Re: SA Internet security issues
ox <[email protected]> Tue, 4 Jul 2017 12:39:52 +0200
| Newsgroups | gmane.org.operators.ioz |
|---|---|
| Organization | ox.co.za |
| Message-ID | <[email protected]> |
On Tue, 4 Jul 2017 12:19:13 +0200 Daniel Schroder <[email protected]> wrote: <snip> > Also I have a feeling Ipv6 is also going to become a problem. > Especially in terms of routing, the primaries for za do not all route > locally, so dns queries can sometimes take a while to answer, and > again you are not sure of all the networks it transverses. DNSEC > queries can take a while. (eg disa.tenet.ac.za) > on eu networks, it already is and replies do take longer > Dnsec does not solve all problems, but it does make things easier if > you need security on a network you admin. DNS is step one. > > Below is queries on an unbound dns server with no query forwarding, > with the default trust anchor. > > --Daniel > Ps. I've given up on all linuxes crap, gone back to FreeBSD. > :) > drill -TD za ns > Works > drill -TD web.za ns > Works > drill -TD www.web.za > Does'nt > drill -TD co.za > [T] Existence denied: co.za. DS > > > successful answer: > Key is now trusted! > [T] web.za. 3600 IN DS 52115 8 2 > 71c7a043c3852da4af98fbd62d4c0ef8cd0420c19d9cc1afa5ad8e29a1417b90 > ;; Domain: web.za. > [T] web.za. 3600 IN DNSKEY 256 3 8 ;{id = 14499 (zsk), size = 1024b} > web.za. 3600 IN DNSKEY 257 3 8 ;{id = 52115 (ksk), size = 2048b} > [T] web.za. 86400 IN A 206.223.136.163 > ;;[S] self sig OK; [B] bogus; [T] trusted > > > On Mon, Jul 3, 2017 at 8:18 PM, Nishal Goburdhan > <[email protected]> wrote: > > > On 04 Jun 2017, at 09:04, ox <[email protected]> wrote: > > > > > For myself, whether my ISP uses dnssec would (and should) be a > > > business factor - a competitive advantage, etc. > > > > what competitive advantage is there, in ensuring that you return the > > correct answer to a question asked? > > > > > > > Technically, DNSSEC is no silver bullet, but it will improve > > > Internet > > security for > > > the small guy, the guy at home and the small business (and for > > > you) > > > > so, there are two parts here; first, the signing, and then, > > validation. while you’re waiting for to get your zone signed, are > > you validating? does your ISP validate? have you asked them to? > > > > here’s some useful data : https://stats.labs.apnic.net/dnssec/ZA > > > > —n. > > _______________________________________________ > > IOZ mailing list > > [email protected] > > http://lists.internet.org.za/mailman/listinfo/ioz > > _______________________________________________ IOZ mailing list [email protected] http://lists.internet.org.za/mailman/listinfo/ioz