CO.ZA is DNSSEC Signed.
Mark Elkins <mje-2mCUHEwelu/[email protected]> Tue, 12 Sep 2017 13:30:53 +0200
| Newsgroups | gmane.org.operators.ioz |
|---|---|
| Organization | Posix Systems |
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============1801562296== Content-Language: en-GB Content-Type: multipart/alternative; boundary="------------B4ACCD4B4FCDE92F9FDE9878" This is a multi-part message in MIME format. --------------B4ACCD4B4FCDE92F9FDE9878 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit In Durban last week at i-Week/SAFNOG, I gave two presentations. You can find the presentations below... 1) A Safer Internet at https://posixafrica.com/Safer-Internet.pdf (Let's Encrypt, DNSSEC and DANE) 2) DNSSEC - Why we can't avoid it at https://posixafrica.com/iweek-17-DNSSEC-wide.pdf Two points from the two presentations. 1 - Using a Web Certificate (Let's Encrypt is free) and DNSSEC means you can implement DANE, which makes for a *safer Internet* experience - thereby increasing trust from customers. 2 - iweek-17-DNSSEC: If you are with a Registrar that signs domains and you then move (without first removing DS records in the parent) to a new Registrar that does not support DNSSEC, then 40% of South Africa will not see it - the percentage of South Africans using DNSSEC aware resolvers. You can see the current value at https://stats.labs.apnic.net/dnssec I personally believe that not just Banks and E-Commerce type sites should be using Certificates to protect their web servers or even any server that uses a Username/Password but even sites that just provide information to people - where you don't want the content changed by other people. This probably includes all web sites. One can now do this with "Let's Encrypt" which gives free Certificates. DNSSEC also increases security. It ensures that people, when they type in a Domain Name, get back the correct response. DNSSEC makes data in the whole zone safe, so now other security information can be inserted into the zone file of the DNSSEC secured Domain. Of course - Web Certificates are in themself not 100% safe - but add a TLSA Record (which is what DANE is) - and things are potentially much better. You now have a fingerprint of the Web site certificate in the secured DNS, so now when you open the Web Certificate - software can cross check that the correct Certificate is found. This also works for Mail servers. DNSSEC itself can be "difficult" but there are various bits of software that can greatly assist in signing a Zone. Some of it allows one to simply switch on DNSSEC. Take baby steps. Do extensive testing. Eat your own dog food. Then of course, Registrars *must be* DNSSEC enabled - even if only to remove existing DS records. Transferring a "still signed" domain to a Registrar that is not DNSSEC enabled may lead to the domain not working for about 40% (and increasing) of the South African population. Why though would a User want to move a Domain from a Registrar that can do DNSSEC to one that can't. -- Mark James ELKINS - Posix Systems - (South) Africa mje-2mCUHEwelu/[email protected] Tel: +27.128070590 Cell: +27.826010496 For fast, reliable, low cost Internet in ZA: https://ftth.posix.co.za --------------B4ACCD4B4FCDE92F9FDE9878 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" In Durban last week at i-Week/SAFNOG, I gave two presentations. You can find the presentations below... 1) A Safer Internet at [1]https://posixafrica.com/Safer-Internet.pdf (Let's Encrypt, DNSSEC and DANE) 2) DNSSEC - Why we can't avoid it at [2]https://posixafrica.com/iweek-17-DNSSEC-wide.pdf Two points from the two presentations. 1 - Using a Web Certificate (Let's Encrypt is free) and DNSSEC means you can implement DANE, which makes for a safer Internet experience - thereby increasing trust from customers. 2 - iweek-17-DNSSEC: If you are with a Registrar that signs domains and you then move (without first removing DS records in the parent) to a new Registrar that does not support DNSSEC, then 40% of South Africa will not see it - the percentage of South Africans using DNSSEC aware resolvers. You can see the current value at [3]https://stats.labs.apnic.net/dnssec I personally believe that not just Banks and E-Commerce type sites should be using Certificates to protect their web servers or even any server that uses a Username/Password but even sites that just provide information to people - where you don't want the content changed by other people. This probably includes all web sites. One can now do this with "Let's Encrypt" which gives free Certificates. DNSSEC also increases security. It ensures that people, when they type in a Domain Name, get back the correct response. DNSSEC makes data in the whole zone safe, so now other security information can be inserted into the zone file of the DNSSEC secured Domain. Of course - Web Certificates are in themself not 100% safe - but add a TLSA Record (which is what DANE is) - and things are potentially much better. You now have a fingerprint of the Web site certificate in the secured DNS, so now when you open the Web Certificate - software can cross check that the correct Certificate is found. This also works for Mail servers. DNSSEC itself can be "difficult" but there are various bits of software that can greatly assist in signing a Zone. Some of it allows one to simply switch on DNSSEC. Take baby steps. Do extensive testing. Eat your own dog food. Then of course, Registrars must be DNSSEC enabled - even if only to remove existing DS records. Transferring a "still signed" domain to a Registrar that is not DNSSEC enabled may lead to the domain not working for about 40% (and increasing) of the South African population. Why though would a User want to move a Domain from a Registrar that can do DNSSEC to one that can't. -- Mark James ELKINS - Posix Systems - (South) Africa [4]mje-2mCUHEwelu/[email protected] Tel: +27.128070590 Cell: +27.826010496 For fast, reliable, low cost Internet in ZA: [5]https://ftth.posix.co.za References 1. https://posixafrica.com/Safer-Internet.pdf 2. https://posixafrica.com/iweek-17-DNSSEC-wide.pdf 3. https://stats.labs.apnic.net/dnssec 4. mailto:mje-2mCUHEwelu/[email protected] 5. https://ftth.posix.co.za/ --------------B4ACCD4B4FCDE92F9FDE9878-- --===============1801562296== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ IOZ mailing list [email protected] http://lists.internet.org.za/mailman/listinfo/ioz --===============1801562296==--