Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

2 Months To World IPv6 Launch… Have You Signed Up?

There are just 2 months left until World IPv6 Launch on June 6, 2012 -

Have you signed up to join the launch?

Will your website be accessible over IPv6? Or if you are a service provider, will you be making IPv6 available to your customers?  If you will be able to participate, just head over to

www.worldipv6launch.org/form/

and sign up as a World IPv6 Launch participant.  Let the world know that you, too, are joining in to this massive event!

And if you are not yet planning to participate, how can we help you get started?

We’ve got tons of resources that can help:

We also have a steady stream of new Deploy360 blog posts related to IPv6 and posts related to World IPv6 Launch. You can also follow World IPv6 Launch activities directly in social media and interact with others who are launching IPv6:

Please join in … sign up as a participant… and please let us know how we can help you get started with IPv6!

CZ.NIC Labs Launchs DNSSEC Validator Extension for Internet Explorer

C Z dot NIC Labs logoThe news out today is that the great folks at CZ.NIC Labs have launched a DNSSEC validation extension for Internet Explorer similar to the Google Chrome DNSSEC extension and Mozilla Firefox DNSSEC Add-on they have previously released.  Details can be found at:

https://labs.nic.cz/page/1031/rozsireni-dnssec-validator-pro-internet-explorer/

(NOTE: To view the page in English you need to click on the “English” link up near the top center of the page.)

The CZ.NIC Labs team labels this a “technical preview” with a version number of “0.1″.  Judging from the warnings they provide the extension is still very early in the development cycle.

Still, for those interested in experimenting with a way to view the DNSSEC validation status of sites you are visiting, this new extension and toolbar provide a way to see this information directly inside of IE.

National Physical Laboratory


20:00 -20:00 National Physical Laboratory
,

Outstanding DNSSEC Workshop at FOSE Tomorrow

FoseWant to learn about the latest with DNSSEC and the US government? Want to listen to a veritable “Who’s Who” of the people involved with DNSSEC? Tomorrow at the FOSE Conference in Washington, DC, there is what looks to be an outstanding event titled:

MAKING DNSSEC THE TRUST INFRASTRUCTURE: WHERE DOMAIN NAME SECURITY IS HEADED

Going from 10:00am to 4:00pm US Eastern time, the event is described as:

Nearly 50 percent of U.S. Federal domains and a significant number of worldwide governmental, commercial, nonprofit and business domains are now secured with DNSSEC, the Domain Name System Security Extensions. Yet large-scale domain name attacks and vulnerabilities continue, not just to the DNS, but to other applications that rely on the DNS to store information. DNSSEC provides the means to protect application information stored in the DNS, in effect, making DNS a trust infrastructure that other applications can utilize.

In the quest to make DNSSEC a useful trust infrastructure for Internet applications, this session will look at the remaining challenges and emerging trends in U.S. Federal DNSSEC deployment; share new DNSSEC-aware applications; and conduct a wide-ranging discussion of the future of domain-name security with leading Federal and private-sector DNS experts.

The speaker list, though, is what is so amazing!

Not only the top people involved with DNSSEC implementation from throughout the US government, but also the very folks behind so many of the DNSSEC resources we’ve listed here on the site and the people we’ve written about in our DNSSEC-related blog posts. Speakers from organizations like CZNic Labs, NIST, NLNet Labs, Shinkuro and many more… from vendors such as Akamai, Comcast, GoDaddy, Afilias, Google, etc. Plus individuals who have been extremely involved with DNSSEC like Steve Crocker and even security researcher Dan Kaminsky!

All in all it looks to be a truly outstanding event!

The Deploy360 Programme will have a presence there in the form of Richard Jimmerson who heads up our overall project. If you are interested in meeting up with him at the event, please contact him at jimmerson@isoc.org.

THERE IS STILL TIME TO ATTEND! If you have registered for FOSE you can choose the DNSSEC workshop as one of your free educational sessions.


P.S. Alas, I’d love to be there myself and was hoping to get there… but I just returned this weekend from 11 days away for IETF and it turns out the travel won’t work for me this week. I’m very much looking forward to hearing from Richard how it goes…

Friday Video: IPv6 and NAT Fanboys

Continuing our series of humorous Friday posts, how could we not post this animated video on the theme of “NATs are good!”?   :-)

Enjoy…

Deploy360 Team At IETF 83 Next Week In Paris…

IETF LogoIf you are going to be at the 83rd meeting of the Internet Engineering Task Force (IETF) next week in Paris, two members of the Deploy360 team, Megan Kruse and myself (Dan York), will be there onsite for the full week.

Given what we do here at Deploy360, you can expect to typically find us in the DNSSEC-related working groups and the IPv6-related working groups as well as various other groups that have IPv6- or DNSSEC-related documents under consideration. Odds are pretty good that we’ll also be in some of the other working groups highlighted in the recently released document:

Internet Society’s Rough Guide to IETF 83′s Hot Topics

Particularly some of the working groups related to routing security. As usual the IETF 83 agenda offers a packed schedule and we’re looking forward to meeting up with people at the event.

On that note, if you’d like to connect with Megan or I at IETF 83, please feel free to drop us an email to deploy360@isoc.org as that may be the best way to reach us.

See some of you there!

P.S. I’m also going to be in Paris on Saturday and Sunday if any of you are interested in connecting over the weekend.

 

New Paper – “Challenges and Opportunities in Deploying DNSSEC” at SATIN 2012

This morning at the SATIN 2012 conference in London I (Dan York) will be speaking on the topic of “challenges and opportunities in deploying DNSSEC“. Basically I’ll be providing a view of our experience here at Deploy360 over the past 6 months in looking at how to accelerate the deployment of DNSSEC.  As we have been building up our list of DNSSEC resources, we’ve been taking a look at DNSSEC from the “user experience” point of view.  What are the pain points for network operators? for developers? for content providers? for enterprises?

Where are the opportunities to simplify the user experience and make it easier to deploy DNSSEC?

As part of this presentation at SATIN 2012, we created a 7-page paper documenting our findings.  You can download the PDF of this document at:

Challenges and Opportunities in Deploying DNSSEC (SATIN 2012)

As I note on the “resource” page for this paper, we look at the issue from the perspective of:

  • Domain name consumers - any person or application that is using a domain name.
  • Domain name holders - people or organizations who have registered a domain and, in the context of DNSSEC, want to sign the domain.
  • Domain name infrastructure operators - people or organizations that provide the actual service behind the Domain Name System and have a role to play in the DNSSEC signing and validation processes.

Creating the paper was a very useful process in that it helped us identify some of the places where we can add value through the Deploy360 program in the form of new DNSSEC tutorials, HOWTOs and other documents.  I hope that it will be helpful for others out there who are also looking at ways to help accelerate DNSSEC deployment.

I’d very much love to hear any and all feedback on the document.  This is very much a “progress report” of what we have found at this point in time and I expect the list of both challenges and opportunities to evolve over time.

What do you think of the list in this document?  Do you agree? Disagree?  Can you think of other opportunities for simplifying the user experience with DNSSEC?

Again, I’d love to hear from you, either as comments to this post, email to deploy360@isoc.org or via our feedback form

Whitepaper: Challenges and Opportunities in Deploying DNSSEC


At the SATIN 2012 conference on March 23, 2012, the Internet Society’s Dan York spoke about a paper that he and other members of the Internet Society staff developed outlining some of the challenges with DNSSEC deployment and identifying opportunities to simplify the user experience to accelerate DNSSEC deployment. The document is now available for download at:

Challenges and Opportunities in Deploying DNSSEC (SATIN 2012)

The document lays out the challenges and opportunities for:

  • Domain name consumers - any person or application that is using a domain name.
  • Domain name holders - people or organizations who have registered a domain and, in the context of DNSSEC, want to sign the domain.
  • Domain name infrastructure operators - people or organizations that provide the actual service behind the Domain Name System and have a role to play in the DNSSEC signing and validation processes.

Within each section, there are multiple subsections with specific examples.  The document concludes with some thoughts about additional opportunities to accelerate DNSSEC deployment and a lengthy list of resources for further exploration of the topic.

Our goal is that this document can stimulate further discussion about these points and lead to solutions that move DNSSEC deployment further.  We also will be using it within the Deploy360 Programme to identify areas where we need to add more DNSSEC resources to the site.

We welcome any and all feedback and comments, either directly here as comments to this page or sent to us via email or our web form.

Whitepaper: .SE Health Status Report on DNS and DNSSEC

This week the folks at .SE in Sweden released a report full of DNS and DNSSEC information and statistics related to .SE at:

.SE Health Status – DNS and DNSSEC (PDF)

Today at the SATIN 2012 event in London, Anne-Marie Eklund Löwinder from .SE discussed many of the statistics and information contained in the report.    She highlighted many of the major errors they’ve seen and provided an intriguing view into how DNSSEC is actually being deployed in terms of key lengths, encryption algorithms, etc.

At the time of the analysis in early February, .SE had 174,487 domains signed with DNSSEC out of a total of 1,195,719 registered domains.  The document contains a number of interesting charts and other data.

While this report is obviously about a single top-level-domain, it provides interesting insight into DNS and DNSSEC deployment.  Sweden has been a leader in DNSSEC deployment and we look forward to seeing future surveys and the continued growth in signed domains.  Thanks to the .SE team for providing this data to the larger community.

P.S. Want to learn more about how to deploy DNSSEC?  View our list of DNSSEC resources to get started!

Video: Dan York on why Deploy360 was at ICANN43

Why was I (Dan York) at ICANN 43 last week in Costa Rica? While I was at the event, a gent named Glenn McKnight was going around recording videos of various attendees talking about why they were attending ICANN 43. Naturally I was glad to speak to him about the DNSSEC Deployment Workshop and my interest there. Glen is now putting those videos online, and my video interview is available.

(Note: The video interview is only 1 minute 47 seconds long, not the 6:49 shown when you start the video.  The remaining 5 minutes seems to be an entirely black screen. Not sure what happened there.)

Thanks, Glen, for recording the interview!