of the other (in)sanity checks we have on our provisioning platform.

The main question though is, "How far should continuous validation really be taken ?":

  1. Check signatures are valid after zone has been signed but prior to publication ?
  2. Perform regular AXFRs of the zones in question and check the signatures/expiry times of each resource record ?

To me, the first option is acceptable but then again, our nameservers see in the regions of tens of queries per second whereas the parts of the in-addr.arpa tree which are delegated to the RIPE NCC will be seeing many many thousands of queries per second in relation to rDNS lookups... if we break DNSSEC on our nameservers, it might result in a single support ticket from our own monitoring boxes telling us to pull our fingers out and fix it plus maybe a couple from some of our more tech-savvy users.

If the same issue hits the RIPE NCC or any other TLD/popular domain, it has far worse consequences due to the dependency which the Internet has on the root and the in-addr.arpa tree.

The second option is more appealing for the RIPE NCC due to the fact that their DNS is more mission-critical than ours (ours is still mission-critical but if ours breaks, we don't have a large part of the Internet shouting at us to fix it) and it is easier to continually validate the small number of zones which the RIPE NCC hosts as opposed to us validating 25,000+ zones on a high-frequency basis.

Nevertheless, I am certain that DNSSEC will continue being a source of fun and games for us and the RIPE NCC alike :-P

 
slashdot

Millions of IPs Remain Infected By USB Worm Years After Its Creators Left It For Dead

Captchas Are Getting Harder

GNOME Foundation To Focus On Fundraising After Years Running A Deficit

Chinese Drone Maker DJI Might Get Banned Next in the US

Android TVs Can Expose User Email Inboxes

Europeans 'Less Hard-Working' Than Americans, Says Norway Oil Fund Boss

Encrypted Email Service Files DMA Complaint Claiming It Vanished from Google Search

Windows 11 Will Display Watermark If Your PC Does Not Support AI Requirements

Apple Removes Nonconsensual AI Nude Apps From App Store

OpenAI's Sam Altman and Other Tech Leaders To Serve on AI Safety Board

Honda To Spend $11 Billion On Four EV Factories In North America

TSMC Unveils 1.6nm Process Technology With Backside Power Delivery

Alphabet Shares Jump 14% On Earnings Beat, First-Ever Dividend

Seagate Joins the HDD Price Hike Party, Blames AI for Spike in Demand

Open Sourcing DOS 4

the register

Two indicted for illegally exporting chip gear from US to China

Kaiser Permanente shared 13.4M people's data with Microsoft Bing, Google, others

Amazon to ditch WorkDocs sharing service, support countdown begins

Huawei and partners reportedly plan to produce high bandwidth memory by 2026

Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B

The eight-bit Z80 is dead. Long live the 16-bit Z80!

Encrypted email service files DMA complaint claiming it vanished from Google Search

TikTok ban could escalate US-China trade war, ex-White House CIO tells The Reg

UK's Investigatory Powers Bill to become law despite tech world opposition

45 Drives adds Linux-powered mini PCs, workstations to growing compute lineup

IBM and LzLabs to clash in UK court over Software Defined Mainframe

UK agriculture department slammed for paper pushing despite tech splurges

Help! My mouse climbed a wall and now it doesn't work right

VMware’s end-user compute community told to brace for ‘Omnissa’ shift

Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

Atlassian loses half its CEOs, but customers stay solid after Server products exit support

Intel excited by PC sales pop and GPU prospects, but investors aren’t because the outlook is poor

What's up with Alphabet and Microsoft lately? Profits, sales – and AI costs

Amazon to blow $11B on cluster of Indiana bit barns

Cops cuff man for allegedly framing colleague with AI-generated hate speech clip

Ring dinged for $5.6M after, among other claims, rogue insider spied on 'pretty girls'

ByteDance 'would rather' torpedo TikTok than sell it off

FCC votes 3-2 to bring net neutrality back from the dead

Detecting drift and dealing with the Silicon Valley mindset

Two cuffed in Samourai Wallet crypto dirty money sting

TSMC says first 1.6nm chips coming in 2026

Spotify claims Apple wants 'tax' for in-app pricing tweak

DARPA's latest toy is a 20-foot, 12-ton tank that drives itself

City council audit trail is an audit fail after disastrous Oracle ERP rollout

SK hynix breaks Q1 revenue records on back of AI boom

Russia, Iran pose most aggressive threat to 2024 elections, say infoseccers

Meta's value plummets as Zuckerberg admits AI needs more time and money

Atos hopes for lifeline as refinancing saga set to drag on into May

Japan's Moon lander makes it through another lunar night

Turns out teaching criminals to write web code keeps them out of prison

Throwflame launches fire-spitting robo-dog from Hell

Microsoft and Amazon's AI ambitions spark regulatory rumble

BMW calls for vendor openness in quest to mine its own processes

Forget the AI doom and hype, let's make computers useful

Indian bank’s IT is so shabby it’s been banned from opening new accounts

Samsung shows off battery tech it says will see you gone in nine minutes

IBM to acquire Hashi for $6.4B, hopes it will boost software biz and Red Hat

Australia’s spies and cops want ‘accountable encryption’ - aka access to backdoors

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

With Run:ai acquisition, Nvidia aims to manage your AI kubes

Apple releases OpenELM, a slightly more accurate LLM

Musk moves Tesla's goalposts, investors happily move shares higher

Shouldn't Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking

Now all Windows 11 users are getting adverts to 'make the Start menu great again'

Lenovo and Micron first to implement LPCAMM2 in laptop

 

Linux

Apache

PHP