Notes from DNS-OARC 38
DoQ for authoritative servers, DNS spoofing countermeasures at Google, the cost of DNSSEC validation, and more from DNS-OARC 38.
DoQ for authoritative servers, DNS spoofing countermeasures at Google, the cost of DNSSEC validation, and more from DNS-OARC 38.
Guest Post: A comprehensive look at real world deployments and open challenges.
PING E15: Server push, combined with DNSSEC could help make DNS resolvers a thing of the past.
Making sense of resolverless name resolution.
Handling resolution failure, truncated responses, stateful hash-based DNSSEC signatures, and more.
Guest Post: Has the time come to phase out 1,024-bit RSA from the DNSSEC ecosystem?
Guest Post: By transferring pre-existing trust from the zone’s DNS operator, a new in-band solution would simplify and secure automation of DNSSEC deployment.
Zone file bug hunting, Adaptive DNSSEC, failure behaviour in the DNS, and more from DNS-OARC 37.
Guest Post: DNS transparency is a gaping hole in Internet security.
Guest Post: How to recover from losing all the keys in your HSMs.