They do appear to have lost a key somewhere at the Pentagon//military level of the DNSSEC hierarchy.
]]>
Comment on DNSSEC deployed in .US; .BIZ shortly to follow, Neustar says by Dan York
https://www.dnssec-deployment.org/2010/06/dnssec-deployed-in-us-biz-shortly-to-follow-neustar-says/#comment-177925
Mon, 07 May 2018 16:17:08 +0000https://www.dnssec-deployment.org/?p=811#comment-177925In reply to Justina Colmena.
Hi. The .BIZ top-level domain was signed back in August 2010. Since that time you can have a .BIZ domain signed with DNSSEC.
]]>
Comment on DNSSEC deployed in .US; .BIZ shortly to follow, Neustar says by Justina Colmena
https://www.dnssec-deployment.org/2010/06/dnssec-deployed-in-us-biz-shortly-to-follow-neustar-says/#comment-160450
Sat, 11 Nov 2017 22:05:07 +0000https://www.dnssec-deployment.org/?p=811#comment-160450Seven years later (11 Nov 2017) this page says “DNSSEC IS OFF” and as the owner of a .biz domain, I am quite curious how this is supposed to work and what the issues are preventing deployment.
This is obstructing business and commerce on the web.
]]>
Comment on Is a $70 router fast enough for DNSSEC? by Richard Cranium
https://www.dnssec-deployment.org/2012/03/is-a-70-router-fast-enough-for-dnssec/#comment-151149
Fri, 26 May 2017 23:27:24 +0000https://www.dnssec-deployment.org/?p=2116#comment-151149Can you share what script or program was used to run these tests? I’ve been tasked with benchmarking some DNS options and would love to start here.
A quick 15min bash script yielded a limitation of fork speeds, so we aren’t really putting much load on the servers.
]]>
Comment on DNSSEC in Higher Education — 1% isn’t enough by Viktor Dukhovni
https://www.dnssec-deployment.org/2012/03/dnssec-in-higher-education-1-isnt-enough/#comment-149700
Tue, 02 May 2017 20:05:38 +0000https://www.dnssec-deployment.org/?p=1642#comment-149700For the record, the truman.edu DNSSEC zone is handled by nameservers that don’t conform to the specification, which leads to interoperability issues with DANE-TLSA-enabled SMTP senders.
The nameserver for truman.edu returns a very slightly different (and thus invalid) signature for the same SOA record in negative replies than it does for a direct SOA query.
;truman.edu. IN SOA
truman.edu. SOA ns3.truman.edu. dns-alerts.truman.edu. 2065422032 3600 900 1209600 3600
truman.edu. RRSIG SOA 5 2 3600 20160906050001 20160807050001 17523 truman.edu. B6Qfu3gkP6P8hzMOrCiCTorxzdBdNny7q5cKAZp9U1HeVEazjfA30v26lyTvqs4TwiJ/jCuwUP62uSCJOGegz84dGWrvYImMoDLrP/jE4EjeWs8ppf1C0ouOw+XAH3fdXDdc34TuQH0gNpNRnI63bFf8Huegq/12gKH+gF+1Mog=
;_25._tcp.barracuda.truman.edu. IN TLSA
truman.edu. SOA ns3.truman.edu. dns-alerts.truman.edu. 2065422032 3600 900 1209600 3600
truman.edu. RRSIG SOA 5 2 3600 20160906050001 20160807050001 17523 truman.edu. B6Qfu3gkP6P8hzMOrCiCTorxzdBdNny7q5cKAZp9U1HeVEazjfA30v26lyTvqs4TwiJ/jCuwUP62uSCJOGegz84dGWrvYImMoDLrP/jE4EjeWs8ppf1C0ouOw+XAH3fdXDdc34TuQH0gNpNRnI63bFf8Huegq/12gKH+gAAAAlg=
These signatures differ only in the final 8 base64 encoded characters:
gF+1Mog=
gAAAAlg=
which decode to:
80 5f b5 32 88
80 00 00 02 58
thus the mysterious damage is in the final 32 bits of the signature.
]]>
Comment on ICANN names trusted community representatives by IT-Experten nehmen Kampf gegen DNS-Missbrauch auf - Securelist
https://www.dnssec-deployment.org/2010/06/icann-names-trusted-community-representatives/#comment-114544
Mon, 19 Oct 2015 18:04:32 +0000https://www.dnssec-deployment.org/?p=868#comment-114544[…] Identifizierung des riesigen Botnetzes Mariposa, und Norm Ritchie, DNS-Experte und einer der sieben Schlüsselwächter für die Wiederherstellung der Root-Zone der […]
]]>
Comment on Call For Participation For ICANN 52 DNSSEC Workshop In Singapore by Attending ICANN 52 In Singapore? Why Not Speak About DNSSEC or DANE? « DNSSEC Deployment
https://www.dnssec-deployment.org/2014/11/call-for-participation-for-icann-52-dnssec-workshop-in-singapore/#comment-49063
Thu, 04 Dec 2014 18:41:47 +0000https://www.dnssec-deployment.org/?p=3090#comment-49063[…] « Call For Participation For ICANN 52 DNSSEC Workshop In Singapore […]
]]>
Comment on Administrative Update: Web site migrating to a new server by Administrative Update: Web site migration completed, mailing list still to do « DNSSEC Deployment
https://www.dnssec-deployment.org/2014/07/administrative-update-web-site-migrating-to-a-new-server/#comment-120
Tue, 05 Aug 2014 18:27:37 +0000https://www.worldipv6week.com/?p=3066#comment-120[…] we mentioned previously, the DNSSEC Deployment Initiative website and mailing list are in the process of being moved to […]
]]>
Comment on Labs around the world enabling DNSSEC by mdavids
https://www.dnssec-deployment.org/2012/03/labs-around-the-world-enabling-dnssec/#comment-10
Wed, 18 Jul 2012 06:58:00 +0000https://www.dnssec-deployment.org/?p=1774#comment-10There’s also this little tool by SIDN that lets you know if you are benefiting from DNSSEC validation on the client-side: https://dnssectest.sidn.nl/
]]>
Comment on Menu for .UA DNSSEC deployment by dk379
https://www.dnssec-deployment.org/2012/03/menu-for-ua-dnssec-deployment/#comment-11
Fri, 13 Apr 2012 19:31:58 +0000https://www.dnssec-deployment.org/?p=2000#comment-11we went live today, April 13th 2012.
Happy Friday đŸ™‚
]]>