大家知道什么在中国内地运行,支持 DNSSEC 的对公众开放的 DNS 服务器吗?

#dns #china #dnssec

Last updated 1 year ago

John Shaft · @shaft
1467 followers · 6391 posts · Server piaille.fr

D'ailleurs l'IANA listant le Siège apostolique comme gestionnaire du .va, ça signifie que le domaine est géré par le pape et la curie. Ça se voit à l'emblème pontifical : il y a les clés utilisées dessus !

fr.wikipedia.org/wiki/Armoirie

#dnssec

Last updated 1 year ago

Stéphane Bortzmeyer · @bortzmeyer
8737 followers · 80792 posts · Server mastodon.gougere.fr

On est dans les locaux de l' esg.fr/ Comme c'est une école de commerce, on leur pardonnera le fait que le résolveur du Wifi "guest" soit 8.8.8.8. (Au moins, comme ça, on a .)

#esg #dns #dnssec

Last updated 1 year ago

MattPounsett · @MattPounsett
78 followers · 360 posts · Server fosstodon.org

When I posted this a few hours ago, I had completely forgotten that @dw would be presenting about the algo roll at today. His talk has just wrapped up, but the slides are available (linked below) and the video should be up on OARC's Youtube channel once it's been processed and edited.

indico.dns-oarc.net/event/47/c
youtube.com/dns-oarc

#oarc41 #dns #dnssec

Last updated 1 year ago

chrbre · @chrbre
36 followers · 127 posts · Server ipv6.social

@kleinezeitung internet.nl/site/www.klein…
Liebe Kleinezeitung. DNS
Da könnt ihr Sicherheit verbessern

#noipv6 #dnssec #nohsts #nosecurityheader

Last updated 1 year ago

MattPounsett · @MattPounsett
78 followers · 353 posts · Server fosstodon.org

Verisign is doing a DNSSEC algorithm roll on the three largest Top Level Domains they operate: .com, .net, and .edu.

conundrum.com/blog/2023/Sep/co

#dns #dnssec #blog #100DaysToOffload

Last updated 1 year ago

John Shaft · @shaft
1454 followers · 6169 posts · Server piaille.fr

OK, I know a little about DNS but wildcards and DNS are out of my league. Nevertheless, I'm pretty confident that this TYPE65283 shenanigans Cloudflare is using in its RR does not come from the RFCs 🤔

$ dig prout.cloudflare.com +dnssec
...
;; AUTHORITY SECTION:
prout.cloudflare.com. 3600 IN NSEC \000.prout.cloudflare.com. RRSIG NSEC TYPE65283

#nsec #dnssec

Last updated 1 year ago

Andreas Taudte · @ataudte
15 followers · 48 posts · Server mastodns.net

See you in for 👋🙂
meetings.icann.org/en/icann78
Special thanks the hosts eco, DENIC and Hamburg

#hamburg #icann78 #dns #dnssec #ipv4 #ipv6

Last updated 1 year ago

Bart Groeneveld · @bartavi
29 followers · 2007 posts · Server mastodon.nl
Katzenjens · @katzenjens
513 followers · 1169 posts · Server social.tchncs.de

Donnerwetter. Das erste Mal gesehen, dass bei etwas nicht rund läuft. Und zwar Ansonsten ist dieser Provider (fast) uneingeschränkt zu empfehlen. Nur die Domains sollte man anderswo hosten, wenn man DNSSEC nutzen will. Z.B. bei

#netcup #dnssec #inwx

Last updated 1 year ago

Ralf Bergs · @r
17 followers · 356 posts · Server ruhr.social

can't be verified anymore due to a bad ?! 😮

validating bt/SOA: verify failed due to bad signature (keyid=9021): RRSIG has expired

#bhutan #tld #dnssec #signature

Last updated 1 year ago

John Shaft · @shaft
1434 followers · 5871 posts · Server piaille.fr

Je m'ennuie au taf, donc je regarde comment faire de la validation avec . Et peut-être implémenter la chose dans mon check_soa 🤔

#dnssec #dnspython

Last updated 1 year ago

chrbre · @chrbre
33 followers · 112 posts · Server ipv6.social

internet.nl/site/www.mavcsopor rails have lot internet issues.
#.1 headers and missing rpki at
Example of hu rails security

#ipv6 #dnssec #nohsts #tls1 #security #isp

Last updated 1 year ago

Leonard/Janis aka lj·rk · @ljrk
601 followers · 20138 posts · Server todon.eu

Thinking about my (still WIP) setup. AFAICT, the guide for with at docs.pi-hole.net/guides/dns/cl only coveres using DoH between the PiHole and the upstream DNS provider (e.g., Cloudflare, Google, etc.). But if I want to use DoH between my browser and my PiHole, I seem to need another DoH Proxy, which makes request flow like this:

1. incoming on dns.ljrk.org:443 (traefik reverse proxy)
2. forwarded to 127.0.0.1:80 (DoH Proxy #1)
3. upstream classic DNS resolver on 127.0.0.1:53 (PiHole)
4. forwards any non-blocked requests to 127.0.0.1:5053 (DoH Proxy #2)
5. upstream DoH DNS resolver such as 1.1.1.1:443/dns-request

Of course, most PiHole setups are local and I'll probably end up opening dns.ljrk.org only through a /#HeadScale , but my browser may still prefer to speak DoH instead of RFC1035. I'm also not sure how plays into this...

#pihole #doh #cloudflared #tailscale #vpn #dnssec

Last updated 1 year ago

Marcel SIneM(S)US · @simsus
205 followers · 4833 posts · Server social.tchncs.de
Petr Menšík :fedora: · @pemensik
20 followers · 78 posts · Server fosstodon.org

@bluca why in the heavens there is no trace of failure? Either admitting this and previous versions contains serious flaw. Or better, fixed version with a note, that this is the first version with properly working validation. Instead there is silence, pretending everything is alright. 🤦🤯

#dnssec

Last updated 1 year ago

heise online · @heiseonline
55581 followers · 8439 posts · Server social.heise.de

10 Jahre nach Snowden: Schlechteres Netz trotz mehr Vertraulichkeit?​

Zehn Jahre nach Snowden zieht die Internet-Community auf dem IETF-Treffen Bilanz: Wir haben jetzt Verschlüsselung, aber noch eine Menge zu tun.​

heise.de/news/10-Jahre-nach-Sn

#bnd #dns #dnssec #edwardsnowden #ietf #internet #netze #nsa #security #news

Last updated 1 year ago

Dataplane.org · @dataplane
99 followers · 61 posts · Server fosstodon.org
wutti · @wutti
105 followers · 1642 posts · Server digitalcourage.social

So, da mit langweilig war, habe ich mal einen kompletten Beitrag zum Einrichten eines mit und DNS-Anfragen über mit inkl. Update-Anleitungen geschrieben:

wutti.com/pihole-installation-

#dnssec #doh #dnscryptproxy #pihole

Last updated 1 year ago

Kajo 📷 :mastolove: · @Kajo
180 followers · 31353 posts · Server social.tchncs.de

Tja, Pech gehabt. Kurz ne neue Verbindung mit der 7.56 initiiert und schon kann sich nicht mehr verbinden.

Im ist "Use DNSSEC" nicht mal aktiviert 🤔 Wobei ich diese beiden DNS-Server nutze, die vermutlich serverseitig nutzen...

#fritzbox #wireguard #pihole #dnssec

Last updated 1 year ago