CO.ZA is DNSSEC Signed.

Mark Elkins <mje-2mCUHEwelu/[email protected]> Tue, 12 Sep 2017 13:30:53 +0200
Newsgroups gmane.org.operators.ioz
Organization Posix Systems
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============1801562296==
Content-Language: en-GB
Content-Type: multipart/alternative;
 boundary="------------B4ACCD4B4FCDE92F9FDE9878"

This is a multi-part message in MIME format.
--------------B4ACCD4B4FCDE92F9FDE9878
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit

In Durban last week at i-Week/SAFNOG, I gave two presentations. You can
find the presentations below...

1) A Safer Internet at https://posixafrica.com/Safer-Internet.pdf  
(Let's Encrypt, DNSSEC and DANE)

2) DNSSEC - Why we can't avoid it at
https://posixafrica.com/iweek-17-DNSSEC-wide.pdf

Two points from the two presentations.

1 - Using a Web Certificate (Let's Encrypt is free) and DNSSEC means you
can implement DANE, which makes for a *safer Internet* experience -
thereby increasing trust from customers.

2 - iweek-17-DNSSEC: If you are with a Registrar that signs domains and
you then move (without first removing DS records in the parent) to a new
Registrar that does not support DNSSEC, then 40% of South Africa will
not see it - the percentage of South Africans using DNSSEC aware
resolvers. You can see the current value at
https://stats.labs.apnic.net/dnssec

I personally believe that not just Banks and E-Commerce type sites
should be using Certificates to protect their web servers or even any
server that uses a Username/Password but even sites that just provide
information to people - where you don't want the content changed by
other people. This probably includes all web sites. One can now do this
with "Let's Encrypt" which gives free Certificates.

DNSSEC also increases security. It ensures that people, when they type
in a Domain Name, get back the correct response. DNSSEC makes data in
the whole zone safe, so now other security information can be inserted
into the zone file of the DNSSEC secured Domain.

Of course - Web Certificates are in themself not 100% safe - but add a
TLSA Record (which is what DANE is) - and things are potentially much
better. You now have a fingerprint of the Web site certificate in the
secured DNS, so now when you open the Web Certificate - software can
cross check that the correct Certificate is found. This also works for
Mail servers.

DNSSEC itself can be "difficult" but there are various bits of software
that can greatly assist in signing a Zone. Some of it allows one to
simply switch on DNSSEC. Take baby steps. Do extensive testing. Eat your
own dog food.

Then of course, Registrars *must be* DNSSEC enabled - even if only to
remove existing DS records. Transferring a "still signed" domain to a
Registrar that is not DNSSEC enabled may lead to the domain not working
for about 40% (and  increasing) of the South African population. Why
though would a User want to move a Domain from a Registrar that can do
DNSSEC to one that can't.

-- 
Mark James ELKINS  -  Posix Systems - (South) Africa
mje-2mCUHEwelu/[email protected]       Tel: +27.128070590  Cell: +27.826010496
For fast, reliable, low cost Internet in ZA: https://ftth.posix.co.za


--------------B4ACCD4B4FCDE92F9FDE9878
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"

   In Durban last week at i-Week/SAFNOG, I gave two presentations. You can
   find the presentations below...
   1) A Safer Internet at [1]https://posixafrica.com/Safer-Internet.pdf
   (Let's Encrypt, DNSSEC and DANE)
   2) DNSSEC - Why we can't avoid it at
   [2]https://posixafrica.com/iweek-17-DNSSEC-wide.pdf

   Two points from the two presentations.

   1 - Using a Web Certificate (Let's Encrypt is free) and DNSSEC means
   you can implement DANE, which makes for a safer Internet experience -
   thereby increasing trust from customers.

   2 - iweek-17-DNSSEC: If you are with a Registrar that signs domains and
   you then move (without first removing DS records in the parent) to a
   new Registrar that does not support DNSSEC, then 40% of South Africa
   will not see it - the percentage of South Africans using DNSSEC aware
   resolvers. You can see the current value at
   [3]https://stats.labs.apnic.net/dnssec

   I personally believe that not just Banks and E-Commerce type sites
   should be using Certificates to protect their web servers or even any
   server that uses a Username/Password but even sites that just provide
   information to people - where you don't want the content changed by
   other people. This probably includes all web sites. One can now do this
   with "Let's Encrypt" which gives free Certificates.

   DNSSEC also increases security. It ensures that people, when they type
   in a Domain Name, get back the correct response. DNSSEC makes data in
   the whole zone safe, so now other security information can be inserted
   into the zone file of the DNSSEC secured Domain.

   Of course - Web Certificates are in themself not 100% safe - but add a
   TLSA Record (which is what DANE is) - and things are potentially much
   better. You now have a fingerprint of the Web site certificate in the
   secured DNS, so now when you open the Web Certificate - software can
   cross check that the correct Certificate is found. This also works for
   Mail servers.

   DNSSEC itself can be "difficult" but there are various bits of software
   that can greatly assist in signing a Zone. Some of it allows one to
   simply switch on DNSSEC. Take baby steps. Do extensive testing. Eat
   your own dog food.

   Then of course, Registrars must be DNSSEC enabled - even if only to
   remove existing DS records. Transferring a "still signed" domain to a
   Registrar that is not DNSSEC enabled may lead to the domain not working
   for about 40% (and  increasing) of the South African population. Why
   though would a User want to move a Domain from a Registrar that can do
   DNSSEC to one that can't.
--
Mark James ELKINS  -  Posix Systems - (South) Africa
[4]mje-2mCUHEwelu/[email protected]       Tel: +27.128070590  Cell: +27.826010496
For fast, reliable, low cost Internet in ZA: [5]https://ftth.posix.co.za

References

   1. https://posixafrica.com/Safer-Internet.pdf
   2. https://posixafrica.com/iweek-17-DNSSEC-wide.pdf
   3. https://stats.labs.apnic.net/dnssec
   4. mailto:mje-2mCUHEwelu/[email protected]
   5. https://ftth.posix.co.za/

--------------B4ACCD4B4FCDE92F9FDE9878--


--===============1801562296==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
IOZ mailing list
[email protected]
http://lists.internet.org.za/mailman/listinfo/ioz

--===============1801562296==--