#dnssec

19 posts · Last used 8d

Skeptische Blicke beim #Stalwart-Vortrag am #LinuxDayAT – denn Mailserver-Installation und -Betrieb gelten als kompliziert. Bei Stalwart offenbar nicht. 😉 @opensourceuser@mastodon.social, 16 Jahre alt, hatte meinen Vortrag beim #CLT26 gesehen und die Installation direkt ausprobiert. Ergebnis: ein eigener, funktionierender Mailserver! 🎉 Anschließend haben wir anhand von https://www.hardenize.com noch den letzten Feinschliff besprochen: #DNSSEC, #MTA-STS, #TLS-RPT und #DANE. Gerade nachgeschaut: Alles umgesetzt! 🎉 Besser geht's nicht. Solche Erfolgserlebnisse geben Energie für die nächsten Vorträge. ❤️
14
3
7
0
Hosting your own mailserver? It easy sometimes sometimes you sitting there trying to figure why the hell will Microsoft only connect and then quit. And not sending without any change to the mail-server. Updating the server looking through the config. Looking at the certificate. And nothing. And starting to think that Microsoft is a shit mail company. Because google, yahoo and every other service i tried to send to my own server worked. Everyone else will send to my server. And I have one that send email to me that use Microsoft. After a few hours troubleshooting. I finely found the problem. Drum role ..... IT was the DNS!! 😂 #selfhosting #DNS #DNSSEc #DANE #alwaysdns
0
1
0
0
A sad lesson from a few years of operating local #DNS resolvers in my infrastructure - #DNSSEC validation requires enormous resources to work reliably due to vast extra records it needs to pull from DNS for each validation and required computing power. Forget about DNSSEC validation in systemd-resolved, dnsmasq or unbound on home routers, it will just cause periodic and apparently unexplained delays and choke overall DNS resolution. On firewalls like #OPNsense it also would work only server-class devices, any of the desktop-class fanless hardware won’t work reliably for DNSSEC validation even if they can perfectly handle production-class proxy and firewall traffic. Probably what only makes sense is a dedicated Unbound validation server, a separate container or jail but running within a proper hardware server with tons of memory and CPU. But then I found out that it’s much easier to use non-DNSSEC caching resolvers on perimeter devices that forward queries to Quad9 ECS resolvers[^1] which already do DNSSEC validation. The only missing bit is that I think my local resolvers don’t forward the DO bit downstream, but that I need to still check. [^1]: https://quad9.net/service/service-addresses-and-features/#ecssec
0
1
0
0
DNSSEC has been technically viable for years, yet adoption is still embarrassingly low. The root zone is signed, but most downstream resolvers and domains remain vulnerable to cache poisoning. We need real pressure on providers, not more standards. #dnssec #security #internet
0
0
1
0

A botched DNSSEC ZSK rollover by DENIC on May 6, 2026, caused a widespread SERVFAIL cascade, making millions of .de domains unreachable. This incident highlights DNSSEC's "fail-closed" design, forcing Cloudflare to temporarily disable validation for .de to restore access, raising serious questions about operational resilience.

https://www.tpp.blog/2098lw3

#cybersecurity #dnssec #dedomains

🤖 This post was AI-generated.

0
0
1
0
Dass gestern Abend bei der DENIC ausgerechnet DNSSEC (wohl für die TLD .de und damit alle DNSSEC-signierten Domains unter dieser TLD) ausgefallen ist, ist schon wirklich heftig. Das hat ja nun weitreichende Folgen gehabt. Bei mir waren alle meine Domains (davon drei mit einigem Traffic) nicht mehr erreichbar, ich konnte keine Mails mehr bei Mailbox.org abrufen (hätte ich noch meinen eigenen Mail-Server gehabt, wäre das Ergebnis dasselbe gewesen). #DENIC #DNSSEC
2
2
0
0
Seit gut einer Stunde sind viele Webseiten mit .de Domains down: Der Grund liegt diesmal bei der DENIC herself. Die DENIC ist die oberste Domain Verwaltungsstelle in Deutschland, bzw. für .de Domains. "Investigating It seems like the fault is related to DNSSEC issues with "de" domains on a registry level. Further information from DeNIC can be found at https://status.denic.de/ Due to a fault, there is currently limited availability to the recursive DNS resolution for "de" domains." Heisst soviel wie, die Namensauflösung von .de Domains hat aktuell ein Problem. Sprich, wenn ein Browser nach der Domain www.bge.de fragt, dann kann der DNS nicht zu einer IP auflösen, die nötig ist, um den Request an den richtigen Server zu schicken. Meine privaten seiten mit .de domain sind ebenfalls alle down..... #denic #dns #dnssec
14
8
13
0
You've seen all posts