nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,8 Tsd.
aktive Profile

#dnssec

3 Beiträge3 Beteiligte0 Beiträge heute
ϺΛDИVTTΛH<p>Version 1.23.0-0 of our <a href="https://fosstodon.org/tags/unbound" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>unbound</span></a> docker image was released by madnuttah-bot yesterday! 💚</p><p><a href="https://fosstodon.org/tags/OpenSSL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSSL</span></a> has been updated to 3.5.0 after testing in the <a href="https://fosstodon.org/tags/canary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>canary</span></a> image, too.</p><p><a href="https://github.com/madnuttah/unbound-docker" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/madnuttah/unbound-d</span><span class="invisible">ocker</span></a></p><p><a href="https://hub.docker.com/r/madnuttah/unbound" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hub.docker.com/r/madnuttah/unb</span><span class="invisible">ound</span></a></p><p><span class="h-card" translate="no"><a href="https://fosstodon.org/@nlnetlabs" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnetlabs</span></a></span> </p><p><a href="https://fosstodon.org/tags/foss" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>foss</span></a> <a href="https://fosstodon.org/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://fosstodon.org/tags/selfhosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhosting</span></a> # homelab <a href="https://fosstodon.org/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://fosstodon.org/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a></p>
John Shaft<p>Yay, Finland goes elliptic after a week or so of insecurity</p><p><a href="https://mastodns.net/@diffroot/114383836309131015" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mastodns.net/@diffroot/1143838</span><span class="invisible">36309131015</span></a></p><p><a href="https://piaille.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a></p>
JP Mens<p>FI. is almost there ... :-) </p><p><a href="https://mastodon.social/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a></p>
Stéphane Bortzmeyer<p>On an <a href="https://mastodon.gougere.fr/tags/IETF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IETF</span></a> mailing list, about an excellent property of data security (as opposed to channel security): "you can pick up your <a href="https://mastodon.gougere.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> answer from the street and still validate it".</p>
John Kristoff<p>NIST SP-800-81: Secure Domain Name System (DNS) Deployment Guide initial public draft open for public comments.</p><p><a href="https://csrc.nist.gov/pubs/sp/800/81/r3/ipd" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">csrc.nist.gov/pubs/sp/800/81/r</span><span class="invisible">3/ipd</span></a></p><p><a href="https://infosec.exchange/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> <a href="https://infosec.exchange/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> <a href="https://infosec.exchange/tags/NIST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NIST</span></a></p>
Stéphane Bortzmeyer<p><a href="https://mastodon.gougere.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> <br>Apple is moving from the old RSA with SHA-1 to ECDSA for its TLD <a href="https://dnsviz.net/d/apple/Z_jGvA/dnssec/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">dnsviz.net/d/apple/Z_jGvA/dnss</span><span class="invisible">ec/</span></a></p>
PowerDNS<p>PowerDNS Recursor 5.0.10, 5.1.4 and 5.2.2 Released<br><a href="https://blog.powerdns.com/2024/04/09/powerdns-recursor-5-0-10-5-1-4-5-2-2-released" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.powerdns.com/2024/04/09/p</span><span class="invisible">owerdns-recursor-5-0-10-5-1-4-5-2-2-released</span></a> <a href="https://fosstodon.org/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://fosstodon.org/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/Dnsmasq" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dnsmasq</span></a> 2.91 has been released (<a href="https://mastodon.social/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> / <a href="https://mastodon.social/tags/AAAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AAAA</span></a> / <a href="https://mastodon.social/tags/CNAME" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CNAME</span></a> / <a href="https://mastodon.social/tags/PTR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PTR</span></a> / <a href="https://mastodon.social/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> / <a href="https://mastodon.social/tags/DHCP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DHCP</span></a> / <a href="https://mastodon.social/tags/DHCPv4" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DHCPv4</span></a> / <a href="https://mastodon.social/tags/DHCPv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DHCPv6</span></a> / <a href="https://mastodon.social/tags/BOOTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BOOTP</span></a> / <a href="https://mastodon.social/tags/TFTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TFTP</span></a> / <a href="https://mastodon.social/tags/PXE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PXE</span></a>) <a href="https://thekelleys.org.uk/dnsmasq/doc.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">thekelleys.org.uk/dnsmasq/doc.</span><span class="invisible">html</span></a></p>
PowerDNS<p>PowerDNS Recursor Security Advisory 2025-01 (aka PowerDNS Recursor 5.2.1 Released)<br><a href="https://blog.powerdns.com/2025/04/07/powerdns-recursor-5-2-1-released" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.powerdns.com/2025/04/07/p</span><span class="invisible">owerdns-recursor-5-2-1-released</span></a> <a href="https://fosstodon.org/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://fosstodon.org/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a></p>
Stéphane Bortzmeyer<p>223.5.5.5 (AliDNS) seems to be one of the few big public <a href="https://mastodon.gougere.fr/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> resolvers without <a href="https://mastodon.gougere.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> validation. Anyone to talk to Xi Jiping about this issue?</p>
Anton<p>Hat hier wer Connections zur IT-Abteilung von aok.de? Die haben gestern das SSL-Zertifikat ihres mx1.aok.de getauscht, aber den TLSA-Record für DANE übersehen...</p><p><a href="https://dane.sys4.de/smtp/service.bw.aok.de" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">dane.sys4.de/smtp/service.bw.a</span><span class="invisible">ok.de</span></a></p><p>20:00 Uhr: geht wieder! Danke :)</p><p><a href="https://mastodon.social/tags/DANE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DANE</span></a> <a href="https://mastodon.social/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> <a href="https://mastodon.social/tags/TLS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLS</span></a> <a href="https://mastodon.social/tags/aok" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>aok</span></a></p>
John Shaft<p>tl;dr :<br>- env. 4 215 000 domaines enregistrés dans .fr au 31 décembre 2024<br>- 19,8% des domaines signés avec <a href="https://piaille.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> (≈ 835 000). Chiffre pudiquement qualifié de « modeste ».<br>- 31646 <a href="https://piaille.fr/tags/IDN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IDN</span></a> enregistrés, soit ≈ 0,75% du total. Ridiculement bas</p><p>« Bilan du .fr en 2024 : plus de 800 000 nouveaux noms enregistrés »<br><a href="https://www.afnic.fr/observatoire-ressources/actualites/bilan-du-fr-en-2024-plus-de-800-000-nouveaux-noms-enregistres/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">afnic.fr/observatoire-ressourc</span><span class="invisible">es/actualites/bilan-du-fr-en-2024-plus-de-800-000-nouveaux-noms-enregistres/</span></a></p>
Jan Schaumann<p>"Nope: Strengthening Domain Authentication with Succinct Proofs"</p><p><a href="https://nope-tools.org/nope.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">nope-tools.org/nope.pdf</span><span class="invisible"></span></a></p><p>Basically:<br>domain owner <a href="https://mstdn.social/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> signs their name, then encodes a proof of that DNSSEC chain into a new domain name, stashes that in a SAN in the cert and wants the client to verify the proof against... the root ZSK? Which it fetches via DoH from Google DNS, but... doesn't verify?</p><p>Not sure I get it.</p><p><a href="https://mstdn.social/tags/realworldcrypto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>realworldcrypto</span></a> <a href="https://mstdn.social/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a></p>
Jan Schaumann<p>Post-Quantum <a href="https://mstdn.social/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> Testbed with BIND and PowerDNS </p><p><a href="https://pq-dnssec.dedyn.io/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">pq-dnssec.dedyn.io/</span><span class="invisible"></span></a></p><p><a href="https://mstdn.social/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://mstdn.social/tags/RealWorldCrypto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RealWorldCrypto</span></a> <a href="https://mstdn.social/tags/pqc" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pqc</span></a></p>
gregR ☯<p><span class="h-card" translate="no"><a href="https://mastodon.gougere.fr/@bortzmeyer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bortzmeyer</span></a></span> le principal intérêt de <a href="https://mamot.fr/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a> <br><a href="https://www.bortzmeyer.org/dns-afrinic-stale.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bortzmeyer.org/dns-afrinic-sta</span><span class="invisible">le.html</span></a><br>Mais vous le connaissez :)<br>Le reste <a href="https://ianix.com/pub/dnssec-outages.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ianix.com/pub/dnssec-outages.h</span><span class="invisible">tml</span></a><br>Avec un petit faible pour Slack <a href="https://lists.dns-oarc.net/pipermail/dns-operations/2021-September/021340.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">lists.dns-oarc.net/pipermail/d</span><span class="invisible">ns-operations/2021-September/021340.html</span></a></p>
Stéphane Bortzmeyer<p>Formation <a href="https://mastodon.gougere.fr/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a> toute la semaine prochaine. Si vous avez des exemples de trucs DNSSEC rigolos (par exemple des erreurs de configuration, ou au contraire des déploiements réussis), c'est le moment de les citer.</p>
ChaCha20Poly1305<p>@bortzmeyer@mastodon.gouger Aurais-tu des conseils pour fournir une zone DNS&nbsp;via un script Python/Perl qui génère des enregistrements à la volée (sans les stocker) et faire du <a href="https://mastodon.libre-entreprise.com/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a>&nbsp;dessus ? Je bataille avec PowerDNS.</p>
PowerDNS<p>First alpha release of PowerDNS DNSdist 2.0.0<br><a href="https://blog.powerdns.com/2025/03/18/first-alpha-release-of-powerdns-dnsdist-2.0.0" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.powerdns.com/2025/03/18/f</span><span class="invisible">irst-alpha-release-of-powerdns-dnsdist-2.0.0</span></a> <a href="https://fosstodon.org/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://fosstodon.org/tags/dnssec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnssec</span></a></p>
IPFire News<p>IPFire protects your DNS requests from being forged by using <a href="https://social.ipfire.org/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a></p>
Jan Schaumann<p>System Administration</p><p>Week 7, The Domain Name System, Part III</p><p>In this video, we try to wrap up our discussion of the Domain Name System by addressing the nature of the root nameservers, looking at various different resource record types, observing reverse lookups, and thinking about how we can have assurance of authenticity and integrity of the <a href="https://mstdn.social/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> results returned to us via <a href="https://mstdn.social/tags/DNSSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSSEC</span></a>.</p><p><a href="https://youtu.be/XDJEJFVNoko" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/XDJEJFVNoko</span><span class="invisible"></span></a></p><p><a href="https://mstdn.social/tags/SysAdmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SysAdmin</span></a> <a href="https://mstdn.social/tags/DevOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevOps</span></a> <a href="https://mstdn.social/tags/SRE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SRE</span></a></p>