5 ms·
Are you doing anything interesting with DNSSEC?
by desufnoc 12y ago
Are you doing anything interesting with DNSSEC?
- AlyssaRowan 12y agoTake a look at the RFCs coming out recently. DANE, in particular. DNSSEC is an important trust root that can be used to pin certificates in addition to PKIX (CAs), or, in some practical cases (such as mailservers), instead of them. Are you still running Telnet?
- desufnoc 12y agoSo you have deployed DNSSEC and are actively using DANE?
- mike-cardwell 12y agoFWIW, I left Namecheap for GKG.net for the sole reason that Namecheap didn't support DNSSEC. And yes, I have deployed DNSSEC and DANE. On https for emailprivacytester.com, and on https, smtp, imap and xmpp for grepular.com.
- desufnoc 12y agoNeat. It's probably difficult to tell but do you have any idea what usage is like?
- mike-cardwell 12y agoI'm guessing for DNSSEC, the usage is probably low and for DANE it's probably almost non-existant. FWIW, I use the Firefox addon "DNSSEC Validator" (also does DANE) - https://www.dnssec-validator.cz/ https://www.dnssec-validator.cz/ - So if somebody managed to MITM my connection and insert a different, but still trusted, cert in the way, I'd notice. DNSSEC/DANE would probably see a lot more adoption if one or more of the main browsers did this sort of validation by default.
- mschout 12y agogkg.net supports a restful api to update DNSSEC DS records https://www.gkg.net/ws/ds.html https://www.gkg.net/ws/ds.html FYI
- desufnoc 12y agoWas this reply destined to https://news.ycombinator.com/item?id=7934758 https://news.ycombinator.com/item?id=7934758 (Slightly confused by this board.)