TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

First-ever DNSSEC root key rollover

132 点作者 danyork超过 6 年前

5 条评论

tptacek超过 6 年前
This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time!<p>An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, <i>if you screw the deployment of DNSSEC up</i>, sites vanish off the Internet, like HBO Now did, on Comcast, the week of its debut.<p>Here&#x27;s a fun exercise. In the thread below, someone brought up <a href="https:&#x2F;&#x2F;dnssec-name-and-shame.com" rel="nofollow">https:&#x2F;&#x2F;dnssec-name-and-shame.com</a> (warning: makes annoying noises). Try to find the largest commercial site on the Internet you can that has adopted DNSSEC. Try, for instance, tech giants, or national banks and financial institutions. (Do you want me to spoil this for you?)<p>Ultimately, this key rollover is sort of interesting in a network nerdery kind of way, but it is no practical importance to anyone, because, after almost 3 decades of attempts, DNSSEC is over; stick a fork in it.
评论 #18146455 未加载
评论 #18145175 未加载
评论 #18145229 未加载
评论 #18146830 未加载
评论 #18145207 未加载
ars超过 6 年前
What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did.<p>I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?
评论 #18144431 未加载
评论 #18144474 未加载
评论 #18144399 未加载
评论 #18144393 未加载
评论 #18144455 未加载
评论 #18147140 未加载
ancarda超过 6 年前
I have a DNSSEC signed zone, do I need to do anything? Like generate a new key using this new root key?
评论 #18143901 未加载
评论 #18144260 未加载
评论 #18143941 未加载
edoceo超过 6 年前
But when will it be supported in Route53?
评论 #18145583 未加载
评论 #18144908 未加载
anon49124超过 6 年前
To check DNSSEC:<p><a href="https:&#x2F;&#x2F;dnssec-name-and-shame.com" rel="nofollow">https:&#x2F;&#x2F;dnssec-name-and-shame.com</a><p>To check DANE (such as freebsd.org port 443):<p><a href="https:&#x2F;&#x2F;www.huque.com&#x2F;bin&#x2F;danecheck" rel="nofollow">https:&#x2F;&#x2F;www.huque.com&#x2F;bin&#x2F;danecheck</a>
评论 #18144335 未加载