Date: Fri, 01 May 2009 07:03:48 -0500
Subject: [dns-operations] .gov has been re-inserted into dlv.isc.org
.gov has just been re-inserted into dlv.isc.org. Please report any
problems to dlv-registry@isc.org.
- --Michael
.govにDLVがインプリされた模様。
なにか問題を発見した方はご連絡を。
5/02/2009
4/23/2009
dns-operations@Apr 22, 2009
Date: Wed, 22 Apr 2009 21:31:01 +0100
Subject: [dns-operations] Cache Poisoning Attacks
Seems there were a couple of fairly high profile cache poisoning
attacks today. Thought some of you might be interested.
http://www.theregister.co.uk/2009/04/22/bandesco_cache_poisoning_attack/
http://www.theregister.co.uk/2009/04/22/msn_hijacking/
More fuel for the dnssec fire.
Brett
キャッシュポイズンによる攻撃についてのニュース2件。
これがdnssec普及へのガソリンになるか、どうか。
Subject: [dns-operations] Cache Poisoning Attacks
Seems there were a couple of fairly high profile cache poisoning
attacks today. Thought some of you might be interested.
http://www.theregister.co.uk/2009/04/22/bandesco_cache_poisoning_attack/
http://www.theregister.co.uk/2009/04/22/msn_hijacking/
More fuel for the dnssec fire.
Brett
キャッシュポイズンによる攻撃についてのニュース2件。
これがdnssec普及へのガソリンになるか、どうか。
4/15/2009
dns-operations@Apr 14, 2009
Date: Tue, 14 Apr 2009 15:07:29 -0500
From: Michael Graff
Subject: [dns-operations] Short DLV outage last weekend
To: dns-operations@mail.dns-oarc.net
Message-ID: <49E4ED01.2000008@isc.org>
Content-Type: text/plain; charset=ISO-8859-1
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
DLV experienced a 6 minute service interruption on April 11 at midnight
UTC. This was caused by an error in a re-signing script error which we
believed to have been fixed. We had staff on-hand to watch the
re-signing, and the zone was quickly rolled-back to a working copy.
We have now added additional human verification steps to ensure that a
DLV zone is not published incorrectly. Development and testing of
additional script-based checking to assist in this verification is under
way.
Although the DLV web front-end had some loss of connectivity during
April 9th when most of the Bay area was out of service due to malicious
fiber damage, ISC's SNS service, which serves DLV, was unaffected.
- --Michael
先週末、6分間DLVが止まった報告。
署名エラーで動かなくなるのは辛いな。機構的に。
From: Michael Graff
Subject: [dns-operations] Short DLV outage last weekend
To: dns-operations@mail.dns-oarc.net
Message-ID: <49E4ED01.2000008@isc.org>
Content-Type: text/plain; charset=ISO-8859-1
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
DLV experienced a 6 minute service interruption on April 11 at midnight
UTC. This was caused by an error in a re-signing script error which we
believed to have been fixed. We had staff on-hand to watch the
re-signing, and the zone was quickly rolled-back to a working copy.
We have now added additional human verification steps to ensure that a
DLV zone is not published incorrectly. Development and testing of
additional script-based checking to assist in this verification is under
way.
Although the DLV web front-end had some loss of connectivity during
April 9th when most of the Bay area was out of service due to malicious
fiber damage, ISC's SNS service, which serves DLV, was unaffected.
- --Michael
先週末、6分間DLVが止まった報告。
署名エラーで動かなくなるのは辛いな。機構的に。
4/06/2009
NANOG@Apr 5, 2009
Date: Sun, 05 Apr 2009 07:00:53 +0000
From: Paul Vixie
Subject: Re: ISC DLV
To: nanog@merit.edu
Message-ID:
Content-Type: text/plain; charset=us-ascii
Paul Ferguson writes:
> On Sat, Apr 4, 2009 at 9:55 PM, Marcelo Gardini do Amaral
> wrote:
>
>> Guys,
>>
>> are you having problems to validate DNSEC using ISC DLV?
>>
>
> No idea, but I did see another reference to this over on the OARC dns-ops
> list:
>
> https://lists.dns-oarc.net/pipermail/dns-operations/2009-April/003726.html
note, this isn't a ddos, so it's probably not related to the other dns ddos
events that have been discussed here recently.
see also geoff's reply on that thread:
Date: Sat, 04 Apr 2009 23:15:55 -0700
From: "Geoffrey Sisson"
To: dns-operations@lists.dns-oarc.net
Subject: Re: [dns-operations] ISC DLV broken?
Sender: dns-operations-bounces@lists.dns-oarc.net
mvn@ucla.edu (Michael Van Norman) wrote:
> Starting a bit after 18:00, my home machines starting failing DNSSEC
> validation using the ISC DLV.
...
> Are other people seeing this?
Yes, starting at around the same time (PDT).
Peter_Losher@isc.org (Peter Losher) wrote:
> ISC is aware that there is a issue with lookups against dlv.isc.org and
> are investigating the cause behind it. You may want to disable DNSSEC
> validation against dlv.isc.org at this time.
It appears as if the RRSIG RRset returned by the DLV nameservers for
"dlv.isc.org" is missing the RRSIG for the KSK, so validation for
dlv.isc.org is failing. It _does_ contain the RRSIG for the ZSK (key
id 64263).
As a test I tried changing the trusted key to the ZSK, and DLV validation
appeared to work correctly. This is, of course, not a recommended
work-around.
Geoff
_______________________________________________
dns-operations mailing list
DLVの障害に関して。
NetworkというよりもDNSの障害なのでdns-operationsに正しくルーティングされました。
From: Paul Vixie
Subject: Re: ISC DLV
To: nanog@merit.edu
Message-ID:
Content-Type: text/plain; charset=us-ascii
Paul Ferguson
> On Sat, Apr 4, 2009 at 9:55 PM, Marcelo Gardini do Amaral
>
>
>> Guys,
>>
>> are you having problems to validate DNSEC using ISC DLV?
>>
>
> No idea, but I did see another reference to this over on the OARC dns-ops
> list:
>
> https://lists.dns-oarc.net/pipermail/dns-operations/2009-April/003726.html
note, this isn't a ddos, so it's probably not related to the other dns ddos
events that have been discussed here recently.
see also geoff's reply on that thread:
Date: Sat, 04 Apr 2009 23:15:55 -0700
From: "Geoffrey Sisson"
To: dns-operations@lists.dns-oarc.net
Subject: Re: [dns-operations] ISC DLV broken?
Sender: dns-operations-bounces@lists.dns-oarc.net
mvn@ucla.edu (Michael Van Norman) wrote:
> Starting a bit after 18:00, my home machines starting failing DNSSEC
> validation using the ISC DLV.
...
> Are other people seeing this?
Yes, starting at around the same time (PDT).
Peter_Losher@isc.org (Peter Losher) wrote:
> ISC is aware that there is a issue with lookups against dlv.isc.org and
> are investigating the cause behind it. You may want to disable DNSSEC
> validation against dlv.isc.org at this time.
It appears as if the RRSIG RRset returned by the DLV nameservers for
"dlv.isc.org" is missing the RRSIG for the KSK, so validation for
dlv.isc.org is failing. It _does_ contain the RRSIG for the ZSK (key
id 64263).
As a test I tried changing the trusted key to the ZSK, and DLV validation
appeared to work correctly. This is, of course, not a recommended
work-around.
Geoff
_______________________________________________
dns-operations mailing list
DLVの障害に関して。
NetworkというよりもDNSの障害なのでdns-operationsに正しくルーティングされました。
3/17/2009
dns-operations@Mar 16, 2009
Date: Mon, 16 Mar 2009 13:54:42 -0700
From: Michael Sinatra
Subject: [dns-operations] Problems resolving .gov using DLV
To: dns-operations@mail.dns-oarc.net
Message-ID: <49BEBC92.9060108@rancid.berkeley.edu>
Content-Type: text/plain; charset=ISO-8859-1
Hi,
Is anyone else having problems resolving .gov using the ISC DLV? Just
about an hour ago, my caching resolvers started choking on .gov
addresses with the following errors (the timestamp in PDT [offset -0700]
represents the earliest log entry in my resolvers.
I am currently trying to manually grab the trust anchor and add it to my
BIND config to see if that helps. In the meantime I am wondering if
anyone else is seeing the problem. (Note that I only have two trust
anchors: One for the DLV and one for .se. I currently do not have any
manually added trust anchors for .gov or any subdomain thereof.)
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x842f89000:
GT6F85BNJETCHV2RSE9H4U44V5QRHFON.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8428cc000:
NHQ1OKBN4C6SVH684SOJTC25JFOHEB23.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x842f89000:
GT6F85BNJETCHV2RSE9H4U44V5QRHFON.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e7000:
01BQVVC92HDUCS6JO571RA0M7AAB1TJ2.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e6000:
FCHQ9FMNKR7B37322STB71CNCNRB6C02.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e7000:
01BQVVC92HDUCS6JO571RA0M7AAB1TJ2.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e6000:
FCHQ9FMNKR7B37322STB71CNCNRB6C02.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.946 dnssec: info: validating @0x842f93000: gov
SOA: no valid signature found
16-Mar-2009 12:43:40.946 dnssec: info: validating @0x842f93000: gov
SOA: no valid signature found
michael
DNSSECを使った際にいくつかのトップレベルドメインで問題が起こる件について。
色々なソフトウェア・バージョン・エラーになるドメインの情報が集まってきています。
DNSはInternetの根幹を成すものなので、これの基盤整備は最重要項目。
DNSが壊れるとInternetで誰と通信しているのか判らなくなる・・・
MailにはDKIMが徐々に浸透中。DNSSECはどうか。
From: Michael Sinatra
Subject: [dns-operations] Problems resolving .gov using DLV
To: dns-operations@mail.dns-oarc.net
Message-ID: <49BEBC92.9060108@rancid.berkeley.edu>
Content-Type: text/plain; charset=ISO-8859-1
Hi,
Is anyone else having problems resolving .gov using the ISC DLV? Just
about an hour ago, my caching resolvers started choking on .gov
addresses with the following errors (the timestamp in PDT [offset -0700]
represents the earliest log entry in my resolvers.
I am currently trying to manually grab the trust anchor and add it to my
BIND config to see if that helps. In the meantime I am wondering if
anyone else is seeing the problem. (Note that I only have two trust
anchors: One for the DLV and one for .se. I currently do not have any
manually added trust anchors for .gov or any subdomain thereof.)
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x842f89000:
GT6F85BNJETCHV2RSE9H4U44V5QRHFON.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8428cc000:
NHQ1OKBN4C6SVH684SOJTC25JFOHEB23.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x842f89000:
GT6F85BNJETCHV2RSE9H4U44V5QRHFON.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e7000:
01BQVVC92HDUCS6JO571RA0M7AAB1TJ2.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e6000:
FCHQ9FMNKR7B37322STB71CNCNRB6C02.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e7000:
01BQVVC92HDUCS6JO571RA0M7AAB1TJ2.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.920 dnssec: info: validating @0x8377e6000:
FCHQ9FMNKR7B37322STB71CNCNRB6C02.gov TYPE50: no valid signature found
16-Mar-2009 12:43:40.946 dnssec: info: validating @0x842f93000: gov
SOA: no valid signature found
16-Mar-2009 12:43:40.946 dnssec: info: validating @0x842f93000: gov
SOA: no valid signature found
michael
DNSSECを使った際にいくつかのトップレベルドメインで問題が起こる件について。
色々なソフトウェア・バージョン・エラーになるドメインの情報が集まってきています。
DNSはInternetの根幹を成すものなので、これの基盤整備は最重要項目。
DNSが壊れるとInternetで誰と通信しているのか判らなくなる・・・
MailにはDKIMが徐々に浸透中。DNSSECはどうか。
登録:
投稿 (Atom)