public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] DNSSEC (w/ DLV) live on *.dev.gentoo.org
@ 2013-01-07  1:31 Robin H. Johnson
  2013-01-07  4:01 ` Doug Goldstein
                   ` (4 more replies)
  0 siblings, 5 replies; 16+ messages in thread
From: Robin H. Johnson @ 2013-01-07  1:31 UTC (permalink / raw
  To: gentoo-dev

Just a heads up,

DNSSEC is now live on *.dev.gentoo.org hosts.

There is a DLV anchor registered at dlv.isc.org, so all public DNSSEC
lookups within the domain should work fine.

Here's visualisation on my two test cases:
http://dnsviz.net/d/dev.gentoo.org/dnssec/
http://dnsviz.net/d/mv78100.arm.dev.gentoo.org/dnssec/

If there are no problems reported in a week or two, I'm going to enable
this for the rest of our DNS zones, as well as registering the DS
records with the TLD. Thereafter, I'd also like to deploy DANE and SSH
fingerprints in DNS, and remove our reliance any elements of the CA
chain.

I haven't implemented NSEC3 by way of a conscious choice. I don't see
the need for any private information in our DNS records - simply
obscuring them isn't really security.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : robbat2@gentoo.org
GnuPG FP   : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85


^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2013-01-24  8:57 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-01-07  1:31 [gentoo-dev] DNSSEC (w/ DLV) live on *.dev.gentoo.org Robin H. Johnson
2013-01-07  4:01 ` Doug Goldstein
2013-01-08 19:25   ` Sven Vermeulen
2013-01-07  4:23 ` "Paweł Hajdan, Jr."
2013-01-07 14:34 ` Maxim Kammerer
2013-01-07 14:42   ` Peter Stuge
2013-01-07 20:59   ` Robin H. Johnson
2013-01-07 23:18     ` Maxim Kammerer
2013-01-07 23:39   ` Benjamin Lee
2013-01-17 23:43     ` Michael Weber
2013-01-12 22:36 ` Robin H. Johnson
2013-01-17 22:36   ` Robin H. Johnson
2013-01-17 23:36     ` Michael Weber
2013-01-17 23:44       ` Michael Weber
2013-01-24  8:02 ` [gentoo-dev] DNSSEC errors on *.bugs.gentoo.org Michael Weber
2013-01-24  8:56   ` Michael Weber

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox