Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Looks like DE ccTLD is unresolvable due to DNSSEC issue:https://dnsviz.net/d/nic.de/dnssec/

Looks like DE ccTLD is unresolvable due to DNSSEC issue:https://dnsviz.net/d/nic.de/dnssec/

Scheduled Pinned Locked Moved Uncategorized
infosecdnssecdnsgermany
39 Posts 18 Posters 80 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rysiek@mstdn.socialR rysiek@mstdn.social

    @domi guess what are the NSes for de.net. though…

    ;; ANSWER SECTION:
    de.net. 86400 IN NS ns1.denic.de.
    de.net. 86400 IN NS ns2.denic.de.
    de.net. 86400 IN NS ns3.denic.de.
    de.net. 86400 IN NS ns4.denic.net.

    domi@donotsta.reD This user is from outside of this forum
    domi@donotsta.reD This user is from outside of this forum
    domi@donotsta.re
    wrote last edited by
    #16

    @rysiek@mstdn.social well, but denic.net has glue records. and so does de.net. so those fields don't really matter much, it's still resolvable

    rysiek@mstdn.socialR 1 Reply Last reply
    0
    • rysiek@mstdn.socialR rysiek@mstdn.social

      Looks like DE ccTLD is unresolvable due to DNSSEC issue:
      https://dnsviz.net/d/nic.de/dnssec/

      😬

      #InfoSec #DNSSEC #DNS #Germany

      tris@chaos.socialT This user is from outside of this forum
      tris@chaos.socialT This user is from outside of this forum
      tris@chaos.social
      wrote last edited by
      #17

      @rysiek cc: @Tutanota

      1 Reply Last reply
      0
      • domi@donotsta.reD domi@donotsta.re

        @rysiek@mstdn.social well, but denic.net has glue records. and so does de.net. so those fields don't really matter much, it's still resolvable

        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.social
        wrote last edited by
        #18

        @domi fair enough

        1 Reply Last reply
        0
        • rysiek@mstdn.socialR rysiek@mstdn.social

          Because it is DNS, everything is cached on multiple levels. Because there are nameservers in different TLDs (which is the correct thing to do!), combined with cache invalidation fun, this will keep looking like intermittent failures for a while most probably.

          rysiek@mstdn.socialR This user is from outside of this forum
          rysiek@mstdn.socialR This user is from outside of this forum
          rysiek@mstdn.social
          wrote last edited by
          #19

          DENIC's status page:
          https://status.denic.de/

          Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

          #DNS #DENIC #DNSSEC #InfoSec #SysAdmin

          Link Preview Image
          rysiek@mstdn.socialR tsia_@chaos.socialT 2 Replies Last reply
          1
          0
          • rysiek@mstdn.socialR rysiek@mstdn.social

            DENIC's status page:
            https://status.denic.de/

            Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

            #DNS #DENIC #DNSSEC #InfoSec #SysAdmin

            Link Preview Image
            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.social
            wrote last edited by
            #20

            Here's a thought:

            The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

            #DNS #InfoSec #SysAdmin

            vincent@knuddelweide.deV jpmens@mastodon.socialJ yetzt@social.yetzt.meY emily@mastodon.deE 4 Replies Last reply
            0
            • rysiek@mstdn.socialR rysiek@mstdn.social

              Looks like DE ccTLD is unresolvable due to DNSSEC issue:
              https://dnsviz.net/d/nic.de/dnssec/

              😬

              #InfoSec #DNSSEC #DNS #Germany

              stekopf@mstdn.socialS This user is from outside of this forum
              stekopf@mstdn.socialS This user is from outside of this forum
              stekopf@mstdn.social
              wrote last edited by
              #21

              @rysiek

              From a users perspective some .de domains are not available on one connection but on another connection?

              At least that's what I'm experiencing currently.

              rysiek@mstdn.socialR 1 Reply Last reply
              0
              • rysiek@mstdn.socialR rysiek@mstdn.social

                Here's a thought:

                The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                #DNS #InfoSec #SysAdmin

                vincent@knuddelweide.deV This user is from outside of this forum
                vincent@knuddelweide.deV This user is from outside of this forum
                vincent@knuddelweide.de
                wrote last edited by
                #22

                @rysiek@mstdn.social True experts questioned their home infra first, because that is obviously the most stable culprit ​​

                emily@mastodon.deE 1 Reply Last reply
                0
                • stekopf@mstdn.socialS stekopf@mstdn.social

                  @rysiek

                  From a users perspective some .de domains are not available on one connection but on another connection?

                  At least that's what I'm experiencing currently.

                  rysiek@mstdn.socialR This user is from outside of this forum
                  rysiek@mstdn.socialR This user is from outside of this forum
                  rysiek@mstdn.social
                  wrote last edited by
                  #23

                  @stekopf read the thread, I explain why this is going to feel intermittent

                  1 Reply Last reply
                  0
                  • rysiek@mstdn.socialR rysiek@mstdn.social

                    Here's a thought:

                    The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                    #DNS #InfoSec #SysAdmin

                    jpmens@mastodon.socialJ This user is from outside of this forum
                    jpmens@mastodon.socialJ This user is from outside of this forum
                    jpmens@mastodon.social
                    wrote last edited by
                    #24

                    @rysiek the last failure of DE I recall was in May (hmm) 2010 (or 2012) when the zone exporter failed because of a file-system full error which wasn’t caught before the zone was shipped out to DE’s secondaries. That caused (alphabetically) all zones > a certain letter (ISTR it was ‘m’) to fail. Quite funny on one hand, sad on another, and hugely embarrassing to the DENIC people 🙂

                    rysiek@mstdn.socialR 1 Reply Last reply
                    0
                    • rysiek@mstdn.socialR rysiek@mstdn.social

                      At this moment, please send #HugOps to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

                      #DNS #DENIC

                      extmind@chaos.socialE This user is from outside of this forum
                      extmind@chaos.socialE This user is from outside of this forum
                      extmind@chaos.social
                      wrote last edited by
                      #25

                      @rysiek Good pun. 🙂

                      rysiek@mstdn.socialR 1 Reply Last reply
                      0
                      • jpmens@mastodon.socialJ jpmens@mastodon.social

                        @rysiek the last failure of DE I recall was in May (hmm) 2010 (or 2012) when the zone exporter failed because of a file-system full error which wasn’t caught before the zone was shipped out to DE’s secondaries. That caused (alphabetically) all zones > a certain letter (ISTR it was ‘m’) to fail. Quite funny on one hand, sad on another, and hugely embarrassing to the DENIC people 🙂

                        rysiek@mstdn.socialR This user is from outside of this forum
                        rysiek@mstdn.socialR This user is from outside of this forum
                        rysiek@mstdn.social
                        wrote last edited by
                        #26

                        @jpmens any public failure of a TLD, especially a ccTLD, is hugely embarrassing…

                        1 Reply Last reply
                        0
                        • extmind@chaos.socialE extmind@chaos.social

                          @rysiek Good pun. 🙂

                          rysiek@mstdn.socialR This user is from outside of this forum
                          rysiek@mstdn.socialR This user is from outside of this forum
                          rysiek@mstdn.social
                          wrote last edited by
                          #27

                          @extmind what pun?

                          extmind@chaos.socialE 1 Reply Last reply
                          0
                          • rysiek@mstdn.socialR rysiek@mstdn.social

                            @extmind what pun?

                            extmind@chaos.socialE This user is from outside of this forum
                            extmind@chaos.socialE This user is from outside of this forum
                            extmind@chaos.social
                            wrote last edited by
                            #28

                            @rysiek ...to *resolve* it as soon as possible.

                            rysiek@mstdn.socialR 1 Reply Last reply
                            0
                            • rysiek@mstdn.socialR rysiek@mstdn.social

                              Here's a thought:

                              The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                              #DNS #InfoSec #SysAdmin

                              yetzt@social.yetzt.meY This user is from outside of this forum
                              yetzt@social.yetzt.meY This user is from outside of this forum
                              yetzt@social.yetzt.me
                              wrote last edited by
                              #29

                              @rysiek last notable outage at denic was almost 16 years ago, when they moved servers from amsterdam to frankfurt.

                              rysiek@mstdn.socialR dergrobi@nrw.socialD 2 Replies Last reply
                              1
                              0
                              • extmind@chaos.socialE extmind@chaos.social

                                @rysiek ...to *resolve* it as soon as possible.

                                rysiek@mstdn.socialR This user is from outside of this forum
                                rysiek@mstdn.socialR This user is from outside of this forum
                                rysiek@mstdn.social
                                wrote last edited by
                                #30

                                @extmind oh damn! I did not do this on purpose. ha!

                                1 Reply Last reply
                                0
                                • yetzt@social.yetzt.meY yetzt@social.yetzt.me

                                  @rysiek last notable outage at denic was almost 16 years ago, when they moved servers from amsterdam to frankfurt.

                                  rysiek@mstdn.socialR This user is from outside of this forum
                                  rysiek@mstdn.socialR This user is from outside of this forum
                                  rysiek@mstdn.social
                                  wrote last edited by
                                  #31

                                  @yetzt this is… how many nines?

                                  yetzt@social.yetzt.meY 1 Reply Last reply
                                  1
                                  0
                                  • rysiek@mstdn.socialR rysiek@mstdn.social

                                    @yetzt this is… how many nines?

                                    yetzt@social.yetzt.meY This user is from outside of this forum
                                    yetzt@social.yetzt.meY This user is from outside of this forum
                                    yetzt@social.yetzt.me
                                    wrote last edited by
                                    #32

                                    @rysiek https://youtu.be/v07H0Px_2UM

                                    rysiek@mstdn.socialR 1 Reply Last reply
                                    1
                                    0
                                    • yetzt@social.yetzt.meY yetzt@social.yetzt.me

                                      @rysiek https://youtu.be/v07H0Px_2UM

                                      rysiek@mstdn.socialR This user is from outside of this forum
                                      rysiek@mstdn.socialR This user is from outside of this forum
                                      rysiek@mstdn.social
                                      wrote last edited by
                                      #33

                                      @yetzt I ded.

                                      1 Reply Last reply
                                      1
                                      0
                                      • yetzt@social.yetzt.meY yetzt@social.yetzt.me

                                        @rysiek last notable outage at denic was almost 16 years ago, when they moved servers from amsterdam to frankfurt.

                                        dergrobi@nrw.socialD This user is from outside of this forum
                                        dergrobi@nrw.socialD This user is from outside of this forum
                                        dergrobi@nrw.social
                                        wrote last edited by
                                        #34

                                        @yetzt Since that day, all my domains have name servers assigned, which are under two distinct TLDs. And this is the reason, that all my domains (except for .de) still resolve at the moment.

                                        1 Reply Last reply
                                        0
                                        • rysiek@mstdn.socialR rysiek@mstdn.social

                                          DENIC's status page:
                                          https://status.denic.de/

                                          Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                          #DNS #DENIC #DNSSEC #InfoSec #SysAdmin

                                          Link Preview Image
                                          tsia_@chaos.socialT This user is from outside of this forum
                                          tsia_@chaos.socialT This user is from outside of this forum
                                          tsia_@chaos.social
                                          wrote last edited by
                                          #35

                                          @rysiek fortunately the status page can still be accessed via https://denic.status.io

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups