DNSSEC with RSA-4096 keys
We must anticipate changes in computational capacity when choosing an encryption algorithm, but is it relevant to DNSSEC?
We must anticipate changes in computational capacity when choosing an encryption algorithm, but is it relevant to DNSSEC?
Guest Post: After issues at recent DNSSEC KSK ceremonies what can we expect at the next one?
Guest Post: What happens at a Root KSK ceremony? What’s at stake, and what could go wrong?
Guest Post: A new visualization project is shedding light on how regularly DNSSEC are keys being updated.
Geoff shares his thoughts on what was being discussed the recent OARConline 35a.
RFC 9102: Trust versus credulity.
Guest Post: Alternative models to zone transfer that can support DNSSEC’s non-standardized features.
Geoff Huston’s snapshot of current working group activities related to the DNS.
What exactly is a ‘key ceremony’ and why are they important for trust?
Guest Post: A lot of groups develop great cybersecurity intelligence. Can we apply that knowledge via public resolvers?