Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

Knot DNS

Knot DNSKnot DNS is an authoritative DNS name server that can be used to serve out zone records and includes support for DNSSEC and DANE.  One of the key design goals is to provide simple DNSSEC support for dynamic DNS.  Knot DNS is developed by the team at CZ.NIC and can be found at:

https://www.knot-dns.cz/

It is available pre-packaged for several versions of Linux and also as source code as a release or directly from a git repository.

Knot DNS is highly scalable and used by CZ.NIC for the operation of the .CZ TLD. It was developed with the target audience of network operators and DNS operators in mind but can be used by anyone needing to serve out DNS records.

For an overview of Knot DNS, you can view this short video interview with Jaromir Talir of CZ.NIC:

Prior to this interview, Jaromir had spoken on stage at ENOG 6 in Kiev, Ukrain, in more detail about Knot DNS. His ENOG 6 slides about Knot DNS are online and a video recording of his presentation is available:

4 Sessions About Routing Resiliency/Security At IETF 88 Next Week

IETF LogoNext week at IETF 88 in Vancouver the topic of routing resiliency/security will be covered in a variety of different working groups.  Our colleague Andrei Robachevsky outlined what will be covered in a post on the “Internet Technology Matters (ITM)” blog: Rough Guide to IETF 88: Routing Resilience.   We’re looking forward to those sessions and you can expect to find me in most of them.  My particular interest is in what is happening within SIDR right now, but in truth all of them should be interesting.

I’d strongly suggest reading Andrei’s post to understand what’s going to be going on with routing.  Here are the relevant working groups and times.

NOTE: If you are not going to be in Vancouver next week, there are multiple ways that you can participate remotely in these working groups, including audio streams and Jabber chat rooms.

Finally! Google+ Starts Rolling Out Custom URLs To Regular Users

Dan York About Google 2Finally! We can now get "custom URLs" for our Google+ accounts! As of this morning you can now find me at the nice and easy URL of:
https://plus.google.com/+DanYork/
One of the supreme annoyances of using Google+ has been the horribly ugly long URLs you have had to use for your profile. You couldn't give people an easy URL to find you on the service and there was no way that normal people would realistically remember the long numbers. Google rolled out "custom URL" support for some brands and celebrities earlier but all of us "regular users" were left with the ugly URLs.

That changed yesterday and was noted with a post on Google+, "Expanding the availability of custom URLs". Tipped off to the change by Neville Hobson's post on G+, I went into my Google+ profile and nicely found this message waiting for me at the top of the page

Google custom url 2

I was delighted to see that "+DanYork" was being offered to me and so I clicked the "Get URL" button to see this screen:

Google get custom url 2

One more click brought me to a confirmation screen nothing that I can't change the URL or transfer it to anyone else:

Google custom url confirm 2

And that was it! My Google+ profile now is at https://plus.google.com/+DanYork/.

Very cool to see and this will definitely make it so much easier to refer people to my profile on the service (and therefore will make it much easier for people to find me and use Google+).

Now, what I really want is this kind of custom URL for my Google+ Pages, and I'm seeing from comments on G+ that some people have this for their pages already. The post from Google says the criteria for custom URLs will be:

If your profile meets the following criteria, you’ll now be able to claim a custom URL:
- Has a profile photo, and
- Has at least 10 followers, and
- Has an account that's at least 30 days old

Meanwhile, any brand or business that has a linked website or is a verified local business can claim a custom URL for their Google+ page.

I do have linked websites for some of my Google+ Pages ... but I'm not yet seeing the option to get a custom URL. As Google indicates, this feature is being rolled out this week, so hopefully I'll see it soon.

I've been using Google+ a great amount these days, and so I'm thrilled to see this new feature that will make it much easier to find people and to refer people to my profile and content.

What about you? Have you been offered a custom URL on Google+ yet? Have you claimed it?


If you found this post interesting or useful, please consider either:


Linphone On iOS Now Supports The Opus Codec

Linphone opus 2When updating my iPhone this week, I was extremely pleased to see the message in the attached screenshot that Linphone now supports the Opus audio codec. Somewhat strangely, I don't see any mention of this Opus support (or even the 2.1 release for iOS) on the Linphone news page or even on the Linphone features page, but the mention of a "Linphone Web" release does also mention Opus, so I'll assume this is real.

I've written before about why the Opus code is so incredibly important if we want to truly deliver a richer and better communications experience than we've had with the traditional PSTN and so it is great to see this support coming in to Linphone. Linphone is certainly not the first SIP softphone to support Opus - there are a number of others out there, including Jitsi and Counterpath's Bria (and X-Lite) - but it's definitely great to see another softphone added to the mix. Hopefully we'll also see this Opus support move to the desktop versions of Linphone (for Windows, OS X and Linux) as well.

Congrats to the Linphone team on making this happen!

P.S. Linphone also supports IPv6, ensuring that it will continue to work on all future networks.

Related Posts


If you found this post interesting or useful, please consider either:


Video: Requirements for IPv6 in ICT Equipment — a tale of RIPE-554 (PLNOG 11)

What is the story behind the creation of the RIPE-554 document specifying IPv6 requirements for Information and Communication Technology (ICT) equipment? At the recent PLNOG 11 event (where we also ran our ION Krakow event), our own Jan Zorz and Sander Steffann spoke about how RIPE-554 came to be and what the next steps are:

TDYR #044 – A Crazy Busy Week Preparing For IETF 88 In Vancouver (Next Week)

This week will be a crazy one for me getting ready for the IETF 88 meeting happening next week in Vancouver. Some of the links I mention are: Intro to the IETF video: https://www.youtube.com/watch?v=Fpuzl9lvOSM IETF 88 page: http://www.ietf.org/meeting/88/index.html IETF on Google+: https://plus.google.com/115114278816279309050/posts IETF on Facebook: http://www.facebook.com/ietf.org

FIR #727 – 10/28/13 – For Immediate Release

FIR On Strategy 5 is up; listener survey early results; Neville saw Byan Person and missed Michael Netzley; upcoming Scoble-Israel appearances; Quick News: the role of news on Facebook, Ryanair looks serious about customer service, native advertising gets regulator attention, Twitter keeps IPO communications in-house; Ragan promo; News That Fits: Knight Frank pays price of ignoring social web, the power of the logo, Media Monitoring Minute from CustomScoop, the decline of Wikipedia, Dan York's report, everyone is ignoring mobile messaging apps; music from Night's Bright Colors; and more.

TDYR #043 – IPv6: The Coolest Part Of My Switch To An iPhone On Verizon Wireless

I recently made the switch from AT&T to Verizon Wireless and in doing so the very first website I visited over Verizon's LTE network was... http://www.test-ipv6.com :-) I was thrilled with the results and very happy to have a smartphone that works natively over IPv6. (For more on why this is important, see http://www.internetsociety.org/deploy360/ipv6/ )

Watch LIVE at 1:00pm US EDT today – ICANN’s DNSSEC Key Signing Ceremony XV

icann-at-15-logoIn about 15 minutes, at 1:00pm US EDT, you can watch live as members of the DNS/DNSSSEC community engage in a “Key Signing Ceremony” that will result in the generation of new keys used for managing DNSSEC at the root of the Domain Name System (DNS).  The live stream will be at:

http://dns.icann.org/ksk/stream/

The schedule, list of attendees and other information can be found at:

http://dns.icann.org/ksk/upcoming-ceremonies/cer15/

The ceremony begins at 1:00pm and is scheduled to end at 4:00pm US EDT. The script that is being followed during the ceremony is available at:

http://data.iana.org/ksk-ceremony/15/KC15_Scripts.pdf

These documents may also be helpful in understanding what happens:

Essentially what is going on is the creation and signing of new “zone-signing keys (ZSKs)” that are being signed by ICANN’s “key-signing key (KSK)” and then deployed by the ZSK operator.

As you will see if you watch, there is a very specific process that is used to ensure the integrity and security of the key signing process.  It is all documented and then archived so that there is full transparency about what goes on.

If you are interested in understanding how DNSSEC works at an operational level, you may find watching today quite informative. If you are unable to watch the stream live, it will be recorded and made available from the archive link for this 15th key signing ceremony.  (And as these key signing ceremonies happen quarterly, the next will be along in just a few months.)

4 NewgTLDs Launched Yesterday Marks Dawn of “DNSSEC From The Start” TLDs

dnssecYesterday was a big day for the Domain Name System (DNS). After a long process, ICANN formally delegated the first four of the “new generic top-level domains (newgTLDs)”, marking the beginning of the largest expansion of the domain name space ever. In addition to the existing “generic TLDs” like .com, .org, .net, etc., and the existing “country code TLDs (ccTLDs)” like .nl, .cz, .tv, etc., over the months and years ahead there are some 1,400 newgTLDs that are expected to be launched.

These first four newgTLDs are interestingly not English-language names like “.shop” or “.bank”, but instead what are called “Internationalized Domain Names (IDNs)” in non-Latin alphabets:

  • شبكة (xn--ngbc5azd) – Arabic for “web/network”
  • онлайн (xn--80asehdb) – Cyrillic for “online”
  • сайт (xn--80aswg) – Cyrillic for “site”
  • 游戏(xn--unup4y) – Chinese for “game(s)”

Yesterday’s “delegation” means that these TLDs now appear in the root zone of the DNS and the registries who operate these TLDs can now begin the process of selling domain names underneath these TLDs.  There is a formal process the registries have to go through to get started, but soon we should see these TLDs available as options for registration at the registrars who are supporting these TLDs.

Now, the exciting aspect of this news from a Deploy360 point of view is simply this:

All of these newgTLDs MUST be signed with and use DNSSEC!

From the very beginning of their operation these newgTLDs are already starting out with more security enabled than many of the existing country-code TLDs (ccTLDs).  If you look at ICANN’s “TLD DNSSEC Report” you can see that pretty much all of the existing major “generic TLDs” (ex. .com, .org, .net, .edu) are signed with DNSSEC.  Similarly over 100 of the existing ccTLDs are signed with DNSSEC.  These four newgTLDs can also be found in that report, with a nice green bar showing that they are all signed with DNSSEC.

The key point here is that these new registries must:

1. Keep the TLD signed with DNSSEC from an operational point of view.
2. Accept DNSSEC records (DS/DNSKEY) from registrars (or domain registrants depending upon the business model).

One important point:

Support of DNSSEC by a newgTLD does NOT mean that ALL domains registered under the newgTLD will be secured with DNSSEC!

But it means that all domain names registered under the newgTLD CAN be secured with DNSSEC – and that is a great step forward!

Furthermore, the new ICANN Registrar Accreditation Agreement (RAA) will require all “ICANN-accredited registrars” to support the passing of DNSSEC records from a domain name registrant up to the TLD registry. This means we should be seeing a great amount more of DNSSEC support from within the registrars.  Hopefully the DNS operators (which are sometimes part of registrars) will follow with making it easy for domain name holders to sign their domains.

All in all this newgTLD launch is great news for those of us looking at add more security to the Internet through the use of DNSSEC.  From here on out all the newgTLDs will be launched with DNSSEC – and hopefully this will also put some competitive pressure on the lagging ccTLDs (and a few lagging gTLDs) to join the rest of the TLDs that have already signed their domains.

And in the end, we’ll have a more secure Internet protecting users from attackers and also enabling new an innovative forms of security such as DANE’s protection of SSL/TLS certificates.

Congratulations to all the teams at these four registries (and their operators) and also at ICANN on this launch of the first new – and secure – gTLDs!

P.S. Want to understand DNSSEC and how (or why?) you can get started?  Check out our DNSSEC Basics page…