@bortzmeyer As the manager of the Cascade project, I feel it's important to provide some context and nuance to the terms "alpha”, “beta" and “production ready”. This applies especially to software that is intended to run in critical infrastructure, with possible grave consequences when there is a failure.

While @nlnetlabs is building Cascade on 25 years of experience in DNS and software architecture, operators should not take our work for granted based on that.

This is our plan.

We have frozen the feature set Cascade has now, for the beta release. That means a DNSSEC signer with HSM support, IXFR in and out with TSIG, deterministic incremental signing, review hooks, and monitoring endpoints.

We will mark this release as “beta” in the coming weeks, but read this as whatever you feel is appropriate given the context I gave. That being said: we will dogfood this release. Starting this summer, operators can put Cascade in their testing environments to put it through their wringers, so we can iron out bugs and fix corner cases.

Over the coming months, our aim to have operators build the confidence to start deploying Cascade in production, with the expectation that we'll see real-world Cascade deployments towards the end of this year.

#DNS #DNSSEC #OARC46 #LoveDNS @dnsoarc

Peter Koch (DENIC) on the 5 may problem in .de.

.de has almost 18 million domain names and is incrementally updated.

Validation is done once it is already published.

HSM were using different keys :-(

#DNSSEC
#OARC46

"Cascade [#DNSSEC key manager and signer]: Beyond alpha" by Ximon Eighteen

Written in Rust. Still alpha (beta was not released yet).

Supported (among others) by the Sovereign Tech Agency.

#OARC46

@ximon18 @dnsoarc after his talk on stage, Ximon will be at the demo table in the lunch area, where he can show all the other tricks Cascade has learned since OARC 45 in Stockholm.

Also, make sure to bring your zone files so you can for example see how fast parallel #DNSSEC signing by @bal4e really is. #DNS #LoveDNS #OpenSource

Please pray to the live demo Gods over lunch so @ximon18 can show you our #DNSSEC signer Cascade in action this afternoon at @dnsoarc 46.

We’ll cover incremental signing with IXFR in and out with TSIG, all on a YubiHSM we packed. 🤞

#LoveDNS

The first ongoing outage is Jordan's IDN xn--mgbayh7gpa (الاردن.). They appear to have misplaced their signing infrastructure.

their monthly sig roll didnt occur a few weeks ago and now all sigs are expired.
#dns #dnssec

Another thing I did this week: Finally got DNSSEC set up on my domains thanks to deSEC.io.

I previously used @hetzner for my DNS, but as much as I like their vserver hosting, their DNS service sadly still doesn't support DNSSEC (after starting work on it in 2017, then pausing it in 2018).

#deSEC #dnssec #dns4EU #hetzner

#DNS root zone key rollover under way. (Planned for 11 october.)

"Who in the room has root access to his resolver?" (Lot of hands, this is an OARC meeting.)

#OARC46 #DNSSEC

Wonderful list of things that can go wrong (and therefore, will) in operations.

(Including an error done on friday afternoon and fixed, will you guess, on monday.)

#DNS #DNSSEC #OARC46

The real world is complicated. For signing a .cn domain, it was necessary to send DS records by email... For .br, errors are not corrected 24x7, only during business hours. (Not always the registry's fault, sometimes you have to use a lot of intermediaries.)

#OARC46 #DNSSEC