3 ms·
> Isn't that the same as any DNS mistake though? No, only the DNS mistakes that involve zone delegation; if you screw those up, then yes, it's pretty much the
by jcgl 7mo ago
> Isn't that the same as any DNS mistake though?
No, only the DNS mistakes that involve zone delegation; if you screw those up, then yes, it's pretty much the same. But most DNS mistakes are scoped to one or a handful of names within a zone.
Intra-zone mistakes not only are more narrowly scoped to begin with, but they also use the TTLs that you, the zone admin, control. Whereas inter-zone/delegation mistakes (e.g. NS and DS records) use the cache policy of your parent zone. This is outside of your control as the zone admin, and the TTLs are often longer. So bigger blast-radius with longer-lasting consequences.
- gucci-on-fleek 7mo agoAh right, I forgot that you can't set the TTL on the DNSSEC records in the registry; my bad. But in theory, you shouldn't need to update your DS records much more often than you update your NS records, although this still means that the initial configuration can be a little risky.
- jcgl 7mo ago> But in theory, you shouldn't need to update your DS records much more often than you update your NS records Maybe? You'd update DS whenever changing your key-signing keys. You'd update your NS records and/or glue records when changing your nameservers and/or their IP addresses respectively. In a parallel world with high DNSSEC adoption and well-oiled key management solutions, you're probably making DS changes far more often than NS changes. NS changes might never even happen after a domain's initial setup.
- gucci-on-fleek 7mo ago> Maybe? You'd update DS whenever changing your key-signing keys. Sure, but if once every ~8 years is good enough for the root zone [0], then surely it's good enough for everyone :). I guess I was mainly thinking of my own setup with a single static key but with glue records that I need to change semi-regularly, but this isn't really a typical setup at all. > In a parallel world with high DNSSEC adoption and well-oiled key management solutions, you're probably making DS changes far more often than NS changes. Yup, agreed. [0]: https://data.iana.org/root-anchors/root-anchors.xml https://data.iana.org/root-anchors/root-anchors.xml
- jcgl 7mo ago> Sure, but if once every ~8 years is good enough for the root zone [0], then surely it's good enough for everyone :) Yeah, I don't know how to feel about that exactly :) like, is it actually good enough for them? Probably, I suppose. Those keys don't need to be used that often, and all the signing can be done offline. Contrast that with places further down the hierarchy where stuff changes much more rapidly. And if you're doing something reasonably dynamic (e.g. [0]) then you're gonna need or want online keys. Which (presumably?) should be rotated more frequently because they're more exposed. [0] https://doc.powerdns.com/authoritative/lua-records/index.html#details-security https://doc.powerdns.com/authoritative/lua-records/index.htm...