vdchuyen.com
DNSSEC
http://vdchuyen.com/blog/2013/10/27/dnssec.html
Một vài điều cần nhớ về DNSSEC:. Lý thuyết DNSSEC dựa hoàn toàn vào PKI, do đó để hiểu về DNSSEC nên đọc trước về PKI. DNSSEC phá vỡ các chuẩn mạng (DNS RFC) hiện tại của DNS, cụ thể vì gói tin trả về quá lớn, hơn 512 bytes là cái chắc, không chứa nổi bằng UDP nên bắt buộc phải switch sang TCP. Khi DNS server chuyển sang TCP thì có khi bị DDOS còn ghê hơn. Zone VN theo lộ trình của VNNIC thì bắt đầu từ 2014, hoàn thành chắc phải đến 2024. Để Validate các domain mà registra chưa hỗ trợ. Cập nhật trang chủ!
nom.za
NomZa:News
http://www.nom.za/news.php
2015 April 01: WHOIS server. A WHOIS server (compliant with RFC 3912. Is now available for IPv4 clients on whois.nom.za. This service will transition to IPv6 only when the greater internet has adopted IPv6 and is no longer reliant on old technology. For a more complete WHOIS service, please use our web based WHOIS service. The above was created to be compliant with ZA SLD General Policy dated 1 April 2015 from ZADNA. 2012 July 24: E-mail deprecated. Please note that host . Nomza is now deprecated. NOMZA ...
tumori.nu
インターネット運用なリンク
http://www.tumori.nu/link/int-link.html
Inter-Domain Routing Security Workshop). SAKURA Internet Looking glass. BGP Routing Table Analysis Reports. 左側の Looking glass や Tools の集積度がすごい. Appendix B. RIPE/RPSL Tool Query Language に便利な引き方有り. RRDTool 1.2系を使う など.
blog.apnic.net
DNSSEC meets end-of-life DLV: turning off is hard @ RIPE 70 | APNIC Blog
http://blog.apnic.net/2015/05/20/dnssec-meets-end-of-life-turning-off-is-hard-ripe-70
DNSSEC meets end-of-life DLV: turning off is hard @ RIPE 70. On 20 May 2015. Image credit: RIPE NCC. Last week at RIPE 70 Jim Martin, ISC presented. On the end-of-life issues of DLV. DLV, or the Domain Name Service (DNS) Look-aside Validation Service. DLV was useful for some people. And ISC, (who manage and code the “bind” DNS code, which is almost ubiquitously distributed worldwide in UNIX systems) decided to make it work in their code by default but leave it turned off,. If you make something sometimes.
blog.stalkr.net
StalkR's Blog: Going DNSSEC, Unbound and PowerDNS
http://blog.stalkr.net/2012/03/going-dnssec-unbound-and-powerdns.html
Blog of a security enthusiast. Tuesday, March 13, 2012. Going DNSSEC, Unbound and PowerDNS. In this post I will quickly describe what is DNSSEC and why I chose to deploy it, then my choice of Unbound. As a resolver and PowerDNS. As a server and finally give a few resources about this topic. Very quickly, what is DNSSEC? A hierarchical system to authenticate ( integrity) DNS to avoid forgery using public key cryptography. Via your registrar (who has to support it, see ICANN's list. Or publish it to ISC DLV.
amo-probos.org
Amo Probos
http://amo-probos.org/tag/security
Using Zone Key Tool to Manage DNSSEC Signed Domains with NSD. Posted by James E. Blair. On January 29, 2011 at 06:11 PM. NSD is an efficient and simple alternative to BIND. Having major portions of Internet infrastructure rely on one piece of software can be risky, so many large DNS providers now use both authoritative servers in production (splitting them among their infrastructure). NSD's use of BIND format zone files makes this easy, and makes it compatible with many existing tools. Install NSD and th...
incertum.net
DNSSEC mit Debian/squeeze: dnssec-tools, bind9 - Informatik aus Versehen
https://www.incertum.net/archives/11-DNSSEC-mit-Debiansqueeze-dnssec-tools,-bind9.html
DNSSEC mit Debian/squeeze: dnssec-tools, bind9. Sonntag, 19. Juni 2011. DNSSEC mit Debian/squeeze: dnssec-tools, bind9. Fangen wir mal so an:. Ich habe in den letzten zwei Wochen sehr sehr viel getestet und mich dann gestern dazu entschlossen, DNSSEC. Für alle meine privaten Domains live zu stellen. Im folgenden dann kurz - primär für mich als Gedächtnisstützte, aber vielleicht ja auch für andere Leute interessant - die Dokumentation dazu, was ich alles dafür tun musste. Zu den Voraussetzungen: Es ist si...
blog.mithis.net
Mithro rants about stuff : HDMI2USB – Production Board Bring Up – Day 2 (22nd July 2014)
https://blog.mithis.net/archives/timvideos-us/1988-hdmi2usb-production-board-bring-up-day-2-22nd-july-2014
Mithro rants about stuff. 17-Oct-2011 11:57, Canon Canon PowerShot SX230 HS, 4.5, 15.011mm, 0.002 sec, ISO 100. 07-Nov-2011 13:55, Canon Canon PowerShot SX230 HS, 3.1, 5.0mm, 0.25 sec, ISO 400. 19-Feb-2006 12:47, KONICA MINOLTA DiMAGE E500, 9.6, 16.2mm, 0.007 sec, ISO 50. 07-Nov-2011 17:27, Canon Canon PowerShot SX230 HS, 3.5, 6.7mm, 0.025 sec, ISO 400. 11-Jul-2005 14:03, KONICA MINOLTA DiMAGE E500, 9.0, 13.5mm, 0.001 sec, ISO 200. HDMI2USB Production Board Bring Up Day 2 (22nd July 2014). Cypress –...
howtoforge.com
Configuring DNSSEC On BIND9 (9.7.3) On Debian Squeeze/Ubuntu 11.10 - Page 3 - Page 3
https://www.howtoforge.com/configuring-dnssec-on-bind9-9.7.3-on-debian-squeeze-ubuntu-11.10-p3
Log in or Sign up. Configuring DNSSEC On BIND9 (9.7.3) On Debian Squeeze/Ubuntu 11.10 - Page 3. Configuring DNSSEC On BIND9 (9.7.3) On Debian Squeeze/Ubuntu 11.10 - Page 3. Land your dream job and get $5k from Indeed Prime. 100% free. 3 Modifying A Signed Zone (server1). 4 Enabling DNSSEC On The Slave (server2). 5 Enabling DNSSEC On The Resolving DNS (server3). 3 Modifying A Signed Zone (server1). If you want to modify the example.org. But the unsigned version pri.example.org. Go to the /etc/bind. Zone "...