Latest posts

Blog Age Hits Title
5205d743Configure DLV (DNSSEC Lookaside Validation) for Unbound
Not all ccTLD (Country Code Top Level Domains) ot gTLD (generic Top Level Domains) are DNSSEC signed (Status 2/2011). Domains below these unsigned TLDs are not in the 'Chain of Trust', even if they are DNSSEC signed,...
5205d624Configure DLV (DNSSEC Lookaside Validation) for Unbound
Not all ccTLD (Country Code Top Level Domains) ot gTLD (generic Top Level Domains) are DNSSEC signed (Status 2/2011). Domains below these unsigned TLDs are not in the 'Chain of Trust', even if they are DNSSEC signed,...
5205d643Episode 21
In this mercifully digression-free episode - perhaps not coincidentally taped in-person in Cricket's office in Santa Clara - Matt and Cricket answer Josh Baverstock's umpteenth question, this one about storing...
5206d620Programming languages in configuration files
Justin Mason posted an interesting article against the use of programming languages in configuration files. I think he is mostly right but his arguments could be improved. His first argument is provability, that is,...
5207d722Running OpenDNSSEC with 50000 zones
Getting OpenDNSSEC to run as a signer for a very large amount of zones is today not a trivial task. Running the software with a thousand zones is not a big deal. In this blog post I will outline how you can reach an even...
5209d601A Lesson in Humility Courtesy DNSSEC
At one time, when my job actually entailed managing name servers and namespace, I was pretty good at troubleshooting DNS problems. Often just a few queries with dig would tell me what was wrong, especially if the issue...
5209d670A Lesson in Humility Courtesy DNSSEC
At one time, when my job actually entailed managing name servers and namespace, I was pretty good at troubleshooting DNS problems. Often just a few queries with dig would tell me what was wrong, especially if the issue...
5213d489DNS and some ccTLDs
.be [1] .de [1][4] .nl [2] .uk [2] .se [2] .fr [3] DNSSEC 2010-10-07 : Expired signatures. Notice . Soon? Soon? 2010-09-13 : Signing failure due to failover. Notice . Soon? 2011-02-12 : Invalid signature on...
5213d490DNS and some ccTLDs
.be [1] .de [1][4] .nl [2] .uk [2] .se [2] .fr [3] DNSSEC 2010-10-07 : Expired signatures. Notice . Soon? Soon? 2010-09-13 : Signing failure due to failover. Notice . Soon? 2011-02-12 : Invalid signature on...
5213d430DNS and some ccTLDs
.be [1] .de [1][4] .nl [2] .uk [2] .se [2] .fr [3] DNSSEC 2010-10-07 : Expired signatures. Notice . Soon? Soon? 2010-09-13 : Signing failure due to failover. Notice . Soon? 2011-02-12 : Invalid signature on...
5213d418DNS and some ccTLDs
.be [1] .de [1][4] .nl [2] .uk [2] .se [2] .fr [3] DNSSEC 2010-10-07:Expired signatures. Notice. Soon? Soon? 2010-09-13:Signing failure due to failover. Notice. Soon? 2011-02-12:Invalid signature on NSEC3 disproofing...
5220d625ISC salutes new era of IPv6 in growth of the Internet
Redwood City, CA – February 4, 2011 – ISC salutes new era of IPv6 in growth of the Internet Today’s announcement by IANA and the NRO regarding the exhaustion of the IPv4 address pool at the IANA central repository...
5223d640IPv6 and DNS
With the imminent exhaustion of IPv4 address space and the U.S. government’s renewed push to implement IPv6 , the protocol has been getting more press lately. The government’s mandate requires Federal government agencies...
5223d631IPv6 and DNS
With the imminent exhaustion of IPv4 address space and the U.S. government’s renewed push to implement IPv6 , the protocol has been getting more press lately. The government’s mandate requires Federal government agencies...
5224d51Tweets of January 31 2011
Replying to @PowerDNS_Bert overwhelm the resolver with nsec3s and then (quote Duke Nukem): Let God sort them out. Mon Jan 31 08:56:47 +0000 2011 The 3 in NSEC3 represents the number of people that actually understand all...
5225d688Pirate Bay, Decentralised P2P-DNS, ICANN and the law of...
submitted by scrubs [link] [comment]
5226d620Run your own recursive, and caching DNS resolver
submitted by bbennett [link] [2 comments]
5231d504Funkensign
How about on-the-fly signing? In this example we add a signature to any packet dealing with www.example.org. Again it is a matter of defining the matching, action and setup functions. Matching We don't have to match...
5231d511Funkensign
How about on-the-fly signing? In this example we add a signature to any packet dealing with www.example.org. Again it is a matter of defining the matching, action and setup functions. Matching We don't have to match...
5231d404Funkensign
How about on-the-fly signing? In this example we add a signature to any packet dealing with www.example.org. Again it is a matter of defining the matching, action and setup functions. Matching We don't have to match...
DNSsexy

Blogs

Blog submission

Send any DNS blog that you feel adds value to the DNS community. Final decisions rest with me.

  • First & Last names
  • Blog name
  • Blog URL
  • Feed URL

About

DNSsexy is an aggregation of DNS related blogs and news. It is built, edited and maintained by Jan-Piet Mens with substantial contributions by Carsten Strotmann.