Re: SA Internet security issues

ox <[email protected]> Tue, 4 Jul 2017 12:39:52 +0200
Newsgroups gmane.org.operators.ioz
Organization ox.co.za
Message-ID <[email protected]>
On Tue, 4 Jul 2017 12:19:13 +0200
Daniel Schroder <[email protected]> wrote:
<snip>
> Also I have a feeling Ipv6 is also going to become a problem.
> Especially in terms of routing, the primaries for za do not all route
> locally, so dns queries can sometimes take a while to answer, and
> again you are not sure of all the networks it transverses. DNSEC
> queries can take a while. (eg disa.tenet.ac.za)
> 
on eu networks, it already is and replies do take longer

> Dnsec does not solve all problems, but it does make things easier if
> you need security on a network you admin. DNS is step one.
> 
> Below is queries on an unbound dns server with no query forwarding,
> with the default trust anchor.
> 
> --Daniel
> Ps. I've given up on all linuxes crap, gone back to FreeBSD.
> 

:)

> drill -TD za ns
> Works
> drill -TD web.za ns
> Works
> drill -TD www.web.za
> Does'nt
> drill -TD co.za
> [T] Existence denied: co.za. DS
> 
> 
> successful answer:
> Key is now trusted!
> [T] web.za. 3600 IN DS 52115 8 2
> 71c7a043c3852da4af98fbd62d4c0ef8cd0420c19d9cc1afa5ad8e29a1417b90
> ;; Domain: web.za.
> [T] web.za. 3600 IN DNSKEY 256 3 8 ;{id = 14499 (zsk), size = 1024b}
> web.za. 3600 IN DNSKEY 257 3 8 ;{id = 52115 (ksk), size = 2048b}
> [T] web.za.     86400   IN      A       206.223.136.163
> ;;[S] self sig OK; [B] bogus; [T] trusted
> 
> 
> On Mon, Jul 3, 2017 at 8:18 PM, Nishal Goburdhan
> <[email protected]> wrote:
> 
> > On 04 Jun 2017, at 09:04, ox <[email protected]> wrote:
> >  
> > > For myself, whether my ISP uses dnssec would (and should) be a
> > > business factor - a competitive advantage, etc.  
> >
> > what competitive advantage is there, in ensuring that you return the
> > correct answer to a question asked?
> >
> >  
> > > Technically, DNSSEC is no silver bullet, but it will improve
> > > Internet  
> > security for  
> > > the small guy, the guy at home and the small business (and for
> > > you)  
> >
> > so, there are two parts here;  first, the signing, and then,
> > validation. while you’re waiting for to get your zone signed, are
> > you validating? does your ISP validate?   have you asked them to?
> >
> > here’s some useful data : https://stats.labs.apnic.net/dnssec/ZA
> >
> > —n.
> > _______________________________________________
> > IOZ mailing list
> > [email protected]
> > http://lists.internet.org.za/mailman/listinfo/ioz
> >  


_______________________________________________
IOZ mailing list
[email protected]
http://lists.internet.org.za/mailman/listinfo/ioz