Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

Testing the details element

I was rather amazed today to discover the <details> element. Where had this been?  Clearly I’ve not been keeping up with the evolution of HTML! 😞


Why is this site called deepdark.blue?I wanted to test out using a “new generic top-level domain” (newgtld).
But why .blue?Why not? And because I like the color blue.
But is there any other point to this site?Nope. None whatsoever. It’s just a testing site.

Per the Mozilla documentation of <details>, this is supported by all modern browsers except Microsoft IE and Microsoft Edge. It does seem that MS is working on adding this to Edge, though.

Hat tip to someone on Mastodon who pointed me to:

TDYR 357 – The DNSSEC KSK Rollover on October 11 was blissfully boring

October 11, 2018, was a blissfully boring day on the Internet - and that was a beautiful thing! The long-planned DNSSEC Root KSK Rollover (described in TDYR 356 - https://soundcloud.com/danyork/tdyr-356-are-you-prepared-for ) did *NOT* "break the Internet". There were no large outages. Everything went as planned. In this episode, I talk about all of that, why it matters - and what is next. Image credit: NLNet Labs - https://www.nlnetlabs.nl/

Website update: Experiencing problems with translations into French and Spanish

I must apologize to readers of our French and Spanish versions of our website. We are currently experiencing a problem with our usage of the WordPress Multilingual (WPML) plugin that is preventing us from sending our new content out for translation.  It is proving to be quite difficult to identify and fix the issue. We are working with our development team, our hosting provider, and the WPML support team to find the solution. I hope that in the next couple of days we can solve this and return to our regular publishing in three languages.

Thank you for your patience.

P.S. Those who want more of the technical details can see the open WPML support ticket. You are also welcome to contact me directly at york@isoc.org.

The post Website update: Experiencing problems with translations into French and Spanish appeared first on Internet Society.

We Need to Talk… about the State of Internet Governance

Pre IGF Speed Dating

In about a month, some of the key stakeholders in Internet Governance will come together in Paris and talk about the public policy challenges facing the Internet in 2018 and beyond. They will do so at the Internet Governance Forum, a UN-supported platform that will meet for the thirteenth time this year.

The IGF traditionally brings different groups of stakeholders into a large conference centre, and provides for the opportunity for these different stakeholders to discuss: the idea being that understanding, consensus and collaboration will emerge between these different communities.

Join us for a pre-IGF stakeholder networking event on Tuesday, 16 October in Brussels.  Learn more and register!

Multistakeholderism: a vivid term with many meanings

The IGF model of multistakeholderism is one of a plethora of different approaches to engaging with actors beyond states in questions of global governance. Some rely more on governments, other processes rely on technical expertise, others have come and gone. Others, like the Internet Society, tend to refer to multistakeholder approaches, rather than one model.

Many observers tend to think this concept was invented by the Internet community, but shaping (global) policy through direct engagement with stakeholders has been an integral part of a range of different policy fields for a long time. In environmental policy, labour relations, and forestry management to name but a few, one of the key questions asked by policymakers has been “how can we develop globally-relevant, fair, legitimate and efficient policies?” The conclusions drawn policymakers often included the strengthening of participatory governance mechanisms, which is where multistakeholder approaches step in. These approaches try to answer the ‘who’ (participation), ‘why’ (purpose), and ‘how’ (process) questions differently from how governments of flesh and steel would normally answer them.

For better or worse, the IGF is one of the biggest platforms for Internet Governance. The IGF undoubtedly serves a purpose at this moment, and is very useful for many of its participants. However, we have been talking about its reform for a while now, and even longer.

What needs to happen?

Does the IGF need another grand review? There are many things that could be done to generate a new momentum behind the IGF. These are not new and do not address all the problems, but as a whole, these elements may work to help us consider some of the ‘who’, ‘how’ and ‘why’ questions that still linger around the IGFs and other multistakeholder fora.

  1. Sort out our calendars. First of all, this IGF takes place at a time when an increasingly important number of ‘competititors’ will also be discussing Internet Governance. For example, the ITU’s Plenipotentiary is taking place at the same time as the IGF.
  2. Give it time. The IGF also has no day zero this year, to enable different groups to organise fringe events and coordination meetings. Hence, meetings like the Brussels pre-IGF meeting, on 16 October are incredibly important to allow for people to share information prior to the meeting itself.
  3. Work out who does what. Other venues are also venturing into the IGF space, with the UN Secretary General’s High Level Panel on Digital Cooperation recently having been announced, amongst others. So, we see a collection of different fora being (re-)established to focus on Internet Governance. Rather than a threat, this is actually an opportunity to think about the next thirteen years of the IGF: a little competition is actually a good thing.
  4. Get real. The IGF has often been touted as the opportunity to gather the world’s Internet community together to discuss how the Internet should be governed. This gargantuan task is not an easy one. What can the IGF actually achieve? The expectations of the forum need to be clearly set out, so that all stakehholders can share the same aim, and then work to deliver it.
  5. Focus. It may be useful to generate common themes and threads for discussion across IGFs, so that reporting, discussion and measurement can be continuous and tell a coherent and consistent story from one IGF to the next.
  6. Make much better use of the NRIs. National and Regional initiatives can feed into discussions at the IGF in a far more constructive way. They can also be platforms to push outcomes from the IGFs.
  7. Ensure all stakeholders are involved. IGFs tend to be open spaces, but that does not mean that self-exclusion, ignorance, or what I have heard termed ‘exclusion by acronym’ does not exist. Despite the diverse and broad nature of the subjects discussed at the IGFs, much of the entrepreneurial community is not present at these discussions; and their discussions on these topics go on in parallel in other spaces, such as this one. Furthermore, if states want the IGF process to be as legitimate as possible, they also need to engage fully in the events.

Join us for a pre-IGF stakeholder networking event on Tuesday, 16 October in Brussels. Learn more and register!

The post We Need to Talk… about the State of Internet Governance appeared first on Internet Society.

TDYR 356 – Are you prepared for the DNSSEC Root Key Rollover on October 11, 2018?

TDYR 356 - Are you prepared for the DNSSEC Root Key Rollover on October 11, 2018? by Dan York

How to Prepare for the DNSSEC Root KSK Rollover on October 11, 2018 (Featured Blog)

Are you ready? Are your systems prepared so that DNS will keep functioning for your networks? One week from today, on Thursday, October 11, 2018, at 16:00 UTC ICANN will change the cryptographic key that is at the center of the DNS security system - what we call DNSSEC. The current key has been in place since July 15, 2010. This is a long-planned replacement. More...

How to prepare for the DNSSEC Root KSK Rollover on October 11, 2018 (Featured Blog)

More...

Are you ready? How to prepare for the DNSSEC Root KSK Rollover on October 11, 2018

skeleton key

Are you ready? Are your systems prepared so that DNS will keep functioning for your networks?  One week from today, on Thursday, October 11, 2018, at 16:00 UTC ICANN will change the cryptographic key that is at the center of the DNS security system – what we call DNSSEC. The current key has been in place since July 15, 2010. This is a long-planned replacement.

If everything goes fine, you should not notice and your systems will all work as normal. However, if your DNS resolvers are not ready to use the new key, your users may not be able to reach many websites!

This change of this central security key for DNS is known as the “Root Key Signing Key (KSK) Rollover”. It has been in discussion and planning since 2013. We’ve written many articles about it and spoken about it at many conferences, as have many others in the industry. ICANN has a page with many links and articles at:

But here we are, with only a few days left and you may be wondering – how can I know if my systems are ready?

The good news is that since the Root KSK Rollover was delayed 1 year, most all of the DNS resolver software has been shipping for quite some time with the new key. If you, or your DNS server administrators, have been keeping up with recent updates, you should be all set.

1. Test if you are doing DNSSEC validation

Before you do anything else, you should first check if you are doing DNSSEC validation on your network.  As noted in ICANN’s guidance document, go to a command-line / terminal / shell window and type:

dig @<IP of your DNS resolver> dnssec-failed.org a +dnssec

For example, using Google’s Public DNS Server, the command would be:

dig @8.8.8.8 dnssec-failed.org a +dnssec

If the response includes this text:

;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL

then you ARE doing DNSSEC validation and should read the rest of this article.

If the response instead includes:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR

… well, you are NOT doing DNSSEC validation. You can skip the rest of this article, go have a beverage, and not have to worry about the Root KSK Rollover on October 11.  However, you should also read up on DNSSEC and understand why you start validating to raise the level of security and trust on your network. (But, at this point, you might as well wait until October 12 to deploy it.)

If you are doing DNSSEC validation, read on. 

Two notes:

  • Unfortunately if you are not an administrator of your DNS resolvers, there are limited mechanisms to check if you have the new key. There are a couple of possibilities (see #2 and #3a below), but otherwise you will need to contact your DNS administrators / IT team and point them to this blog post and other resources.
  • In DNS / DNSSEC circles the root key is also referred to as a “trust anchor”.

2. Try the Sentinel KSK Test

For a small percentage of you reading this, you might be able to use the “sentinel test” that is based on an Internet draft that is in development. You can do so at either of these sites:

Right now there is only one DNS resolver (Unbound) that implements this sentinel test. Hopefully by the time we do the next Root KSK Rollover, some years from now, this will be more widely deployed so that regular users can see if they are protected.

However, for most of us, myself included, we need to go on to other methods…

3a. Check if your DNS resolvers have the new Root KSK installed – via various tools

There are several tests you may be able to perform on your system. ICANN has published a list at:

That document lists the steps for the following DNS resolvers:

  • BIND
  • Unbound
  • PowerDNS Recursor
  • Knot Resolver
  • Windows Server 2012RS and 2016
  • Akamai DNSi Cacheserve
  • Infoblox NIOS

For BIND users, ISC2 also provides a focused document: Root KSK Rollover in BIND.

3b. Check if your DNS resolvers have the new Root KSK installed – via specific files

If you have command-line access to your DNS servers, you can look in specific files to see if the new key is installed.  The current key (“KSK 2010”) has an ID of 19036. The new key has an ID of 20326. As Paul Wouters wrote in a Red Hat blog post today, these keys can be found in these locations in Red Hat Linux:

  • bind – see /etc/named.root.key
  • unbound / libunbound – see /var/lib/unbound/root.key
  • dnsmasq – see /usr/share/dnsmasq/trust-anchors.conf
  • knot-resolver – see /etc/knot-resolver/root.keys

Look in there for a record with an ID of 20326. If so, you are all set. If not, you need to figure out how to get the new key installed.

Note – these locations here are for Red Hat Linux. Other Linux distributions may use slightly different file locations – the point is that there should be a file somewhere on your system with these keys.

4. Have a backup plan in case there are problems

As Paul notes in his post today, it would be good to have a backup plan in case there are unexpected DNS problems on your network on October 11 and users are not able to resolve addresses via DNS. One suggestion is to temporarily change your systems to give out one of the various sets of “public” DNS servers that are operated by different companies. Some of these include:

IPv4 IPv6 Vendor
1.1.1.1 2606:4700:4700::1111 Cloudflare
8.8.8.8 2001:4860:4860::8888 Google DNS
9.9.9.9 2620:fe::fe Quad9
64.6.64.6 2620:74:1b::1:1 Verisign

You can switch to one of these resolvers while you sort out the issues with your own systems. Then, once you have your systems correctly configured, you can switch back so that the DNSSEC validation is happening as close to your users as possible (thereby minimizing the potential areas of the network where an attacker could inject malicious DNS traffic).

5. Plan to be around on 11 October 2018 at 16:00 UTC

Finally, don’t schedule a day off on October 11th – you might want to be around and able to monitor your DNS activity on that day.  This Root KSK Rollover has been in the works for many years now. It should be a “non-event” in that it will be “just another day on the Internet”. But many of us will be watching whatever statistics we can. And you’ll probably find status updates using the #KeyRoll hashtag on Twitter and other social networks.

The end result of all of this will be the demonstration that we can safely and securely change the cryptographic key at the center of DNS – which allows us to continue improving the level of security and trust we can have in this vital part of the public core of the Internet!


Image credit: Lindsey Turner on Flickr. CC BY 2.0

P.S. This is NOT what the “Root key” looks like!

Acknowledgements:  Thanks to Ed Lewis, Paul Hoffman, Paul Wouters, Victoria Risk, Tony Finch, Bert Hubert, Benno Overeinder, Hugo Salgado-Hernández, Carlos Martinez and other members of the dnssec-coord discussion list for the discussion that informed this post.

The post Are you ready? How to prepare for the DNSSEC Root KSK Rollover on October 11, 2018 appeared first on Internet Society.

TDYR 355 – A personal update about my post-cancer recovery

As a follow-up to episode 354, I provide an update about my recovery from surgery and colon cancer....

(No title)

Fascinating to see another billionaire buy a major media property, in this case Time Magazine – https://m.huffpost.com/us/entry/us_5b9efe6fe4b046313fbc441c