Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

DNSSEC Presentations Coming Up at ICANN46 in Beijing

ICANN 46 logoNext week at the ICANN 46 meetings in Beijing, China, there will be a series of DNSSEC-related workshops. I (Dan York) will be there at ICANN 46 and will be participating in these sessions. If you are able to attend in person, the events will be an excellent way to learn more about DNSSEC.

NOTE: Remote participation IS possible. See the links below to listen to the live streams.


The major DNSSEC-related meetings are on Monday, April 8, 2013, and Wednesday, April 10, 2013. They are:

DNSSEC for Everybody – A Beginner’s Guide

Monday, 8 April 2013 – 5pm-6:30pm, Auditorium – http://beijing46.icann.org/node/37065

This very basic introductory session is aimed to help attendees understand more about how DNSSEC can secure the Domain Name System and make the Internet more secure. As DNSSEC gets more widely deployed it is critical to understand how DNSSEC works. This session provides an interactive and fun way to learn how DNSSEC works, what tools are available to help and what best practices are currently being used.

DNSSEC Workshop

Wednesday, 10 April 2013, 8:30am-2:45pm, Rainbow – http://beijing46.icann.org/node/37125

This 6+ hour workshop brings together industry leaders on DNSSEC for a series of panel discussions about the state of the art in implementing DNSSEC, current best practices, government regulations and operational practices. Sessions also include talks about the latest and innovative uses of DNSSEC. Panels at ICANN 46 include:

  • Introduction and DNSSEC Deployment Around The World
  • DNSSEC: Regulative, Legislative and Persuasive Approaches to Encouraging Deployment
  • DNSSEC Deployment in Asia Pacific
  • Use of DNSSEC in the Reverse Name Space
  • The Operational Realities of DNSSEC
  • DNSSEC Innovation: DANE and Other DNSSEC Applications
  • Root Key Rollover

There will be case studies and reports on some of the latest tools. Of interest to many may be the talk from someone at CNNIC about China’s plans for deploying DNSSEC and signing .CN.  I’ll be moderating the panel on “DNSSEC Innovation” as well as providing a brief tutorial about the DANE protocol and how it helps.  Several of the other panelists will also be talking about DANE so it should be a good session.

I’ve attended several of these workshops now and have been very impressed by the quality of the sessions in terms of technical content.  If you’re at all interested in DNSSEC, I really can’t recommend the event strongly enough.  In full disclosure, I joined the Program Committee for this ICANN 46 workshop, so I’m a wee bit biased… but it also means I’ve seen many of the proposals as well as the completed slide decks – and I can say that there will be some excellent sessions there.


On Monday evening, there will also be an informal gathering of people involved with implementing DNSSEC to discuss and exchange information about DNSSEC implementations.  As noted in the email announcement, you need to RSVP by Thursday, April 4, as it is being held at a local restaurant and a count of attendees is needed.

In looking over the ICANN 46 schedule, another meeting I will probably attend is the “Joint DNS Security and Stability Analysis Working Group (DSSA)” on Thursday, April 11, 2013.  While it is not specifically about DNSSEC, it relates to “DNS security” in general and I would think it should be a rather interesting session given the recent DDoS attacks going on that are using DNS amplification.

If you are going to be at ICANN 46 and would like to meet with me to talk about DNSSEC, IPv6, routing resiliency or just Deploy360 in general, please feel free to drop me a note or find me in one of these sessions mentioned here.


You can also listen to an audio version of this post at:

FIR #697 – 4/1/13 – For Immediate Release

Rubel interview and London content marketing panel Speakers and Speeches coming; FIR Book Club with Andrea Weckerle on Friday; Quick News: how Google empowers employees, Google wants native ads out of Google News, BBC survey shows evolving news consumption habits, language of social media permeates advertising; Ragan promo; News That Fits: Flipboard self-published mini magazines could be disruptive, Ford crisis management stops a kerfuffle started by its India ad agency, Dan York and Michael Netzley's joint report, listener comments, how social media can benefit CEOs in their first hundred days, Kred introduces Kred for Brands; music from Harmony and Groove; and more.

Jumper Cables And The Absolutely Awesome Kindness Of Total Strangers

Jumper Cables And The Absolutely Awesome Kindness Of Total Strangers by Dan York

Comcast Publishing Domains Failing DNSSEC Via Twitter

Comcast DNS Twitter accountHow do you know when a domain is failing DNSSEC validation? What if there was a way to let the broader industry know about these validation failures?  The folks over at Comcast’s DNS team have been trying an experiment for a while in posting these DNSSEC validation failures publicly to Twitter at:

https://twitter.com/comcastdns

If you are a system/network operator deploying DNSSEC and want to be alerted when sites are found to be failing validation, following this Twitter account is one way you can get alerts.

I don’t know whether publishing domains failing DNSSEC validation via Twitter will really be a long-term solution to letting the wider industry know about domains that are currently failing validation, but I applaud Comcast’s DNS team for trying something different … and I do follow the account myself because I find the occasional tweets interesting to see.

Reflections About Singapore Before Leaving

Some thoughts on Singapore as I wrap up my 48 hours in the country and get ready to fly back to the USA. I talk about my trip and the activities. Separately, I recorded some thoughts about the ION Singapore conference that I was here to speak at over in the Deploy360 SoundCloud account at: https://soundcloud.com/deploy360/deploy360-ion-singapore-draws

IPSO Challenge 2013 Offers $10K To Winner With Best New Internet of Things Idea/Product

IPSO AllianceLooking for an interesting new weekend project?  Are you interested in devices for the “connected home” or the “Internet of Things?”  Have you been automating your home or building sensor networks?  Do you like experimenting with hardware platforms like Arduino or the Raspberry Pi?

Would you like to potentially win $10,000 USD?

If so, check out the IPSO Alliance’s “IPSO Challenge 2013” where the About page explains the challenge:

The IPSO (Internet Protocol for Smart Objects) Alliance is sponsoring a worldwide challenge to showcase the use of the Internet Protocol (IP) in sensor/control and M2M applications enabling the Internet of Things (IOT). IPSO Challenge 2013 is a competition promoting the development of Smart Objects which use the Internet Protocol. Just 30 years after the official adoption of the TCP/IP networking protocol, nearly 10 billion devices can connect to the Internet; and before the end of the decade, that number is forecast to nearly triple. Over the coming years, the vast majority of newly connected devices won’t be computers, tablets, or smartphones, but will be intelligent embedded devices participating in the Internet of Things (IoT).

The deadline to submit a written proposal is coming up soon on APRIL 5, 2013, using the submission form at the bottom of the main IPSO Challenge 2013 page. Semi-finalists will be notified soon thereafter and will need to submit a functional prototype by May 17, 2013.  Ultimately winners will be chosen who will receive $10,000,  $5,000 and $2,500.  More details about what you need to do can be found on the About page for the contest.

Why are we writing about this contest here on Deploy360?  Simple.  The reality is that to get the massive scale being considered for the “Internet of Things” many implementations will need to use IPv6.

We were in contact with the people behind this IPSO Challenge 2013 and they are very definitely interested in receiving IPv6 entries.

So we’d like to encourage any of you developers out there to submit some IPv6 proposals!  It would be great if some of the semi-finalists or finalists were entries working over IPv6.

So… if you like working with these kind of projects, do check out the IPSO Challenge site and submit your ideas!

Video Interview: Emil Ivov about how the Jitsi softphone works with IPv6 and DNSSEC

How does the Jitsi softphone work with IPv6? And what role could DNSSEC play with VoIP? At IETF86 earlier this month, I sat down with Emil Ivov, project leader of the Jitsi Project to talk about a wide range of topics including how Jitsi got started and why it does so much with IPv6 (interesting reason!), what they are looking to do with Jitsi now, the role of DNSSEC and why they added that support to Jitsi... and much, much more... I quite enjoyed talking to Emil and the Jitsi project is certainly one that I will continue to watch - and use!

If you found this post interesting or useful, please consider either:


Live Webcast Thursday March 28 of ION Singapore IPv6 and DNSSEC Sessions (Featured Blog)

For those of you interested in IPv6 and/or DNSSEC, we'll have a live webcast out of the Internet Society's ION Singapore conference happening tomorrow, March 28, 2013, starting at 2:00pm Singapore time. More...

Live Webcast Thursday March 28 of ION Singapore IPv6 and DNSSEC Sessions (Featured Blog)

More...

APNIC Offering DNSSEC Training in Mongolia April 1-3

APNIC logoWe noticed that our friends over at APNIC are offering DNSSEC training in Ulaanbaatar, Mongolia, from April 1-3 and since, well, we’ve never written anything about Mongolia on this site before, we figured we ought to do so!

The course is APNIC’s DNS/DNSSEC workshop and sounds like an excellent offering.  Given that APNIC was recently tweeting about this event we are assuming there is still space available.

The training session is one in a whole series of training workshops APNIC is offering on topics including DNS/DNSSEC, IPv6, Routing and more.

Given that Mongolia’s .MN TLD is signed with DNSSEC (as shown in the list of signed TLDs), we’re looking forward to seeing more signed .MN domains and more usage of DNSSEC in Mongolia after this workshop!