Just a guy in Vermont trying to connect all the dots...
Author's posts
Apr 01
DNSSEC Presentations Coming Up at ICANN46 in Beijing
Next week at the ICANN 46 meetings in Beijing, China, there will be a series of DNSSEC-related workshops. I (Dan York) will be there at ICANN 46 and will be participating in these sessions. If you are able to attend in person, the events will be an excellent way to learn more about DNSSEC.
NOTE: Remote participation IS possible. See the links below to listen to the live streams.
The major DNSSEC-related meetings are on Monday, April 8, 2013, and Wednesday, April 10, 2013. They are:
DNSSEC for Everybody – A Beginner’s Guide
Monday, 8 April 2013 – 5pm-6:30pm, Auditorium – http://beijing46.icann.org/node/37065
This very basic introductory session is aimed to help attendees understand more about how DNSSEC can secure the Domain Name System and make the Internet more secure. As DNSSEC gets more widely deployed it is critical to understand how DNSSEC works. This session provides an interactive and fun way to learn how DNSSEC works, what tools are available to help and what best practices are currently being used.
DNSSEC Workshop
Wednesday, 10 April 2013, 8:30am-2:45pm, Rainbow – http://beijing46.icann.org/node/37125
This 6+ hour workshop brings together industry leaders on DNSSEC for a series of panel discussions about the state of the art in implementing DNSSEC, current best practices, government regulations and operational practices. Sessions also include talks about the latest and innovative uses of DNSSEC. Panels at ICANN 46 include:
- Introduction and DNSSEC Deployment Around The World
- DNSSEC: Regulative, Legislative and Persuasive Approaches to Encouraging Deployment
- DNSSEC Deployment in Asia Pacific
- Use of DNSSEC in the Reverse Name Space
- The Operational Realities of DNSSEC
- DNSSEC Innovation: DANE and Other DNSSEC Applications
- Root Key Rollover
There will be case studies and reports on some of the latest tools. Of interest to many may be the talk from someone at CNNIC about China’s plans for deploying DNSSEC and signing .CN. I’ll be moderating the panel on “DNSSEC Innovation” as well as providing a brief tutorial about the DANE protocol and how it helps. Several of the other panelists will also be talking about DANE so it should be a good session.
I’ve attended several of these workshops now and have been very impressed by the quality of the sessions in terms of technical content. If you’re at all interested in DNSSEC, I really can’t recommend the event strongly enough. In full disclosure, I joined the Program Committee for this ICANN 46 workshop, so I’m a wee bit biased… but it also means I’ve seen many of the proposals as well as the completed slide decks – and I can say that there will be some excellent sessions there.
On Monday evening, there will also be an informal gathering of people involved with implementing DNSSEC to discuss and exchange information about DNSSEC implementations. As noted in the email announcement, you need to RSVP by Thursday, April 4, as it is being held at a local restaurant and a count of attendees is needed.
In looking over the ICANN 46 schedule, another meeting I will probably attend is the “Joint DNS Security and Stability Analysis Working Group (DSSA)” on Thursday, April 11, 2013. While it is not specifically about DNSSEC, it relates to “DNS security” in general and I would think it should be a rather interesting session given the recent DDoS attacks going on that are using DNS amplification.
If you are going to be at ICANN 46 and would like to meet with me to talk about DNSSEC, IPv6, routing resiliency or just Deploy360 in general, please feel free to drop me a note or find me in one of these sessions mentioned here.
You can also listen to an audio version of this post at:
Apr 01
FIR #697 – 4/1/13 – For Immediate Release
Mar 29
Jumper Cables And The Absolutely Awesome Kindness Of Total Strangers
Mar 29
Comcast Publishing Domains Failing DNSSEC Via Twitter
How do you know when a domain is failing DNSSEC validation? What if there was a way to let the broader industry know about these validation failures? The folks over at Comcast’s DNS team have been trying an experiment for a while in posting these DNSSEC validation failures publicly to Twitter at:
If you are a system/network operator deploying DNSSEC and want to be alerted when sites are found to be failing validation, following this Twitter account is one way you can get alerts.
I don’t know whether publishing domains failing DNSSEC validation via Twitter will really be a long-term solution to letting the wider industry know about domains that are currently failing validation, but I applaud Comcast’s DNS team for trying something different … and I do follow the account myself because I find the occasional tweets interesting to see.
Mar 28
Reflections About Singapore Before Leaving
Mar 28
IPSO Challenge 2013 Offers $10K To Winner With Best New Internet of Things Idea/Product
Looking for an interesting new weekend project? Are you interested in devices for the “connected home” or the “Internet of Things?” Have you been automating your home or building sensor networks? Do you like experimenting with hardware platforms like Arduino or the Raspberry Pi?
Would you like to potentially win $10,000 USD?
If so, check out the IPSO Alliance’s “IPSO Challenge 2013” where the About page explains the challenge:
The IPSO (Internet Protocol for Smart Objects) Alliance is sponsoring a worldwide challenge to showcase the use of the Internet Protocol (IP) in sensor/control and M2M applications enabling the Internet of Things (IOT). IPSO Challenge 2013 is a competition promoting the development of Smart Objects which use the Internet Protocol. Just 30 years after the official adoption of the TCP/IP networking protocol, nearly 10 billion devices can connect to the Internet; and before the end of the decade, that number is forecast to nearly triple. Over the coming years, the vast majority of newly connected devices won’t be computers, tablets, or smartphones, but will be intelligent embedded devices participating in the Internet of Things (IoT).
The deadline to submit a written proposal is coming up soon on APRIL 5, 2013, using the submission form at the bottom of the main IPSO Challenge 2013 page. Semi-finalists will be notified soon thereafter and will need to submit a functional prototype by May 17, 2013. Ultimately winners will be chosen who will receive $10,000, $5,000 and $2,500. More details about what you need to do can be found on the About page for the contest.
Why are we writing about this contest here on Deploy360? Simple. The reality is that to get the massive scale being considered for the “Internet of Things” many implementations will need to use IPv6.
We were in contact with the people behind this IPSO Challenge 2013 and they are very definitely interested in receiving IPv6 entries.
So we’d like to encourage any of you developers out there to submit some IPv6 proposals! It would be great if some of the semi-finalists or finalists were entries working over IPv6.
So… if you like working with these kind of projects, do check out the IPSO Challenge site and submit your ideas!
Mar 28
Video Interview: Emil Ivov about how the Jitsi softphone works with IPv6 and DNSSEC
If you found this post interesting or useful, please consider either:
- following me on Twitter;
- adding me to a circle on Google+;
- following me on App.net
- subscribing to my email newsletter; or
- subscribing to the RSS feed
Mar 27
Live Webcast Thursday March 28 of ION Singapore IPv6 and DNSSEC Sessions (Featured Blog)
Mar 27
APNIC Offering DNSSEC Training in Mongolia April 1-3
We noticed that our friends over at APNIC are offering DNSSEC training in Ulaanbaatar, Mongolia, from April 1-3 and since, well, we’ve never written anything about Mongolia on this site before, we figured we ought to do so!
The course is APNIC’s DNS/DNSSEC workshop and sounds like an excellent offering. Given that APNIC was recently tweeting about this event we are assuming there is still space available.
The training session is one in a whole series of training workshops APNIC is offering on topics including DNS/DNSSEC, IPv6, Routing and more.
Given that Mongolia’s .MN TLD is signed with DNSSEC (as shown in the list of signed TLDs), we’re looking forward to seeing more signed .MN domains and more usage of DNSSEC in Mongolia after this workshop!
