Archive for category Uncategorized

Visual inventories track U.S., Sweden deployment

As DNSSEC deployment rolls out in government domains in the U.S. and elsewhere, we’re seeing more lists that visually display the status of deployment within a top-level domain.  Here are some recent examples:

  • From the U.S. .GOV TLD:  Using a list of domain names taken from the web sites catalogued in the USA.gov website, Initiative partner Scott Rose of the U.S. National Institute of Standards and Technology wrote a script that queried which had a secure link from .GOV.  The results, shown here, note that the “U.S. Federal Government maintains some domain names outside of the .gov gTLD. Likewise, there are state, local, and sovereign nation delegations found in .gov that are not required to deploy DNSSEC, but may deploy voluntarily.”   Signed U.S. state domains include Vermont’s vermont.gov, vermonttreasurer.gov, and healthvermont.gov, the state’s health department;  Idaho’idaho.gov and idahobyways.gov from the state’s transportation department; Louisiana‘s lacoast.gov, from the Louisiana Coastal Wetlands Conservation and Restoration Task Force; the Tennessee Valley Authority’s tva.govUtah Fire Info, a federal-state partnership; and Virginia.gov.
  • From Sweden:  Two separate pages display DNSSEC deployment progress among municipal domains and in public sector agencies there, with hundreds of sites listed.

, ,

No Comments

DNSSEC overhead examined

Cricket Liu of Infoblox has posted a second article in his series on DNSSEC overhead.  He notes: 

…I’ve recommended that organizations deploying DNSSEC watch the CPU load on their recursive name servers carefully:  As the proportion of responses that are signed increases, so will the load on their recursors. Ultimately, though, the ever-increasing speed of processors and networks will trump the burden DNSSEC adds.  Years from now – assuming DNSSEC becomes widely deployed – we’ll look back at our concerns about the overhead of DNSSEC and chuckle.  I hope.

,

No Comments

Deployment watch: SWITCH turns on DNSSEC at Domain Pulse meeting

Circle ID reports that SWITCH, the registry for Switzerland’s .CH and .LI, was enabled yesterday at the Domain Pulse conference in Luzern.  From the article: 

SWITCH became the third ccTLD registry to enable DNSSEC giving registrants of .CH domain names added security following .SE (Sweden) and .CZ (Czech Republic)….At the Domain Pulse conference, Urs Eppenberger of SWITCH and Marc Furrer of the Swiss Federal Communications Commission (ComCom) enabled DNSSEC….”I am particularly proud of the fact that Switzerland is one of the first countries in Europe to introduce DNSSEC. This now guarantees security in the internet” said a delighted Marc Furrer, President of ComCom, in a statement.

No Comments

Speakers added to DNSSEC FOSE program

New speakers have been added to the Initiative’s daylong session What’s Next in DNSSEC at the FOSE conference and expo in March in Washington, DC.   New speakers include representatives from Afilias, BlueCat Networks, Data Mountain Solutions, F5 Networks, Nominum, Secure64 and Xelerance.

No Comments

Preview: DNSSEC workshop at ICANN Nairobi meeting

ICANN’s Security and Stability Advisory Committee will convene a DNSSEC workshop at the Nairobi meeting on Wednesday, March 10, from 9:00 am to 12 noon.  The program, intended for “anyone with an interest in the deployment of DNSSEC, especially registry and registrar representatives from technical, operational, and strategic planning roles,” is still in development.  Thus far, updates are expected on these topics:

  • Implementation of DNSSEC at the Root
  • Operational issues with DNSSEC, including technical presentations on transfers and key rollovers
  • Adoption Issues, including experience with hurdles and incentives
  • Activities from the region
  • Extending DNSSEC deployment

To register or learn more about the ICANN Nairobi meeting, go here.

No Comments

AFNIC urges readiness for a signed root

AFNIC, the registry of the database of .fr (France) and .re (Reunion Island) Internet domain names, has issued this announcement to network administrators, inviting them to prepare for the advent of DNSSEC deployment at the root and offering preparation steps, links to resources and more.

No Comments

Deployment watch: Nominet to sign .UK March 1

Nominet, the Internet registry for .UK domain names, has announced it will implement DNSSEC in zones it manages, beginning March 1, 2010 with the .UK top-level domain. The announcement notes:

With the signing of the root so close (scheduled for mid-2010), we have taken the decision not to include the keys in the major DNSSEC key stores…Instead, we will use the period as an extended operational test, waiting until the root goes live before publishing our trust anchor in the root zone.

The next phase will include signing .co.uk and other SLDs, Nominet said.

, , ,

No Comments

Deployment watch: 15,000 Czech domains signed “in one go”

The Czech registry CZ.NIC announced yesterday that nearly 15,000 Czech domains (14,236) were signed yesterday, all at once.  WEB4U, one of the largest Czech registrars with 21,000 registered .CZ domains, decided to implement DNSSEC in all its registered domains, automatically and free of charge. 

The CZ.NIC Association launched DNSSEC in October 2008 and says it registered 1414 DNSSEC-protected domains by the end of 2009.   CEO Ondrej Filip said:  

We greatly appreciate WEB4U’s decision because it will significantly contribute to the security of not only the Czech Internet. By doing so, we also point the way to other countries which are currently launching the technology. DNSSEC is important in particular for those who seek the highest possible security of their information on the Internet. Among these are banks or e-shops on whose websites the visitors often enter sensitive personal data such as user names and passwords, credit card numbers etc.

No Comments

DNSSEC session at FOSE adds speakers

Picture1We’re adding new speakers every day: Follow this link to see the updated program for the DNSSEC Deployment Coordination Initiative’s special session at the FOSE conference and exhibition. ” What’s Next in DNSSEC: Securing the Domain Name System,” will take place on Wednesday, March 24, 2010, from 10:30 a.m. to 4:30 p.m.  The conference attracts U.S. government information technology professionals in Washington, D.C.  In addition to the session, the FOSE Expo will include a special DNSSEC Pavilion with booths from the Initiative as well as other DNSSEC-related exhibitors. 

Registration for FOSE is free for U.S. government employees, government contractors and U.S. military, and registration for the Expo is $50.  Go here to register for FOSE.  To exhibit in the DNSSEC Pavilion at FOSE, contact Don Berey, Show Director at 703-876-5073 or email [email protected].

No Comments

Deployment watch: Malaysia targets 4th quarter

Malaysia’s .my registry is targeting the fourth quarter of 2010 for its deployment, following a testbed and a public trial. Norsuzana Harun, technology and innovation manager at .myDomainRegistry, writes this update in TechCentral:

In Malaysia, .myDomainRegistry is also preparing for DNSSEC deployment. Following the completion of a closed testbed, the organisation will be conducting the DNSSEC Public Trial, which aims to provide first-hand experience on the workings of DNSSEC, encourage adoption of the technology and improve current DNSSEC policies and end-user manuals.  .myDomainRegistry targets for DNSSEC deployment in Q4 this year. Key stakeholders play a very important part in creating a trusted network that will ensure the success of DNSSEC.

No Comments