Logo

DNSSEC and Security Workshop - Shared screen with speaker view
Kimberly Carlson - ICANN Org
02:30:28
Hello, my name is Kim Carlson and along with Kathy Schnitt and Andrew McConachie, we will be monitoring this chat room and the Q&A pod. In this role, I am the voice for remote participants. Please note that questions or comments will only be read aloud if submitted within the Q&A pod. I will read them aloud during the time set by the Chair or Moderator of this session. Questions and comments placed in chat will be considered as part of the “chat” and will not be read out loud on the microphone.This session also includes automated real time transcription. By clicking on the “closed caption” button in the Zoom toolbar you can view the real time transcription. This transcript is not official or authoritative.Please note that chat sessions are being archived and follow the ICANN Expected Standards of Behavior. http://www.icann.org/en/news/in-focus/accountability/expected-standards.
Glenn McKnight, Virtual School of Internet Governance
02:32:11
I don't see Steve's slides on the website.
Kathy Schnitt - ICANN Org
02:33:15
@Glenn they are here: https://70.schedule.icann.org/meetings/EFynAdkZzbmxA2M5Y#/?limit=10&sortByFields[0]=isPinned&sortByFields[1]=lastActivityAt&sortByOrders[0]=-1&sortByOrders[1]=-1&uid=E6umHFHPvcfTAnSNE
Kathy Schnitt - ICANN Org
02:45:10
Reminder: During this session, questions or comments will only be read aloud if submitted within the Q&A pod. I will read them aloud during the time set by the Chair or Moderator of this session. If you would like to ask your question or make your comment verbally, please raise your hand. When called upon, you will be given permission to unmute your microphone. Kindly unmute your microphone at this time to speak.
brett
02:48:31
Not directly relevant to the current ppt but are there any plans for ICANN/IANA to support the use of CDS/CDNSKEY polling to enable automated rollovers at the TLD level, making it easier for KSK rolls and also for registry transitions between RSPs.
Clement Genty - Fellow
02:50:07
Hi alln, sorry for the delay, the coffee break lasted...
Steve Crocker
02:50:53
@Brett: I don’t think ICANN/IANA has a role here, but perhaps I misunderstand your question.
Peter van Dijk
02:53:11
Steve, us lowly attendees cannot see whatever it is that Brett said that you responded to.
Steve Crocker
02:54:03
Brett wrote: Not directly relevant to the current ppt but are there any plans for ICANN/IANA to support the use of CDS/CDNSKEY polling to enable automated rollovers at the TLD level, making it easier for KSK rolls and also for registry transitions between RSPs.
Peter van Dijk
02:54:24
thanks Steve
brett
02:55:34
@steve I’m trying to imagine a way that I can do dnskey rolls or GTLD transitions (from another provider) to Nominet and do this without the multiple interactions we do with the RZM manually. EG by placing a CDS record in the TLD that IANA can poll for then insert the new DS into the root (or remove of course)
brett
02:56:23
@steve we have done a lot of GTLD transitions and the multiple interactions needed with the RZM are a PITA
Steve Crocker
02:57:06
Brett, can you repeat for the attendees too?
brett
02:57:27
I’m trying to imagine a way that I can do dnskey rolls or GTLD transitions (from another provider) to Nominet and do this without the multiple interactions we do with the RZM manually. EG by placing a CDS record in the TLD that IANA can poll for then insert the new DS into the root (or remove of course)
Jaromír Talíř
03:00:51
Yes, TLD operator could in theory publish CDNSKEY and IANA could poll for it and update root zone the same way as some TLDs automate DNSSEC towards SLDs. To me it is relevant question. AFAIK, they prefer solution by creating some API for automation instead of this.
brett
03:01:53
Yes an API would also work but it seems to be IANA and the TLDs should be doing it the same way as everyone else, if you see what I mean.
Steve Crocker
03:03:04
I think I understand now. IANA has its own interface for TLD operators to update records in the root. I don’t know whether they plan to change their interface or support polling for DNS/CDNSKEY records. I recommend asking Kim Davies directly.
brett
03:04:36
Thanks Steve, sorry if i phrased the question in a confusing manner. I’ll speak to Kim :)
Kathy Schnitt - ICANN Org
03:06:28
REMINDER: During this session, questions or comments will only be read aloud if submitted within the Q&A pod. I will read them aloud during the time set by the Chair or Moderator of this session. If you would like to ask your question or make your comment verbally, please raise your hand. When called upon, you will be given permission to unmute your microphone. Kindly unmute your microphone at this time to speak.
Steve Crocker
03:07:54
I think I was completely focused on the next level down and just missed what you were asking. My apologies
Mike Arbrouet
03:08:47
That's pretty awesome, coming from a tech guy.
Joe Abley
03:09:12
TLDs tend to change their DS RRSets very infrequently, and there is usually a good deal of planning involved. I'm not convinced that CDS/CDNSKEY in TLD zones would be solving a problem that really exists, but perhaps there are use-cases I am unfamiliar with
Peter van Dijk
03:09:29
CSYNC support has been merged into PowerDNS and is available from our snapshot builds. It will indeed be part of the next release (4.5).
Joe Abley
03:09:46
for contracted parties, publishing CDS/CDNSKEY might technically be contrary to the registry agreement so there might be some policy work to do there ("might" because I am definitely not a lawyer :-)
Joe Abley
03:10:02
publishing CDS/CDNSKEY in the TLD zone itself, I mean, not digesting it from child zones
Wes Hardaker
03:12:59
Excellent Peter!
Peter Thomassen
03:14:11
thanks :)
Kathy Schnitt - ICANN Org
03:27:49
REMINDER: During this session, questions or comments will only be read aloud if submitted within the Q&A pod. I will read them aloud during the time set by the Chair or Moderator of this session. If you would like to ask your question or make your comment verbally, please raise your hand. When called upon, you will be given permission to unmute your microphone. Kindly unmute your microphone at this time to speak.
Javier Rúa-Jovet
03:27:58
Do we know what the current DNSSEC adoption rate is by ICANN region and how that growth rate is expected to behave like?
Mike Arbrouet
03:29:14
Can we post links of the projects that Eric and team are working on? I'd like to follow up.
Dan York
03:29:18
I can answer
Jacques Latour
03:29:49
When a child publishes a CDS/CDNSKEY, how do we know who's responsible to poll? the registrar? the registry? a DNS operator? or it does not matter if the CDS is properly signed...
Ulrich Wisser
03:30:20
https://github.com/DNSSEC-Provisioning
Steve Crocker
03:31:32
@Jacques, my view is the registry determines who does the work. That is, some registries will do it, but in other cases, the registry will not do it and then must make it clear to the registrars that it’s up to them.
Dan York
03:31:36
DNSSEC Tools Stats - https://stats.dnssec-tools.org/
Jaap Akkerhuis
03:32:19
dnsthough.n;netlabs.nl has some other stats as well
Jaap Akkerhuis
03:32:49
O meant: https://dnsthought.nlnetlabs.nl
Jaap Akkerhuis
03:33:21
It looks at what resolvers do
Eric Osterweil
03:33:54
This the link I was talking abouthttp://secspider.net/islands.html
Eric Osterweil
03:34:05
This the link I was talking abouthttp://secspider.net/islands.html
Viktor Dukhovni
03:35:30
The regions with the most DNSSEC adoption are Northern and Central Europe, USA and Brazil.
Shumon Huque
03:35:42
How widely are DPS statements published by TLDs? Does ICANN have any policy on this w.r.t. contracted parties?
KeNIC Admin
03:35:57
Any tracking of CCTLDs?
Shumon Huque
03:35:57
How widely are DPS statements published by TLDs? Does ICANN have any policy on this w.r.t. contracted parties?
KeNIC Admin
03:36:26
Any tracking of CCTLDs?
Viktor Dukhovni
03:37:06
What does “tracking of ccTLDs” mean?
Steve Crocker
03:38:12
mailing list: dnssec-provisioning@shinkuro.com
Ulrich Wisser
03:38:25
https://github.com/DNSSEC-Provisioning
Steve Crocker
03:38:35
I will be happy to add anyone who’s interested. Send email to me at steve@shinkuro.com
Kathy Schnitt - ICANN Org
03:50:02
Thank you for joining us for the DNSSEC and Security Workshop Part 2. Part 3 will begin at 17:30 UTC and will be in this same Webinar Room therefore there is no need to disconnect. Enjoy your break 