Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

A Great Amount Of DNSSEC/DANE Activity At ICANN 51 In L.A. Next Week

ICANN 51 Los AngelesStarting in just a few days there is going to be a great amount of activity related to DNSSEC and DANE happening in conjunction with the ICANN 51 meeting in Los Angeles from October 12-16, 2014.

As usual, there will be the large DNSSEC Workshop on Wednesday, October 15 that always happens with ICANN meetings, as well as the “DNSSEC for Everybody” and “DNSSEC Impelementer’s Gathering” on Monday.

However, at ICANN 51 there will be three other activities:

Due to some schedule conflicts I will be unfortunately missing the DNS-OARC meetings but I’ll be out there on Monday afternoon and look forward to seeing many of you there!

To walk through the activities, let me break it down day by day.

Saturday and Sunday, October 11-12

DNS-OARC will be holding its 2014 Fall Workshop and Annual General Meeting this weekend.  Saturday the 11th is primarily focused on organizational matters but on Sunday the 12th the group gets into detailed technical discussions.  Some of the sessions that may be of interest to Deploy360 readers include:

  • Measuring the cost of DNSSEC
  • Improved NSEC3 performance in DNSSEC
  • NSEC5: Provably Preventing DNSSEC Zone Enumeration
  • A Survey of Current DANE/TLSA Deployment

Many of the other sessions look quite fascinating as well (to a “DNS geek” such as myself!). Per the Overview page, you can participate remotely using these means:

Monday, October 13

10:30 – 17:00 PDT – Tech Day (combined ccNSO/DNS-OARC)

On every Monday of an ICANN week the ccNSO (for country-code top-level domains (ccTLDs)) holds a “Tech Day” full of technical presentations on a wide range of topics. For ICANN 51 they have combined with DNS-OARC and the result is an excellent session full of DNS and DNSSEC talks.  Remote participation info is available at:

http://la51.icann.org/en/schedule/mon-tech

although the actual agenda is on the DNS-OARC site.  Some of the sessions that may be of interest to Deploy360 readers include:

  • DNSViz – powerful and extensible DNS analysis
  • Low-Cost Threshold Cryptography HSM for OpenDNSSEC
  • DNS Bake-off

This last “bake-off” session I mention is one in which the different vendors/organizations behind various DNS servers all get up in front of the room and talk about what is new or different in their latest software. When this panel has happened before at Tech Day it’s been a great way to learn what is new with the different DNS software implementations.

A number of other sessions will probably be quite interesting and the opening keynote at 11:00 by Paul Mockapetris should be quite educational as well.

17:00 – 18:30 PDT – DNSSEC for Everybody: A Beginner’s Guide

In this session we’ll once again go back to the caveman days and talk about blue smoke in a light-hearted session aimed at helping people understand DNSSEC.  We’ll also do our “skit” acting out DNS and DNSSEC again… and typically answer a great number of questions from people.  You can participate remotely and view the handout at:

http://la51.icann.org/en/schedule/mon-dnssec-everybody

19:30 – 21:30 (or later) PDT – DNSSEC Implementers Gathering

After that session is over there will be a smaller informal gathering at a nearby restaurant where people who are actually involved in deploying DNSSEC and/or creating the tools to deploy DNSSEC will gather together for food, drinks and conversation to explore what more can be done to accelerate DNSSEC deployment. These sessions have created strong connections and usually generated new projects and ideas for further work.

Alas, there is no way that anyone can participate remotely. :-)  We would like to thank Comcast, NBC Universal and the MPAA for providing sponsorship money so that we could hold this gathering and make it accessible to all who will attend.  (Attendance has now been closed due to space limitations.)

Wednesday, October 15

08:30 – 14:45 PDT – DNSSEC Workshop

This is the BIG session of the week related to all things about DNSSEC and DANE.  The full agenda, slides and remote participation information can be found at:

http://la51.icann.org/en/schedule/wed-dnssec

(Slides and detailed agenda are not online yet but should be soon.)

The bulk of the session includes 5 panels for which we have assembled an excellent collection of speakers:

  • DNSSEC Activities in North America
  • Impact of Root Key Rollover
  • DNSSEC Deployment in Operating Systems
  • DNS/DNSSEC Monitoring
  • DANE and Email Services

Additionally I’ll be providing some DNSSEC deployment statistics and the beginning and wrapping it up with a “How You Can Help” session at the end.

These DNSSEC Workshop sessions bring together an outstanding group of technical people involved with DNS and DNSSEC and are well worth attending either in person or remotely.

09:00 – ? – Root KSK Rollover Interoperability Testing

At the same time as the public DNSSEC Workshop is taking place, there will be a private meeting of service providers, vendors, application developers and others who will be focused on performing some actual interoperability testing to determine what exactly will be some of the technical issues when we as a community roll (or change) the “Root Key Signing Key (KSK)” that is at the top of the global “chain of trust” in DNSSEC.

This closed interop workshop will then lead to…

Thursday, October 16

09:00 – 12:00 DNSSEC Key Rollover Workshop

ICANN Chief Technology Officer (CTO) David Conrad is organizing a public discussion about issues related to changing the Root KSK.  This will be a chance to publicly discuss what we collectively see as potential issues when the Root KSK is rolled or changed and what we need to do about those issues.  This is a critically important topic and so it is great to see ICANN holding this session.  Information about how to participate remotely can be found at:

http://la51.icann.org/en/schedule/thu-dnssec-key-rollover

(Note: the times on that page have not yet been updated.  The workshop will only be from 09:00-12:00.)

I would expect some of the discussion will involve the results of the interop testing happening on Wednesday but the intent is to have it be a wider discussion during this workshop.  If you are interested in this topic, you can join ICANN’s “ksk-rollover” mailing list and read the archives.

It is also worth noting that ICANN’s Security and Stability Advisory Committee (SSAC) will hold its public meeting from 08:00 – 09:00 immediately prior to this workshop.  The SSAC public meetings usually include topics of interest to those of us working with DNSSEC and “DNS security” in general.


And… after all of that we’ll all make our journeys home rather exhausted from so much conversation about DNSSEC! :-)

Seriously, though, it will be an excellent week full of DNSSEC and DANE conversations.  If you are out at ICANN 51 please do find me at one of the events and say hello, or drop me an email message and we can arrange a time to connect.  You will of course find info on our Deploy360 social media channels during the events next week.

And if you want to get started NOW with deploying DNSSEC, why not visit our Start Here page to find resources tailored for your type of organization?

See (some of) you in L.A.!

Join The Monthly “DNSSEC Coordination” Calls To Help Advance DNSSEC

If you are interested in helping advance the deployment of DNSSEC, there are a group of us that gather in a conference call on the first Thursday of each month to exchange information, share ideas and develop plans to accelerate more usage and deployment of DNSSEC.  This is a group focused more on the advocacy and promotion of DNSSEC and DANE, rather than focused on technical deployment issues. (There are other email lists and groups for that.)  It is not a formal group but just a group of people interested in coordinating our activities so that we can we can learn from each other and work together to make thing happen quicker.

These “DNSSEC coordination” calls are hosted by the Internet Society and open to anyone interested in helping.  Please simply join the “dnssec-coord” mailing list to be connected to others and learn about the upcoming calls and events.

P.S. While you are at it, you may want to join in to some of the other lists and forums that make up the “DNSSEC community”.

Watch LIVE Today – INET Trinidad and Tobago – IPv6, DNSSEC, More

INET Trinidad and TobagoAs we mentioned earlier this week,  the INET Trinidad and Tobago event starts TODAY bringing great Internet infrastructure information to the Caribbean region. Some of the presentations today covering IPv6 and DNSSEC include:

  • IPv6: What Is It? Why Is It Needed?
  • IPv6 Deployment: Business Cases and Development Options (in the Caribbean)
  • Securing the DNS and Internet Routes

The event continues tomorrow, Thursday, October 9, with a range of sessions related to Internet Exchange Points (IXPs), cybersecurity and trends in the overall industry.

You can watch the event live at:

http://new.livestream.com/internetsociety/inet-trinidad-and-tobago

The agenda can be found at:

http://www.internetsociety.org/events/inet-trinidad-and-tobago

Note that Trinidad and Tobago use Atlantic Standard Time (AST) which is UTC-4 and right now the same as US Eastern Daylight Time.

Our colleague Shernon Osepa has more information about the INET Trinidid and Tobago event in a post on our Internet Technology Matters (ITM) blog earlier this week.

CloudFlare Publishes Excellent Introduction To DNSSEC

CloudFlare logoThe team over at CloudFlare published an excellent introduction to DNSSEC today that is well worth a read.  CloudFlare has developed a reputation for writing blog posts that provide a solid level of technical depth and this one certainly does.  Nick Sullivan starts by walking through the basics of DNS and including some packet captures and nice illustrations. Then he gets into man-in-the-middle (MITM) attacks and provides a great graphic that very succinctly shows a MITM attack against DNS:

CloudFlare MITM example

Even better, Sullivan nicely explains the “Kaminsky Attack” and the situation that makes the attack possible.    He then plunges into DNSSEC, explains RRsets and RRSIGs, ZSKs and KSKs, and touches on the value of NSEC/NSEC3 to prove that records don’t exist.

All in all it is an excellent introduction and we’re very pleased to see CloudFlare publishing this piece.  Thanks to Nick Sullivan and his team for getting this out there!

As we’ve written about before, CloudFlare has been saying since the ICANN 50 DNSSEC Workshop back in July that they would have DNSSEC available for their customers by the end of 2014.  Their post today says “in the next six months”… but we’ll hope it comes in on the sooner side of that. :-)  It was also great to see the official announcement that CloudFlare has hired Olafur Gudmundsson, one of the developers of the first DNSSEC implementation many, many years ago and currently one of the co-chairs of the DANE Working Group within the IETF.  We’ve been working with Olafur over the past few years through our partnership with Shinkuro, Inc., where he worked before, and we’re delighted that he’s now working on DNSSEC at CloudFlare.

All great to see – and this will only help get DNSSEC much more widely deployed!

If you want to get started with DNSSEC today, please visit our Start Here page to find resources targeted at your role or type of organization. Help us make the Internet more secure today!

Simple DNSSEC Fact Sheet Now Available In English, French and Spanish

DNSSEC Fact SheetHave you ever wished that there was a simple “2-page” document that you could give people explaining DNSSEC and what it is all about?  Would you like a DNSSEC “handout” that you can distribute at events or send to colleagues or vendors?

If so, we’ve now added a “DNSSEC Fact Sheet” to our site in the following languages:

We’ll be adding versions in Arabic,  Chinese and Russian soon.

Please feel free to download these and use them in whatever way you wish.  Email them to people.  Print them out and pass them out at a meeting.  Distribute them on a conference USB drive… do whatever you want with them!

Because we may update the fact sheets from time to time, we would encourage you to direct people to this simple URL to find the fact sheets:

http://www.internetsociety.org/deploy360/dnssec/factsheet/

And please let us know any feedback you have on these documents.  We’re here to help you get DNSSEC more widely deployed and want to be as helpful as possible.  How can we help you get the information you need?

Finally, please do direct people to our Start Here page at https://www.internetsociety.org/deploy360/start/ so that they can find DNSSEC resources targeted at their role or type of organization.

P.S. You can expect to see a fact sheet for IPv6 coming soon…

Chris Grundemann At NANOG62 This Week Talking BCOP

NANOG 62 LogoAre you at NANOG 62 in Baltimore, MD, this week?  If so, look for our Chris Grundemann (see team photo) who is there all week.

Chris is primarily at NANOG for the Best Current Operational Practices (BCOP) Track happening today from 4:30 to 6:00pm US EDT in the “Maryland Suites” room.   Chris was very active with this BCOP work in NANOG before joining the Internet Society and remains closely connected to what is going on.  As we’ve written about in the past, our team here is working to help facilitate the creation of regional BCOP documentation efforts around the globe and a good bit of what Chris expects to be doing at NANOG 62 is speaking with operators about what other BCOP documents could be written.

He’ll also be speaking with people about all the work we’re doing here to promote IPv6, DNSSEC, TLS and technologies to secure BGP.  If you’d like to meet up with him, please drop an email to deploy360@isoc.org and he can connect with you there at the show.

Beyond the BCOP session today, which is unfortunately not being webcast, there is an outstanding agenda of presentations this week, many of which will be webcast / live streamed for remote viewing.  Some of the sessions that hit the topics we cover here at Deploy360 include (slides are available for sessions that are already over, and the video recordings should be available soon):

Monday, October 6, 2014

  • Detecting and Quantifying IPv6-based SMTP Abuse
  • Project Turris  (an IPv6-capable and DNSSEC-validating home gateway/router from CZ.Nic)
  • Single Pass Load Balancing with Session Persistence in IPv6 Network

Tuesday, October 7, 2014

  • DNS Track (unfortunately not webcast)

Wednesday, October 8, 2014

  • Adventures in RPKI (non)Deployment

There are a great range of other talks on the NANOG 62 agenda that may be of interest, too.  I’m personally interested in the talk on Thursday (right before the RPKI talk) from Tim Stronge at TeleGeography about submarine cables as I just find that whole area intriguing.

All in all it should be a great event – and if you want to learn more about what we are doing and want to provide some feedback about what you could use help with to get started with IPv6, DNSSEC and other technologies, please do find Chris and say hello!

INET Trinidad and Tobago To Cover IPv6, DNSSEC, IXPs and more

INET Trinidad and TobagoThis Wednesday and Thursday the INET Trinidad and Tobago event will bring a great amount of technical presentations to the Caribbean region. Starting on October 8, 2014, some of the presentations covering IPv6 and DNSSEC include:

  • IPv6: What Is It? Why Is It Needed?
  • IPv6 Deployment: Business Cases and Development Options (in the Caribbean)
  • Securing the DNS and Internet Routes

The event continues on Thursday, October 9, with a range of sessions related to Internet Exchange Points (IXPs), cybersecurity and trends in the overall industry.  It looks like a great event and the excellent news is that you can watch it all live at:

http://new.livestream.com/internetsociety/inet-trinidad-and-tobago

Note that Trinidad and Tobago use Atlantic Standard Time (AST) which is UTC-4 and right now the same as US Eastern Daylight Time.

Our colleague Shernon Osepa has more information about the INET Trinidid and Tobago event in a post on our Internet Technology Matters (ITM) blog earlier today.

FIR #776 – 10/06/14 – For Immediate Release

Shel traveling through November 1 but the show will go on; Quick News: Facebook addresses real names and experiments, Windows 10 technical preview released, employees with friends at work are more committed to their employers, Dubai detectives get Google Glass to fight crime; Ragan promo; News That Fits: implications of wearable tech on the workplace, Dan York's Tech Report, it's time to take Snapchat seriously, Media Monitoring Minute from CustomScoop, listener comments, Igloo Software promo, brace yourself for the corporate journalism wave, the last week on the FIR Podcast Network; music from Tasherra Project; and more.

Reflections On Ello – October 5, 2014

Ello logo 180 pixelsAs people who follow me on Ello know, I've been experimenting a good bit with the platform. In order to capture some thoughts for own recollection (and also for the FIR report I need to record this morning), here are some quick thoughts and links about Ello that reflect what I've learned over the past few weeks.

First, as I wrote, we have to remember that Ello is not Facebook, Twitter, Google+, etc., and we have to just go in with an open mind.

The Ello platform is very definitely still a "beta" with a long list of features that they want to add, but over the past bit there have been some changes of interest:

I love the display of photos in Ello, but there's one bit of brokenness that does bother me:

I asked the question of why should Ello have to have a mobile app and wondered about how Ello behaved different from other apps... and I learned a bit more about why (and what you can do)

Clay Shirky had two great posts about Ello being a conversational versus annotative medium:

He also had two other good articles and threads:

Oh, and there's now a parody social network... Owdy! :-)

Please do join me on Ello if you are interested in the continuing experiments... and please feel free to share your own tips and insights!


If you found this post interesting or useful, please consider either:


Join Me On VUC Today At Noon US EDT To Talk IPv6, IoT, WebRTC and more…

Today at 12 noon US Eastern (in about 3.5 hours), I'll be part of a panel on the VoIP Users Conference (VUC) talking about IPv6, WebRTC, the Internet of Things (IoT) and much, much more... you should be able to watch it live at live.vuc.me or embedded here:

VUC host Randy Resnick had a scheduled guest be unable to attend and so he asked a group of us to come on for what he is calling a "VUC Vision" session. I will be on there, as will, I believe, Tim Panton and a number of others. I expect the discussion should range over good variety of topics. It should be a good time... you're welcome to join in the discussion.

It's probably best to also join the IRC backchannel where links are shared, questions are answered and other comments occur. You also can visit the Google+ event page for the VUC session today where there may be additional links and info.

If you won't be at your computer, you can also call in via:

  • sip:200901@login.zipdx.com
  • +1 (646) 475-2098
  • Skype:vuc.me

The session will of course be recorded so you can listen/watch later.

Vuc vision 20141003


If you found this post interesting or useful, please consider either: