Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

TDYR 176 – The Aftermath Of The Keene Pumpkin Festival Riots

We had an awesome day at the Keene Pumpkin Festival this past Saturday, October 18, 2014. It was an amazing, wonderful event... but you wouldn't know that from the media coverage that focused on the rioting of a large mass of college students and other young people a few streets away from where the Pumpkin Festival was happening.

FIR #778 – 10/20/14 – For Immediate Release

Millennials interview coming; Quick News: McDonald's addresses food questions, BBC's WhatsApp Ebola service, Marketers flee from YouTube to Facebook for video, UK trolls face prison; Ragan promo; News That Fits: Digital Naturals, Dan York's Tech Report, CEOs don't want to hear about intranets, Media Monitoring Minute from CustomScoop, listener comments, Google will connect you with a doctor, Igloo Software promo, last week on the FIR Podcast Network, travel tech industry connects staff with customers; how to comment; music from Holly Denton; and more.

Root DNSSEC KSK Rollover Workshop Streaming Live Today From ICANN 51

ICANN 51 Los Angeles

Today (Oct 16, 2014) from 9:00 am to 12 noon US Pacific, a special public workshop about implications of a “rollover” of the “Root Key Signing Key (KSK)” that serves as the ultimate “trust anchor” for DNSSEC will be streamed live from ICANN 51 in Los Angeles. Information about how to participate remotely can be found at:

http://la51.icann.org/en/schedule/thu-dnssec-key-rollover

(Note: the times on that page have not yet been updated.  The workshop will be from 09:00-12:00, although it may extend later if discussions continue.  It will definitely conclude by no later than 13;30 PDT.)

ICANN Chief Technology Officer (CTO) David Conrad has organized this public discussion about issues related to changing the Root KSK.  This will be a chance to publicly discuss what we collectively see as potential issues when the Root KSK is rolled or changed and what we need to do about those issues.  This is a critically important topic and so it is great to see ICANN holding this session.

The public workshop is aimed to be a discussion forum to collect guidance from a wide range of people.  An adhoc program committee was established of Joe Abley, Duane Wessels, Roy Arends, Jakob Schlyter, David Conrad and myself.  I was asked to act as a moderator to ensure that the flow moves appropriately and that all get to contribute.  The proposed agenda is:

1. INTRODUCTION

A brief level setting of why the workshop has been called, where we are at in the process (ICANN public consultation in early 2013, SSAC report, ICANN Board resolution in Nov 2013), and what we hope to do in the workshop.  (See my recent “Background Information” post for links for more info.)

2. HOW a Root KSK Rollover might occur

We would like to discuss how an automated (RFC5011) would occur as well as non-5011 roll options and options for a staggered roll.  Joe Abley will discuss a couple of relevant Internet Drafts.

3. WHAT a Root KSK Rollover might involve

We would like to discuss what changes might be made during a Root KSK Rollover. Specifically two points:

  a. ALGORITHM CHANGE – Geoff Huston will give a presentation about potential impacts of a change of the algorithm. (Geoff also presented this information about the DNS-OARC meeting this past weekend.)

  b. Length of KSK – There has been some discussion about changing the length of ZSKs and KSKs and moving to longer key sizes.  We would like a discussion around this idea and the potential impacts.

4. IMPLICATIONS

Discussion of additional implications beyond those discussed earlier.  For instance, issues around response sizes.

5. POTENTIAL TIMELINE (unanchored)

We would like to discuss what a potential timeline might look like for the entire process.  The intent is NOT to establish a fixed date but rather to establish what a timeline might look like for the full process to take place.

6. NEXT STEPS

We want to spend the end of the session identifying specific steps and actions that will occur coming out of this workshop.

If you are interested in this topic, you can join ICANN’s “ksk-rollover” mailing list and read the archives.

And if you want to get started NOW with deploying DNSSEC, why not visit our Start Here page to find resources tailored for your type of organization?

 

Watch LIVE Today – DNSSEC Workshop at ICANN 51

ICANN 51 Los AngelesStarting in just a few minutes will be the large DNSSEC Workshop from 08:30-14:45 PDT in the Pacific Palisades room at ICANN 51.  This is the BIG session of the week related to all things about DNSSEC and DANE.  The full agenda, slides and remote participation information can be found at:

http://la51.icann.org/en/schedule/wed-dnssec

(Slides and detailed agenda are not online yet but should be soon.)

The bulk of the session includes 5 panels for which we have assembled an excellent collection of speakers:

  • DNSSEC Activities in North America
  • Impact of Root Key Rollover
  • DNSSEC Deployment in Operating Systems
  • DNS/DNSSEC Monitoring
  • DANE and Email Services

Additionally I’ll be providing some DNSSEC deployment statistics and the beginning and wrapping it up with a “How You Can Help” session at the end.

These DNSSEC Workshop sessions bring together an outstanding group of technical people involved with DNS and DNSSEC and are well worth attending either in person or remotely.

And if you want to get started NOW with deploying DNSSEC, why not visit our Start Here page to find resources tailored for your type of organization?

 

DNSSEC Workshop Streaming Live From ICANN 51 On Wednesday, Oct 15 (Featured Blog)

Want to learn about the state of DNSSEC usage in North America? Or what is new in DNS monitoring? Or where DNSSEC fits into the plans of operating systems? Or how DANE is being used to bring a higher level of security to email? All those questions and much more will be discussed at the DNSSEC Workshop at ICANN 51 happening on Wednesday, October 15, 2014, from 8:30 am to 2:45 pm Pacific Daylight Time (PDT, which is UTC-7). More...

Watch LIVE Today – DNSSEC For Everybody: A Beginners Guide (ICANN51)

ICANN 51 Los AngelesAs we mentioned last week, in just a few hours you’ll be able to watch and listen live to this event coming out of ICANN 51 in Los Angeles:

17:00 – 18:30 PDT – DNSSEC for Everybody: A Beginner’s Guide

In this session we’ll once again go back to the caveman days and talk about blue smoke in a light-hearted session aimed at helping people understand DNSSEC.  We’ll also do our “skit” acting out DNS and DNSSEC again… and typically answer a great number of questions from people.  You can participate remotely and view the handout at:

http://la51.icann.org/en/schedule/mon-dnssec-everybody

It’s usually always a good time with many great questions.  I’ll be there doing the introduction and then helping with the answering of questions.

Please do look at our larger list of DNSSEC activities happening at ICANN 51 this week – MANY great activities going on!

And if you want to get started NOW with deploying DNSSEC, why not visit our Start Here page to find resources tailored for your type of organization?

See (some of) you in L.A.!

FIR #777 – 10/13/14 – For Immediate Release

People use social media when business activity is low, teens are leaving Facebook again, Comedy club in Spain charges per laugh using facial recognition, Snapchat breech shouldn't deter marketers, the Millennial you're targeting deosn't exist, Michael Netzley's Asia Report, journalism's competitors don't look like journalism, linear measurement doesn't work in social media, Dan York's Tech Report, B2B purchase decisions happen before buyers even contact your company, music from Chris Nelson, and more.

Rough Guide To ICANN 51: DNSSEC And The Root KSK Rollover

How do we increase the security of the Domain Name System (DNS)? How can we expand the usage of DNS Security Extensions (DNSSEC) and use it to create a higher level of trust on the Internet? How do we make the Internet more secure?

Most of us probably don't think all that much about DNS but yet we use it for almost every interaction we have on the Internet. Whether we are reading the latest news, buying something online, sending email to a friend or joining into whatever the latest social network is, domain names are the tool we use to connect to sites without having to remember long numerical IP addresses. We just expect it to work and take it for granted.

Dan York

Background Information For The DNSSEC Root KSK Rollover Workshop At ICANN51

ICANN 51 Los AngelesAs I mentioned yesterday, there is a great amount of DNSSEC-related activity happening at ICANN 51 in Los Angeles next week.  One of the new items is the Root KSK Rollover Workshop on Thursday, October 16, 2014, from 9:00-12noon US Pacific time (UTC-7).  This workshop will be accessible remotely from links off of this page:

http://la51.icann.org/en/schedule/thu-dnssec-key-rollover

The point of this session is to publicly discuss what potential impact we see might happen with a change of the Root Key Signing Key (KSK) that is at the heart of the DNSSEC “global chain of trust”. What impacts might there be on people using DNSSEC validation in their daily operations?  And how do we help mitigate those potential issues?

If we change the Root KSK, all the DNSSEC-validating DNS resolvers out there might update their local trust anchors to the new Root KSK and everything will be perfectly fine.  Or… they might not and so when the old Root KSK disappears those DNS resolvers might start failing to return valid DNSSEC-signed records… effectively breaking Internet usage for many people and giving DNSSEC a very bad reputation (and slowing/reducing deployment).  How do we prevent that?

It is a very important discussion!

ICANN Public Consultation

For some background on this whole issue, you can go back to the public consultation ICANN performed about the KSK rollover back in early 2013:

https://www.icann.org/public-comments/root-zone-consultation-2013-03-08-en

A report summarizing the public comments is available here:

https://www.icann.org/en/system/files/files/report-comments-root-zone-consultation-08apr14-en.pdf

That document also contains the list of “ICANN Recommendations” that were given to the ICANN Board.

The public comments themselves are available individually here:

http://forum.icann.org/lists/comments-root-zone-consultation-08mar13/

They include the comments that Andrei Robachevsky and I submitted on behalf of the Internet Society which could effectively be summarized as: we believe the Root KSK should be rolled as soon as possible and as frequently as possible.

SSAC Report

Additionally, SSAC released SAC063 with their advice on DNSSEC Key Rollover in November 2013:

https://www.icann.org/en/system/files/files/sac-063-en.pdf

All of these documents  (the comments and the SSAC report) do provide some background information into the views of various people and organizations into the implications of a KSK rollover and also motivation for the views of most that we need to roll the KSK sooner rather than later.

ICANN Board Resolution

I would also note that on November 21, 2013, the ICANN Board adopted a resolution directing ICANN’s President and CEO to evaluate the SSAC advice and provide a recommendation to the board regarding the acceptance of that advice within 90 days:

https://features.icann.org/board-advice#advice-to-board_f=dnssec%20key%20rollover&advice-to-board_d=false&advice-to-board_e=18

That process started… but then stalled when the larger “IANA Transition” issue was injected by the NTIA last year.  This workshop next week, as well as the private interop testing, is, in my view, an effort by ICANN’s new CTO, David Conrad, to try to get this effort back on track and make some actions happen.

Going Forward

A key point about this workshop on Thursday, October 16, is that most people are not talking about IF the Root KSK will be rolled, but rather HOW the Root KSK can be rolled most effectively and how we can mitigate any potential issues that arise.  It is also interesting to note that some of the discussion has changed from the need to roll the key for cryptographic/security reasons to talking about the need to change the Root KSK to, for instance, utilize a better and faster encryption algorithm.

Ksk-rollover Mailing List

Much of this discussion is happening on the ksk-rollover mailing list hosted by ICANN. This list is open to the public and anyone can join.  The ksk-rollover list archives provide additional background info for the meeting on Thursday.

This public workshop should be an interesting discussion next Thursday.  I do encourage anyone interested in this important issue to join in and participate.

2-Page IPv6 Fact Sheet Now Available In English, French and Spanish

DNSSEC Fact SheetHave you ever wished that there was a simple “2-page” document that you could give people explaining IPv6 and what it is all about?  Would you like a IPv6 “handout” that you can distribute at events or send to colleagues or vendors?

If so, we’ve now added a “IPv6 Fact Sheet” to our site in the following languages:

We’ll be adding versions in Arabic,  Chinese and Russian soon.

Please feel free to download these and use them in whatever way you wish.  Email them to people.  Print them out and pass them out at a meeting.  Distribute them on a conference USB drive… do whatever you want with them!

Because we may update the fact sheets from time to time, we would encourage you to direct people to this simple URL to find the fact sheets:

http://www.internetsociety.org/deploy360/ipv6/factsheet/

And please let us know any feedback you have on these documents.  We’re here to help you get IPv6 more widely deployed and want to be as helpful as possible.  How can we help you get the information you need?

Finally, please do direct people to our Start Here page at https://www.internetsociety.org/deploy360/start/ so that they can find IPv6 resources targeted at their role or type of organization.

P.S. Please also check out our DNSSEC Fact Sheet.