November 5, 2014 archive

Rough Guide to IETF 91: DNSSEC, DANE and DNS Security

IETF 91 will once again be busy for those of us interested in DNSSEC, DANE and DNS security in general. Two of the major DNS-related working groups, DNSOP and DANE, are both meeting with busy agenda and a new working group called DPRIVE will be meeting to talk about DNS privacy concerns. There are naturally other items related to DNSSEC and "DNS security" in general scattered throughout the week - here is what the week looks like...

NOTE: If you are unable to attend IETF 91 in person, there are multiple ways to participate remotely and listen to these sessions.

Dan York

12 Days Until ION Tokyo!

ION TokyoION Tokyo is coming up soon on Monday, November 17, 2014!  We’ll be live in the same venue as the Japan IPv6 Summit with an agenda packed full of technical sessions.  To learn more visit our ION Tokyo page at:

http://www.internetsociety.org/deploy360/ion/tokyo2014/

The sessions will include:

  • An IPv6 Case Study from NTT
  • The Business Case for Implementing DNSSEC
  • Best Current Operational Practices Update
  • Panel Discussion – IPv6 in Asia

The event has excellent speakers and we’re looking forward to meeting with network operators, enterprises and many others.

If you are going to be in Tokyo for the Japan IPv6 Summit or for Internet Week Japan, please do join us Monday morning for ION Tokyo!

A Great Amount of DNSSEC / DANE / DNS Activity At IETF 91 Next Week

IETF LogoWhat is happening next week at IETF 91 in Honolulu with regard to DNSSEC, DANE and other “DNS security” topics?

great amount of activity, it turns out!

So much that my “Rough Guide to IETF 91: DNSSEC, DANE and DNS Security” turned into quite a lengthy article.  Please read that article for the full description, but a quick summary can be:

  • DNSOP will have discussions around “Negative Trust Anchors”, “DNS Cookies” and more.
  • DANE will discuss using DANE for email, and specifically S/MIME, as well as SRV records and a discussion led by me about what we can learn from current deployments of DANE.
  • A brand new DPRIVE working group will be exploring challenges around privacy and confidentiality of DNS queries.
  • TRANS will look at applying Certificate Transparency (CT) mechanism to DNSSEC keys.
  • EPPEXT will discuss how to move a draft forward about secure transfer of DNSSEC-signed domains between registrars.
  • HOMENET and DNSSD will both be looking at different aspects of using DNS with small networks or “Internet of Things” (IoT) environments – and the question of course is how this usage gets secured.

… and again you’ll want to read the full article to understand more.  The key point is that it will be busy for those of us interested in DNS-related issues!   If you are going to be out at IETF 91, please do contact us or find me there.  Odds are pretty good you’ll find me in either the DNS or IPv6 sessions!

And if you want to get started today with DNSSEC, please visit our Start Here page to learn how!