Re: [dns-operations] Important change for the .ga TLD 6th june 2023

2023-06-04 Thread Puneet Sood via dns-operations
--- Begin Message --- Stephane, Looks like google.ga is returning NXDOMAIN from the nic.fr servers. Can you please check what could be wrong with the delegation info? Thanks, Puneet $ dig @d.nic.fr google.ga ; <<>> DiG 9.10.6 <<>> @d.nic.fr google.ga ; (2 servers found) ;; global options: +cmd

Re: [dns-operations] [Ext] New addresses for b.root-servers.net

2023-06-04 Thread Paul Hoffman
To augment what Joe and Viktor said, please see RSSAC028, "Technical Analysis of the Naming Scheme Used For Individual Root Servers", . That document is about how the root servers are named, and how that naming affects the

Re: [dns-operations] Important change for the .ga TLD 6th june 2023

2023-06-04 Thread Stephane Bortzmeyer
On Fri, Jun 02, 2023 at 09:28:24AM +0200, Stephane Bortzmeyer wrote a message of 56 lines which said: > The .ga TLD will change its mode of operation on 6th june 2023. The majority > of domain names, registered under disputable conditions, will be removed. Do > not be surprised if many

Re: [dns-operations] New addresses for b.root-servers.net

2023-06-04 Thread Viktor Dukhovni
On Sun, Jun 04, 2023 at 08:44:19AM +0100, Matthew Richardson via dns-operations wrote: > Without wishing to ask a really stupid question, is there any reason > why root-servers.net is not DNSSEC signed? > > Would signing it provide any additional security? For the glue records to be

Re: [dns-operations] New addresses for b.root-servers.net

2023-06-04 Thread Joe Abley
Hi Matthew, Signing the ROOT-SERVERS.NET zone would provide the ability to validate its contents, but since it's rare for applications and end users to ask questions that are answerable from that zone the benefit is arguably marginal. The ability to follow a chain or trust through keys

Re: [dns-operations] New addresses for b.root-servers.net

2023-06-04 Thread Matthew Richardson via dns-operations
--- Begin Message --- Dave Knight wrote:- >> all you can validate is the NS set. The host records cannot be validated >> because root-servers.net is not signed. > >Good point! > >They're still used to replace what was provided in the root.hints after the >priming response is received though.