Re: [dns-operations] Google Public DNS has enabled case randomization globally

2023-07-29 Thread Evan Hunt
aps he can call up the chapter and verse?) If I'm mistaken about that, and it's still only implicit, then I'd support clarifying the protocol in that way. If it's already been clarified, though, then I'm not sure why a 0x20 RFC is needed now. -- Evan Hunt -- e...@isc.org In

Re: [dns-operations] why DNS can't have nice things

2023-04-14 Thread Evan Hunt
compliant software be required to literally smell bad. (For some reason I still haven't gotten my Nobel prize for that. Maybe I should check today's mail...) -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-o

Re: [dns-operations] CNAME at the apex breaks DNSSEC DS lookups from caches

2022-04-16 Thread Evan Hunt
y reason I wrote it was that I believed browser vendors would remain unwilling to adopt a more sensible alternative, and as soon as my pessimism turned out to be unfounded, I was quite happy to drop the proposal. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. _

Re: [dns-operations] slack.com bogus

2021-09-30 Thread Evan Hunt
hopes, resolver operators will get tired of having to keep resetting the things. It's been six years, I haven't seen much evidence of harm to the DNSSEC ecosystem yet. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing li

Re: [dns-operations] Spurious (?) DNSSEC SERVFAIL with some (?) versions of BIND for one domain?

2021-03-10 Thread Evan Hunt
iction since NSEC3 support was first added in 2008. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Re: [dns-operations] [Ext] Signing on the fly and UltraDNS

2021-01-06 Thread Evan Hunt
On Wed, Jan 06, 2021 at 03:24:10AM +, Evan Hunt wrote: > I wonder aloud if dig's default behavior should be to try IDN and > silently fall back to conventional output formatting if it fails. > I imagine there are situations where you'd want the rules strictly > enforced, but

Re: [dns-operations] [Ext] Signing on the fly and UltraDNS

2021-01-05 Thread Evan Hunt
a good reason to do that by default. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Re: [dns-operations] named-checkzone warnings about missing SPF records

2015-04-18 Thread Evan Hunt
zone antiglam.com/IN: 'antiglam.com' found SPF/TXT record but no SPF/SPF record found, add matching type SPF record Will this warning be phased out? It already was, in 9.9.6 and 9.10.1. It warns now if you have an SPF record without a corresponding TXT, not the other way around. -- Evan

Re: [dns-operations] Python or Ruby

2015-02-09 Thread Evan Hunt
this for love, try them all (ESPECIALLY go!) and see which one grabs you. if you're doing it for relevance and compatibility and code re-use and code sharing, use python. I can't speak to the accuracy of the first paragraph, but I'm gonna +1 everything else Paul just said. -- Evan Hunt -- e

Re: [dns-operations] DNS Security Advisory (infinite recursion)

2014-12-08 Thread Evan Hunt
On Mon, Dec 08, 2014 at 05:33:58PM +0100, Stephane Bortzmeyer wrote: For BIND, I'm not aware of a patch yet. https://kb.isc.org/article/AA-01216 The 9.10 release also had an unrelated, less significant security problem fixed at the same time, covered in https://kb.isc.org/article/AA-01217.

Re: [dns-operations] cool idea regarding root zone inviolability

2014-11-29 Thread Evan Hunt
On Sat, Nov 29, 2014 at 01:15:48PM -0800, Paul Vixie wrote: can you tell me the use case for having this signature be in-band? An out-of-band signature can only cover an out-of-band transfer. An in-band signature could cover both kinds. -- Evan Hunt -- e...@isc.org Internet Systems Consortium

Re: [dns-operations] latest bind, EDNS TCP

2014-10-11 Thread Evan Hunt
issue. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman

Re: [dns-operations] Another public DNS resolver, this time with DNSSEC

2014-07-20 Thread Evan Hunt
: it's not obvious from the website, and dns.watch doesn't have an MX record. It's harder to evaluate claims of neutrality and data privacy when I don't know who I'm talking to. I also wish I knew who they were because (assuming legit) I'd be happy to offer assistance. -- Evan Hunt -- e

Re: [dns-operations] Another public DNS resolver, this time with DNSSEC

2014-07-20 Thread Evan Hunt
to. whois ? The website and whois record both indicate that they're associated with Ideal Hosting UG, but it isn't obvious to me whether dns.watch *is* Ideal Hosting, or just clients of theirs. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] Forcing BIND to randomly expire records from cache ahead of time

2014-07-03 Thread Evan Hunt
This is implemented in BIND 9.10 as the prefetch option. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs

Re: [dns-operations] about the underline in hostname

2014-05-29 Thread Evan Hunt
the underscore to the allowed list, and not any other special characters, which would break all kinds of things, without adding any real value. Can I ask what specific problem you're having that would be solved by this? -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] The Decline and Fall of BIND 10

2014-05-15 Thread Evan Hunt
On Thu, May 15, 2014 at 07:12:53AM -0400, Jared Mauch wrote: I heard they are skipping number 11, the next release would be 9.12. It's on our roadmap as 9.11. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing

Re: [dns-operations] Subverting BIND's SRTT Algorithm Derandomizing NS Selection

2014-05-06 Thread Evan Hunt
On Tue, May 06, 2014 at 10:56:03AM -0700, Paul Ferguson wrote: ISC plans to address this deficiency by reimplementing the SRTT algorithm in future maintenance releases of the BIND 9 code. Was this reimplementation done, and if so, what version was it implemented? Not yet. -- Evan Hunt

Re: [dns-operations] BIND performance difference between RHEL 6.4 and FreeBSD 7

2014-04-22 Thread Evan Hunt
stack that caused a big performance drop relative to BSD or Solaris, essentially reducing it to single-thread performance. I believe all the major Linux distributions have switched to lockless UDP by now, but it might be worth checking out. -- Evan Hunt -- e...@isc.org Internet Systems Consortium

[dns-operations] key management in bind9 (was Re: summary of recent vulnerabilities)

2013-10-25 Thread Evan Hunt
Jan 23 17:46:46 UTC 2014: Delete: example.com/005/53481 (ZSK) No errors found -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman

Re: [dns-operations] Implementation of negative trust anchors?

2013-08-23 Thread Evan Hunt
of signing failures is the wrong thing to do, but people are going to do the wrong thing whether I like it or not, and if we must choose between evils, I prefer rndc validation off nasa.gov to rndc validation off. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] Implementation of negative trust anchors?

2013-08-23 Thread Evan Hunt
to use narrow NTAs would have any effect on resolver operators. Of course not, but it could affect the choices made by DNS implementors. (I expect to pay attention to Jason's draft if and when I implement this feature.) -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] bind + client-subnet

2013-08-13 Thread Evan Hunt
but how to implement that? since local DNS server always has caching. Yes, this is why I said it would be a big job to implement it in BIND. It becomes necessary to cache multiple different answers to the same question. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] bind + client-subnet

2013-08-12 Thread Evan Hunt
on sponsorship. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net

Re: [dns-operations] Both KSK ZSK signing DNSKEY records

2013-03-17 Thread Evan Hunt
dnssec-dnskey-kskonly yes; to your options statement. If you're using dnssec-signzone, you can override it by using the -x flag. It seems harmless, beyond the extra payload in responses pushing up packet sizes. Exactly so. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc

Re: [dns-operations] BIND 9.7 was Re: what nameserver software have you been using?

2012-12-14 Thread Evan Hunt
like very much to know more about this? -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https