I saw this start at 10:14:29 CST.
Russian TLD .RU fails DNSSEC validation
11–20 of 24 posts
Re: Russian TLD .RU fails DNSSEC validation
#12I'm not familiar with DNSSEC. What sis the impact of this? Do web pages fail to load or is it just some security warning? Also was this just someone failing to update a cert in time or is this some sort of hack?
Re: Russian TLD .RU fails DNSSEC validation
#13As a side question: am I correct in reading this to imply that the two "leaf" keys here are both RSA 1024 keys? RSA 1024 has been considered within nation-state capabilities for well over a decade, and NIST has explicitly discouraged them for DNSSEC for close to a decade[1]. I can understand not using larger RSA key sizes for framing reasons, but what is stopping the DNSSEC ecosystem from using ECC? [1]: https://nvlp…
The .EDU, .NET, and .COM zones were recently migrated from RSA to ECDSA (DNSSEC algorithm 13); see, for instance: https://lists.dns-oarc.net/pipermail/dns-operations/2023-Dec...
Anyone newly enabling DNSSEC on their zone should probably use ECDSA.
Re: Russian TLD .RU fails DNSSEC validation
#14I saw this start at 10:14:29 CST.
DNSSEC is such a nightmare. All this "how do we make this old protocol secure and private without changing it much"
Also, the security chain is top-down, from owner of the TLD to the domain to the resolver to the client. With DNS over TLS and DNSCurve, you have it the other way around.
Re: Russian TLD .RU fails DNSSEC validation
#15As a side question: am I correct in reading this to imply that the two "leaf" keys here are both RSA 1024 keys? RSA 1024 has been considered within nation-state capabilities for well over a decade, and NIST has explicitly discouraged them for DNSSEC for close to a decade[1]. I can understand not using larger RSA key sizes for framing reasons, but what is stopping the DNSSEC ecosystem from using ECC? [1]: https://nvlp…
Re: Russian TLD .RU fails DNSSEC validation
#16As a side question: am I correct in reading this to imply that the two "leaf" keys here are both RSA 1024 keys? RSA 1024 has been considered within nation-state capabilities for well over a decade, and NIST has explicitly discouraged them for DNSSEC for close to a decade[1]. I can understand not using larger RSA key sizes for framing reasons, but what is stopping the DNSSEC ecosystem from using ECC? [1]: https://nvlp…
Also: why would you bother changing at this point? DNSSEC isn't getting traction (see, once again, Geoff Huston).
The 1024-bit key thing is unforgivable in 2024, but also endemic to DNSSEC.
Re: Russian TLD .RU fails DNSSEC validation
#17Poor blog's getting the hug of death :)
There are others around which I won't link to right now lest they get clobbered too.