Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-22 Thread Joe Abley
Hi Leo, Late reply! Sorry. Have been neglecting this folder. On 2010-07-16, at 16:53, Leo Bicknell wrote: In a message written on Fri, Jul 16, 2010 at 02:35:39PM +, Joe Abley wrote: The transition from Deliberately-Unvalidatable Root Zone (DURZ) to production signed root zone took

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-18 Thread Tony Finch
On Fri, 16 Jul 2010, Jeffrey Ollie wrote: The ITAR anchors.xml and anchors2keys use a different XML schema than the root-anchors.xml does. *sigh* Tony. -- f.anthony.n.finch d...@dotat.at http://dotat.at/ NORTHWEST FITZROY SOLE: SOUTHWESTERLY 5 OR 6, DECREASING 3 OR 4 LATER. MODERATE OR

Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-07-16 This is the twelfth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Leo Bicknell
In a message written on Fri, Jul 16, 2010 at 02:35:39PM +, Joe Abley wrote: The transition from Deliberately-Unvalidatable Root Zone (DURZ) to production signed root zone took place on 2010-07-15 at 2050 UTC. The first full production signed root zone had SOA serial 2010071501. There have

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Steven Bellovin
Wonderful news!

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Mike
Leo Bicknell wrote: Perhaps you could explain why the keys are being made available in formats that, as far as I can tell, no nameserver software on the planet uses? Pretty much 100% of the users will need a conversion from one of the 6 formats you provided, when you could have provided 6

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Chris Adams
Once upon a time, Leo Bicknell bickn...@ufp.org said: Perhaps you could explain why the keys are being made available in formats that, as far as I can tell, no nameserver software on the planet uses? Pretty much 100% of the users will need a conversion from one of the 6 formats you provided,

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Edward Lewis
At 7:53 -0700 7/16/10, Leo Bicknell wrote: Perhaps you could explain why the keys are being made available in formats that, as far as I can tell, no nameserver software on the planet uses? (My guess:) There's no standard input format for name servers, especially regarding configuration

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Tony Finch
On Fri, 16 Jul 2010, Chris Adams wrote: A simple XSLT will transform it into any needed format. XSLT can't turn root-anchors.xml into the DNSKEY RR that BIND requires. Tony. -- f.anthony.n.finch d...@dotat.at http://dotat.at/ TYNE DOGGER FISHER: SOUTHERLY VEERING WESTERLY 5 TO 7, DECREASING

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Joel Jaeggli
On 7/16/10 11:07 AM, Tony Finch wrote: On Fri, 16 Jul 2010, Chris Adams wrote: A simple XSLT will transform it into any needed format. XSLT can't turn root-anchors.xml into the DNSKEY RR that BIND requires. Tony. anchors2keys will.

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Chris Adams
Once upon a time, Tony Finch d...@dotat.at said: On Fri, 16 Jul 2010, Chris Adams wrote: A simple XSLT will transform it into any needed format. XSLT can't turn root-anchors.xml into the DNSKEY RR that BIND requires. That sounds like a problem with BIND then. :-) -- Chris Adams

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Jeffrey Ollie
On Fri, Jul 16, 2010 at 1:12 PM, Joel Jaeggli joe...@bogus.com wrote: On 7/16/10 11:07 AM, Tony Finch wrote: On Fri, 16 Jul 2010, Chris Adams wrote: A simple XSLT will transform it into any needed format. XSLT can't turn root-anchors.xml into the DNSKEY RR that BIND requires. anchors2keys

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-07-16 Thread Joel Jaeggli
Yeah oops. Just noticed that Joel's iPad On Jul 16, 2010, at 5:34 PM, Jeffrey Ollie j...@ocjtech.us wrote: On Fri, Jul 16, 2010 at 1:12 PM, Joel Jaeggli joe...@bogus.com wrote: On 7/16/10 11:07 AM, Tony Finch wrote: On Fri, 16 Jul 2010, Chris Adams wrote: A simple XSLT will transform

Root Zone DNSSEC Deployment Technical Status Update

2010-07-14 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-07-14 This is the eleventh of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can

Root Zone DNSSEC Deployment Technical Status Update

2010-07-10 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-07-10 This is the tenth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can

Root Zone DNSSEC Deployment Technical Status Update

2010-06-18 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-06-18 This is the ninth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can

Root Zone DNSSEC Deployment Technical Status Update

2010-06-09 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-06-09 This is the eighth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread itservices88
=== On Wed, May 5, 2010 at 2:23 PM, Joe Abley joe.ab...@icann.org wrote: Root Zone DNSSEC Deployment Technical Status Update 2010-05-05 This is the sixth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread Valdis . Kletnieks
On Thu, 20 May 2010 08:33:47 PDT, itservices88 said: I am having this problem now: # dnssec-signzone -N INCREMENT mydomain.org Verifying the zone using the following algorithms: RSASHA1. Missing RSASHA1 signature for . NSEC Missing trust anchor? pgpG65C3ZegOp.pgp Description: PGP

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread itservices88
I have these in named.conf dnssec-enable yes; dnssec-validation yes; // dnssec-lookaside . trust-anchor DLV.ISC.ORG; With the trust-anchor uncommented, as soon as i enable and reload bind, dig gives timeout, while dig has no issues with first two commands enabled. -dani On

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread itservices88
Is there any specific dnssec mailing list, which might be more helpful. Thanks -dani On Thu, May 20, 2010 at 8:53 AM, valdis.kletni...@vt.edu wrote: On Thu, 20 May 2010 08:33:47 PDT, itservices88 said: I am having this problem now: # dnssec-signzone -N INCREMENT mydomain.org Verifying

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread Valdis . Kletnieks
On Thu, 20 May 2010 09:19:44 PDT, itservices88 said: Is there any specific dnssec mailing list, which might be more helpful. https://lists.dns-oarc.net/mailman/listinfo/dns-operations (Unless I've fat-fingered it and it's elsewhere?) pgp8YgFVEOAym.pgp Description: PGP signature

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread Joe Abley
On 2010-05-20, at 12:18, itservices88 wrote: I have these in named.conf dnssec-enable yes; dnssec-validation yes; // dnssec-lookaside . trust-anchor DLV.ISC.ORG; With the trust-anchor uncommented, as soon as i enable and reload bind, dig gives timeout, while dig has no

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-20 Thread Steven G. Huter
Is there any specific dnssec mailing list, which might be more helpful. DNSSEC Deployment dnssec-deploym...@dnssec-deployment.org http://www.dnssec-deployment.org/ steve

Root Zone DNSSEC Deployment Technical Status Update

2010-05-18 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-05-17 This is the seventh of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. CHANGE IN DEPLOYMENT SCHEDULE The date for the publication of the root zone trust

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-16 Thread itservices88
...@icann.org wrote: Root Zone DNSSEC Deployment Technical Status Update 2010-05-05 This is the sixth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. ** The final transition to a signed root zone took place

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-16 Thread Rubens Kuhl
;; Query time: 11 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Sun May 16 11:02:43 2010 ;; MSG SIZE  rcvd: 641 === On Wed, May 5, 2010 at 2:23 PM, Joe Abley joe.ab...@icann.org wrote: Root Zone DNSSEC Deployment Technical Status

Re: Root Zone DNSSEC Deployment Technical Status Update

2010-05-16 Thread itservices88
:43 2010 ;; MSG SIZE rcvd: 641 === On Wed, May 5, 2010 at 2:23 PM, Joe Abley joe.ab...@icann.org wrote: Root Zone DNSSEC Deployment Technical Status Update 2010-05-05 This is the sixth of a series of technical status

Root Zone DNSSEC Deployment Technical Status Update

2010-05-05 Thread Joe Abley
Root Zone DNSSEC Deployment Technical Status Update 2010-05-05 This is the sixth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. ** The final transition to a signed root zone took place today ** on J-Root

Root Zone DNSSEC Deployment Technical Status Update

2010-04-14 Thread Joe Abley
This is the fourth of a series of technical status updates intended to inform a technical audience on progress in signing the root zone of the DNS. RESOURCES Details of the project, including documentation published to date, can be found at http://www.root-dnssec.org/. We'd like to hear from