Hello, During last CENTR joint Tech and R&D workgroups meeting, we had a group session about defining "DNSSEC validation best practices". We outlined some key principles and identified some strengths and weaknesses (especially concerning time-based/historical validation) in our current operations.
One objective could be to come out with guidelines and corresponding tool set (existing or developed) to implement those practices. I am not speaking for other CENTR members but if the outcome of those reflections is valuable, it might be a good idea to get insight from and share it with the broader DNS community. Regards, On 2023-10-23 15:21, Landry KOUADIO wrote:
Bonjour à tousJust reassure you that steps have been taken to resolve the problem noted on the .CIIn fact, we noticed a DNS service stoppage on our Signer DNSSEC server.From this observation, we quickly carried out service resumption activities and are currently analyzing all the elements to understand the cause. I would like to thank you for the alerts and also a big thank you to everyone who assisted us with their proposals and recommendations during the management of this incident. I would like to take advantage of this email to reflect on a DNSSEC repository integrating a common knowledge base for all DNS players. we could thus enrich ourselves and contribute effectively to the management of DNS incidents and prevent ourselves from any DNS threats or vulnerabilitiesSincerely logoN.png *Landry KOUADIO* *Chef de Centre POINT CI* Tél. :27 20 34 42 53 Email :[email protected] <[email protected]> Site web :https://www.artci.ci/ <https://www.artci.ci/><https://www.facebook.com/artcipageofficielle?_rdc=1&_rdr> <https://twitter.com/artcitic> <https://www.youtube.com/channel/UCDiVco1S4ljRNjpoRN0U5wQ> <https://ci.linkedin.com/in/autorit%C3%A9-de-r%C3%A9gulation-des-tic-artci-112670240>------------------------------------------------------------------------ *De :* Cedrick Adrien Mbeyet <[email protected]> *Envoyé :* lundi 23 octobre 2023 12:52 *À :* [email protected] <[email protected]> *Cc :* Landry KOUADIO <[email protected]> *Objet :* Re: [dns-operations] TLD .ci DNSSEC-down Yes, also notice the same. I have CC one the people responsible for the .ci in case their is a takeaway for us. Best regards,
-- Guillaume-Jean Herbiet, PhD .lu Technical Manager Fondation Restena 2, avenue de l'Université L-4365 Esch-sur-Alzette T +352 42 44 09 1 F +352 42 24 73 restena.lu | dns.lu | my.lu PGP 0x3A4C47C7 This email may contain information for limited distribution only, please treat accordingly. *** I am out-of-office on Wednesdays ***
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations
