Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Winfried Angele 🇺🇦🇪🇺

@winfried@fosstodon.org
mastodon 4.7.3
  • Open on fosstodon.org
0 Followers
0 Following
11 Posts
Joined November 20, 2022
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 8mo ago
Replying to
@gunstick@mastodon.opencloud.lu now you lost a piece of entropy ;)
3
1
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social I guess for nonexistent DS RRs it's the 'minimum' of the de. SOA RR which is 2h. But resolvers may have shorter overwrites.
1
1
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social proactive mitigation idea: permanent NTAs for zones that you are sure are not, and will not be, signed. But I'm not sure if the (signed) referrals (NS RRs) of the parent would work once they have expired
0
1
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social but I read that it's not common practice to sign referrals. https://datatracker.ietf.org/doc/html/rfc4035#appendix-B.5
RFC 4035: Protocol Modifications for the DNS Security Extensions
IETF Datatracker

RFC 4035: Protocol Modifications for the DNS Security Extensions

This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of new resource records and protocol modifications that add data origin authentication and data integrity to the DNS. This document describes the DNSSEC protocol modifications. This document defines the concept of a signed zone, along with the requirements for serving and resolving by using DNSSEC. These techniques allow a security-aware resolver to auth

0
0
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 9mo ago
Replying to
@cstrotm @miek some resolvers don't rotate the RRs of a RRset anyway. IIrc, that's the case with the PowerDNS Recursor and dnsdist. IMHO RRsets are not a use case for redundancy but for load sharing. Since the queries usually come from different resolvers, this is nevertheless achieved
0
3
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 9mo ago
Replying to
@otto @cstrotm @miek yes, turning off packet cache helps! I remember one case 3 years ago where we implemented this for 1 zone because of a complaint from a CDN. No one else has complained since. Apparently not a general problem
0
0
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 6mo ago
Replying to
@tagesschau@ard.social Pflanzen absorbieren CO2? Was für eine geniale Entdeckung
0
0
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@simon_m@infosec.exchange Yes, DNS resolver operators have implemented workarounds (NTA for de). DENIC has since fixed the issue. A post-mortem report is still pending
0
0
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social "particularly when the absence of the DS record must be ‘proven’ for an unsigned child zone." I wonder when and how often a resolver checks for the presence of the DS in a parent zone. Because it escalated very quickly
0
1
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social If I understand correctly, unsigned 'de' zones for which an NTA existed would not have been affected by the incident
0
1
0
0
Open post
Winfried Angele 🇺🇦🇪🇺 @winfried@fosstodon.org
· 5mo ago
Replying to
@jpmens@mastodon.social yes, you're absolutely right! I have a scenario in mind where I control the clients' resolvers and make my own unsigned domains/services more resilient against such incidents
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:42:09 UTC