Just a guy in Vermont trying to connect all the dots...
Author's posts
Feb 03
CircleID: Thinking Strategically About the Benefits of IPv6
I love it when my Monday morning begins by seeing posts like this one: Thinking Strategically About The Benefits of IPv6 by Mukom Akong Tamon. Please go over there and read that piece. He’s absolutely right that we need to be thinking about IPv6 beyond simply the fact that IPv4 addresses are on their way to being exhausted. I love his conclusion (my emphasis added):
One of these types of organisation will lead the provision of devices, software and services for tomorrow’s Internet, the other type will lose relevance and then will play catch up. Just remember this: The day you see concrete data to show the benefits of IPv6, it means you are already late to the game, that data will be coming from an early mover who is already making a ‘killing’ with IPv6.
Also, check out this great comment on the post (over on Mukom Tamon’s own site) that begins with:
It is in fact, the mobile arena that will deploy IPv6, we as a small company have already migrated to IPv6 and see huge benefits…
Great to see people relaying that they are already seeing the benefits of making the move to IPv6! (And yes, I think I may try to contact them to find out more about their situation.)
What are you waiting for? Are you going to be a leader in your field and seize any opportunities that are made possible with IPv6? Or are you going to wait until the last possible moment?
Feb 03
FIR #741 – 2/3/14 – For Immediate Release
Feb 02
TDYR #088 – Kudos To The NFL And Fox Sports For Streaming The Super Bowl Live To Cord-cutters
Feb 02
Slides: Case Study Of An IPv6 Addressing Plan (RIPE67)
How do you best plan how to allocate IPv6 addresses across your network? In addition to the resources we already link to on our IPv6 Address Planning page, this case study presented back at RIPE 67 in October also provided a nice graphical illustration of one way in which you could allocate IPv6 addresses:
The answer of course comes down to “it depends” upon the configuration and situation of your specific network environment. Cases studies like this one, though, help provide yet another view of how you can set up IPv6 on your network.
What about you? What is stopping you from deploying IPv6 today?
Feb 01
TDYR #087 – How Far Are We Willing To Go To Help Those In Need?
Feb 01
Weekend Project: Install The DNSSEC/TLSA Validator for Chrome, Firefox, more
How do you know if a website has a domain signed by DNSSEC? Here’s another quick weekend project, very similar to last weekend’s project , where you can add support to your web browsers to know the DNSSEC status of sites you are visiting. Even better, as people start to use the DANE protocol to secure TLS/SSL certificates, you’ll be able to know when DANE is being use.
The great team at CZ.NIC Labs has released a new version 2.1 of their plugin for Google Chrome, Mozilla Firefox, Microsoft Internet Explorer and Opera. You can get it at:
https://www.dnssec-validator.cz/
A key difference in this version from previous versions is that it now has support for the TLSA record in DNS that is used by the DANE protocol to add an extra layer of trust to the usage of TLS/SSL certificates.
Once you have the DNSSEC/TLSA validator installed in your browser, you should be able to go to links on these pages to test out your new capabilities:
When you visit the sites, you should see additional icons in your browser’s address bar that will give you information such as this:
The addition of TLSA record support is a great new feature! While TLSA record usage is still quite small among web sites today, having this ability to see the TLSA usage will definitely help the people out there who are pioneering the usage.
Kudos to the CZ.NIC team for making this available!
P.S. Do note that in order for this to work in your web browser needs to have access to a DNSSEC-validating DNS resolver. [UPDATE: As noted in the comments to this post, the add-on no longer requires access to a DNSSEC-validating DNS resolver. The required capabilities were built into the code instead. Having said that, it's still also great to make sure your local DNS resolver does do DNSSEC validation for all the other apps you have.] The add-on can use DNSSEC-validating DNS resolvers from CZ.NIC or Google, buy why not make your network that much more secure and install your own DNSSEC-validating resolvers? Check out our recent weekend project to learn more about how to configure DNSSEC validation on your local DNS resolver.
Jan 31
TDYR #086 – A Special Thank You To Lynn St. Amour
Jan 31
First “Middle East DNS Forum” Happening Feb 3-4 in Dubai – Live Video Stream Available (Featured Blog)
Jan 31
Video – ENOG6: DNSSEC and DANE Deployment Trends, Tools And Challenges
What are DNSSEC and DANE all about? What advantages do they have? What tools are out there to help? Back in October I spoke at the ENOG 6 event in Kiev, Ukraine, about DNSSEC deployment trends and also the opportunities with the DANE protocol to build an additional secure layer of trust in TLS/SSL certificates. The video is available for viewing and the slides are also available online:
It was a great session and I had a good number of questions from people in the room. Now.. the question is… how can we help YOU deploy DNSSEC?


