DNSSEC disruption affecting .de domains – Resolved
171–180 of 440 posts
Re: DNSSEC disruption affecting .de domains – Resolved
#172Earlier quoted context omitted.
What you see here is decentralisation working. The issue is with the operator of the de TLD, and as such only that TLD is affected. DNS is not decentralised in such a way, that multiple organisations run the infrastructure of a TLD, those are always run by a single entity.(.com and .net are operated by Verisign) So what the issue is, that the operator has, does not change the impact.
What if the root (.) certificate breaks?
The world might be a little bit better with more decentralization of the root zone.
Re: DNSSEC disruption affecting .de domains – Resolved
#173Earlier quoted context omitted.
It's Germany, pessimistic time estimation + 1/3 and you are in a realistic time frame for the issue being resolved.
It's night. Somebody has to fill a form to approve night work first.
Re: DNSSEC disruption affecting .de domains – Resolved
#174Re: DNSSEC disruption affecting .de domains – Resolved
#175Crazy. I can't remember an incident like this ever happened before and it's still not fixed? .de is probably the most important unrestricted domain after .com from an economical perspective. Millions of businesses are "down".
Re: DNSSEC disruption affecting .de domains – Resolved
#176I have never used DNSSEC and never really bothered implementing it, but do I understand it correctly that we took the decentralized platform DNS was and added a single-point-of-failure certificate layer on top of it which now breaks because the central organisation managing this certificate has an outage taking basically all domains with them?
> which now breaks because the central organisation managing this certificate has an outage The ".de" TLD is inherently managed by a single organization, and things wouldn't be much better if its nameservers went down. Some of the records would be cached by downstream resolvers, but not all of them, and not for very long. > we took the decentralized platform DNS was and added a single-point-of-failure certificate lay…
but how would one verify the signature if the DNSKEY expired and you cannot fetch a fresh one because the organisation providing those keys is down? As far as I understood the TTL for those keys is different and for DENIC it seems to be 1h [0]. So if they are down for more than an hour and all RRSIG caches expire, DNS zones which have a higher TTL than 1h but use DNSSEC would also be down?
[0] dig RRSIG de. @8.8.8.8
de. 3600 IN RRSIG DNSKEY 8 1 3600 20260519214514 20260505201514 26755 de. [...]
Re: DNSSEC disruption affecting .de domains – Resolved
#177Looks like a DNSSEC issue, not a nameserver outage. Validating resolvers SERVFAIL on every .de name with EDE: RRSIG with malformed signature found for a0d5d1p51kijsevll74k523htmq406bk.de/nsec3 (keytag=33834) dig +cd amazon.de @8.8.8.8 works, dig amazon.de @a.nic.de works. Zone data is intact, DENIC just published an RRSIG over an NSEC3 record that doesn't validate against ZSK 33834. Every validating resolver therefor…
So a single configuration mistake in a single place wiped out external reachability of a major economy. It happened in the evening local time and should be fixable, modulo cache TTLs, by morning. This will limit the blast radius somewhat. Still, at this level, brittle infrastructure is a political risk. The internet's famous "routing around damage" isn't quite working here. Should make for an interesting post mortem.
Re: DNSSEC disruption affecting .de domains – Resolved
#178DENIC's status page currently says "Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability. The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.
Re: DNSSEC disruption affecting .de domains – Resolved
#179Re: DNSSEC disruption affecting .de domains – Resolved
#180There’s no way it’s DNS
It was DNSSEC