John Shaft · @shaft
1280 followers · 2612 posts · Server piaille.fr

Good to know:

"The DNSKEY RR has no special TTL requirements." (RFC 4034 section 2, does not seem to have been updated)

takes the SOA TTL. Seems a reasonnable choice 🤔

#ldns #dnssec

Last updated 2 years ago

John Shaft · @shaft
1279 followers · 2555 posts · Server piaille.fr

I wish -signzone had an option to tell it to not touch a DNSKEY RRSIG in the zone file he signs :-)

#ldns

Last updated 2 years ago

John Shaft · @shaft
1279 followers · 2554 posts · Server piaille.fr

Ok, let's not go to NSEC3 territory: too much of a hassle.

Here's the plan:
- Sign zone using only the ZSK with
- Edit signed zone file to add KSK DNSKEY RR
- Change DNSKEY RRSIG with precomputed RRSIG for our RRset

That way, I should be able to generate in advance DNSKEY RRSIG for my zone, using the KSK private key only once in a while (to generate in advance RRSIG for 3-4 months), instead of having to use it every time

#ldns #dnssec

Last updated 2 years ago

It's today!

Consider following those really nice folks @nlnetlabs, they are creating software to make the a safer, better place.

If you know what , , , (...) means, they're surely the ones you'd like to follow!

#followerfriday #opensource #internet #krill #unbound #nsd #ldns #dns #dnssec

Last updated 2 years ago

Julien M. · @julm
485 followers · 4935 posts · Server framapiaf.org

> The command supports (type 65) in the latest git revision [1]. To use it, build with --enable-rrtype-svcb-https
stackoverflow.com/a/68064522

@bortzmeyer @codewiz @angristan

#ldns #rr #https #drill

Last updated 4 years ago