4 ms·
> DNSSEC also isn't that hard if you're not self-hosting your DNS servers It isn't that hard if: - you use your domain registrar for serving your DNS as well.
by thayne 6mo ago
> DNSSEC also isn't that hard if you're not self-hosting your DNS servers
It isn't that hard if:
- you use your domain registrar for serving your DNS as well. Even if you aren't "self-hosting", but use a different service for DNS hosting than you registered your domain with, then it can be complicated to coordinate between them. And
- your domain registrar makes it easy to set up. For some it is just a checkbox, for others, you have to contact customer support, and sometimes pay more.
Also, the server is just half of the problem. It also requires dns resolvers and clients to validate DNSSEC, which often isn't done today, and even when it is, often fails open, because so many domains don't use DNSSEC, and intermediate resolvers don't always support it. Validating DNSSEC can also hurt performance, in part because of the larger response sizes.
- jeroenhd 6mo ago> Even if you aren't "self-hosting", but use a different service for DNS hosting than you registered your domain with, then it can be complicated to coordinate between them Indeed, you'd need to copy-paste four text fields > for others, you have to contact customer support, and sometimes pay more. That's ridiculous, I've never seen any registrar do that. Even if you do choose a terrible registrar, actual DANE rollout in browsers would put pressure on them to get their shit together. As for DNSSEC validation: validation currently seems to happen between 0 to 95% according to https://stats.labs.apnic.net/dnssec https://stats.labs.apnic.net/dnssec Obviously, for DANE to work, verification must happen. DANE-enabled browsers will enforce validation, or fall back to regular TLS (with the scary warnings if someone stripped DNSSEC for a DANE server, as the certificate doesn't work any more). On operating systems that don't bother with DNSSEC validation, browsers can still query the necessary keys. As for performance, DNSSEC does impose extra network traffic, but so does transmitting an intermediate certificate.
- tptacek 6mo agoHard to square this with the operational history of DNSSEC at some of the best-resourced ops teams in the world.
- jeroenhd 6mo agoIf you're stuck with something like AWS and their buggy implementation then you might indeed run into trouble. Luckily, normal DNS servers don't have this issue. Most people and websites don't have ops teams, though. It's mostly a challenge if you manage your own DNS, which most people don't do.
- tptacek 6mo agoThe point isn't that you're stuck using Route53, it's that large, hypercapable teams, including the one at Route53, have attempted to deploy and manage DNSSEC and failed, indicating that the challenge is not simply "4 lines in a text file".