[dns-wg] Announcement - DNS flag day on 2019-02-01

2018-05-29 Thread Petr Špaček
eb site or similar as Github issues: https://github.com/dns-violations/dnsflagday I hope you find the information useful. -- Petr Špaček @ CZ.NIC

Re: [dns-wg] automatic DS record updates in the RIPE database

2018-11-29 Thread Petr Špaček
it can be made neater if > it is integrated more closely. > > I would like to help get RFC 7344 support into the RIPE database, so what > do we need to do next to make it happen? BTW scanner tool (for registry side) is available from https://github.com/CZ-NIC/fred-cdnskey-scanner -- Petr Špaček @ CZ.NIC

Re: [dns-wg] RIPE 78 talk proposal: DNS flag day 2019 and beyond

2019-04-02 Thread Petr Špaček
u for understanding and considering this talk. Petr Špaček @ CZ.NIC On 27. 02. 19 0:57, Dave Knight wrote: > Dear colleagues, > > The RIPE 78 meeting in Reykjavik is a few weeks away and we’d like to > form our agenda. > > Please submit your presentation ideas, or suggest

Re: [dns-wg] RIPE 78 talk proposal: DNS flag day 2019 and beyond

2019-04-02 Thread Petr Špaček
Doh! I apologize for lame copy-paste error. Petr Špaček @ CZ.NIC On 02. 04. 19 16:28, Petr Špaček wrote: > Hello, > > please see proposed lightning talk proposal. > > DNS flag day 2019 and beyond > > During February 2019 DNS recursive resol

Re: [dns-wg] New on RIPE Labs: NXNSAttack: Upgrade Resolvers to Stop New Kind of Random Subdomain Attack

2020-05-21 Thread Petr Špaček
for variants of this problem (CWE-405, CWE-406, CWE-1050 are first three I found right now). That very strongly suggests security community cares enough to distinguish individual "insufficiently bounded work" problems no matter what protocol or software it affects. To conclude: No matt

Re: [dns-wg] DNSSEC Validation Failures for RIPE NCC Zones

2020-05-25 Thread Petr Špaček
key roll-overs to be finished too early, leading to temporary DNSSEC validation failures. More detailed problem description + workaround: https://lists.nic.cz/pipermail/knot-dns-users/2020-May/001813.html We apologize to everyone affected. -- Petr Špaček @ CZ.NIC

[dns-wg] Survey: How Do You Configure DNS Resolvers?

2020-06-26 Thread Petr Špaček
participate in the survey. The survey closes on Tuesday 2020-06-30. Have a nice weekend! -- Petr Špaček @ CZ.NIC

Re: [dns-wg] DNS wg co-chair selection: candidates

2021-11-10 Thread Petr Špaček
+1 for Moritz as well Petr Špaček On 03. 11. 21 14:09, João Damas wrote: Dear all, The deadline for DNS WG co-chair candidate volunteering is now over. I am happy to announce that we have two great candidates. The period to express support for your preferred candidate(s) starts now and runs

Re: [dns-wg] Lower TTLs for NS and DS records in reverse DNS delegations

2021-12-02 Thread Petr Špaček
- Even if the delegation was hijacked (unlikely for reverse zone, so here just to illustrate) the lower TTL would help fixing it/pointing it back to the rightful owner. What do you think? It seems so simple that I now have to wonder why registries are not doing it? -- Petr Špaček @ Inter

Re: [dns-wg] Lower TTLs for NS and DS records in reverse DNS delegations

2021-12-02 Thread Petr Špaček
don't believe we are in this ideal world. And if the "explicit" option not practical for any reason, we are left either with static or dynamic "defaults" imposed by the registry. Pick you poison then. On 02. 12. 21 15:37, Jim Reid wrote: On 2 Dec 2021, at 13:46, Petr Š

Re: [dns-wg] EU: DNS abuse study

2022-02-04 Thread Petr Špaček
worldwide that can be effectively used as amplifiers in distributed denial-of-service attacks (Appendix 1 – Technical Report, Section 16.4, p. 70). The numbers above sound interesting. -- Petr Špaček -- To unsubscribe from this mailing list, get a password reminder, or change your subscription

Re: [dns-wg] DNS4EU community comment draft proposal

2022-02-04 Thread Petr Špaček
not picking here at DT. Other big telcos report similarly grandiose financials. -- Petr Špaček speaking only for myself -- To unsubscribe from this mailing list, get a password reminder, or change your subscription options, please visit: https://lists.ripe.net/mailman/listinfo/dns-wg

Re: [dns-wg] DNS wg co-chair selection: candidates

2022-10-10 Thread Petr Špaček
the candidate. Willem Toorop I propose myself as a candidate to follow-up Shane as DNS working group co-chair. I support the selection of Willem as the next RIPE DNS working group co-chair. -- Petr Špaček -- To

Re: [dns-wg] DNSSEC and DHCP

2023-05-23 Thread Petr Špaček
the dynamic update. Besides other things this allows for redundancy both on DHCP and DNS side. If you want to migrate to another DHCP server then please skip ISC DHCP (that's basically end-of-life) and go straight to Kea (also by ISC) or something else. HTH. -- Petr Špaček Internet Sys

Re: [dns-wg] Draft of RIPE DNS Resolver Best Common Practices

2023-11-29 Thread Petr Špaček
I think this is worth calling out. "Even if your server is not going to answer a query, send back at least RCODE REFUSED." or something like that. Congratulations if you made it this far - and thank you for your time! -- Petr Špaček Internet Systems Consortium -- To unsubscr

Re: [dns-wg] Draft of RIPE DNS Resolver Best Common Practices

2023-11-29 Thread Petr Špaček
n/related monitoring. I have witnessed attacks where it actually helped to keep performance at reasonable levels while under PRSD. The trouble is that attacker quickly realizes that it's not working _for him_ and moves to another target, so of it does not make it into the news :-

[dns-wg] OARC 43 - Call for Contribution

2024-04-17 Thread Petr Špaček
:00 UTC-5 Co-located with - related industry events, will be confirmed later Deadline for Submissions - 2024-06-23 23:59 UTC For further details please see https://indico.dns-oarc.net/event/51/abstracts/ Petr Špaček, for the DNS-OARC Programme Committee -- To unsubscribe from this mailing list

[dns-wg] Survey & invitation: Open source quality assurance & risks @ RIPE 88 Open Source WG

2024-05-13 Thread Petr Špaček
e see the open-source Q&A processes, compare these wishes with real example of what is being done today around BIND DNS server, and follow all that with an open discussion at the microphone. See you in Krakow! -- Petr Špaček Internet Systems Consortium -- To unsubscribe from this mailin

[dns-wg] DNS-OARC 43 - moved to Prague, CZ - 2024 October 26-27

2024-06-04 Thread Petr Špaček
Community day which will happen in the original location and date. See https://indico.dns-oarc.net/e/SMR2024 for more details. See you there! -- Petr Špaček, for the DNS-OARC Programme Committee -- To unsubscribe from this mailing list, get a password reminder, or change your subscription

[dns-wg] DNS-OARC 44 - Call for Contribution

2024-09-13 Thread Petr Špaček
. For further details please see https://www.dns-oarc.net/oarc44 Petr Špaček, for the DNS-OARC Programme Committee - To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/dns-wg.ripe.net/ As we have migrated to Mailman