Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Looks like DE ccTLD is unresolvable due to DNSSEC issue:https://dnsviz.net/d/nic.de/dnssec/

Looks like DE ccTLD is unresolvable due to DNSSEC issue:https://dnsviz.net/d/nic.de/dnssec/

Scheduled Pinned Locked Moved Uncategorized
infosecdnssecdnsgermany
39 Posts 18 Posters 80 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rysiek@mstdn.socialR This user is from outside of this forum
    rysiek@mstdn.socialR This user is from outside of this forum
    rysiek@mstdn.social
    wrote last edited by
    #1

    Looks like DE ccTLD is unresolvable due to DNSSEC issue:
    https://dnsviz.net/d/nic.de/dnssec/

    😬

    #InfoSec #DNSSEC #DNS #Germany

    nemo@mas.toN rysiek@mstdn.socialR dwm@mastodon.socialD tris@chaos.socialT stekopf@mstdn.socialS 6 Replies Last reply
    2
    0
    • rysiek@mstdn.socialR rysiek@mstdn.social

      Looks like DE ccTLD is unresolvable due to DNSSEC issue:
      https://dnsviz.net/d/nic.de/dnssec/

      😬

      #InfoSec #DNSSEC #DNS #Germany

      nemo@mas.toN This user is from outside of this forum
      nemo@mas.toN This user is from outside of this forum
      nemo@mas.to
      wrote last edited by
      #2

      @rysiek yeah there is some weird sh!t going on lately yesterday when I checked dnscheck.tools and also mullvad.net/en/check I got the firts time an DNS error. Not quite sure what to make out of that 🤔

      1 Reply Last reply
      0
      • R relay@relay.infosec.exchange shared this topic
      • rysiek@mstdn.socialR rysiek@mstdn.social

        Looks like DE ccTLD is unresolvable due to DNSSEC issue:
        https://dnsviz.net/d/nic.de/dnssec/

        😬

        #InfoSec #DNSSEC #DNS #Germany

        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.social
        wrote last edited by
        #3

        If I am reading this correctly – and I might not, it's been a long day – the issue is not directly with DE itself, but with nic.de.

        Which doesn't necessarily make it much better.

        rysiek@mstdn.socialR 1 Reply Last reply
        0
        • rysiek@mstdn.socialR rysiek@mstdn.social

          If I am reading this correctly – and I might not, it's been a long day – the issue is not directly with DE itself, but with nic.de.

          Which doesn't necessarily make it much better.

          rysiek@mstdn.socialR This user is from outside of this forum
          rysiek@mstdn.socialR This user is from outside of this forum
          rysiek@mstdn.social
          wrote last edited by
          #4

          And that's why it doesn't make it much better:

          ;; ANSWER SECTION:
          de. 86400 IN NS a.nic.de.
          de. 86400 IN NS f.nic.de.
          de. 86400 IN NS l.de.net.
          de. 86400 IN NS n.de.net.
          de. 86400 IN NS s.de.net.
          de. 86400 IN NS z.nic.de.

          If nic.de. is down, nameservers in nic.de. are down. Which will cause issues for DE.

          rysiek@mstdn.socialR packetcat@tenforward.socialP domi@donotsta.reD 3 Replies Last reply
          0
          • rysiek@mstdn.socialR rysiek@mstdn.social

            And that's why it doesn't make it much better:

            ;; ANSWER SECTION:
            de. 86400 IN NS a.nic.de.
            de. 86400 IN NS f.nic.de.
            de. 86400 IN NS l.de.net.
            de. 86400 IN NS n.de.net.
            de. 86400 IN NS s.de.net.
            de. 86400 IN NS z.nic.de.

            If nic.de. is down, nameservers in nic.de. are down. Which will cause issues for DE.

            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.social
            wrote last edited by
            #5

            At this moment, please send #HugOps to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

            #DNS #DENIC

            rysiek@mstdn.socialR wall_e@ioc.exchangeW extmind@chaos.socialE 3 Replies Last reply
            0
            • rysiek@mstdn.socialR rysiek@mstdn.social

              And that's why it doesn't make it much better:

              ;; ANSWER SECTION:
              de. 86400 IN NS a.nic.de.
              de. 86400 IN NS f.nic.de.
              de. 86400 IN NS l.de.net.
              de. 86400 IN NS n.de.net.
              de. 86400 IN NS s.de.net.
              de. 86400 IN NS z.nic.de.

              If nic.de. is down, nameservers in nic.de. are down. Which will cause issues for DE.

              packetcat@tenforward.socialP This user is from outside of this forum
              packetcat@tenforward.socialP This user is from outside of this forum
              packetcat@tenforward.social
              wrote last edited by
              #6

              @rysiek its causing a cascading failure onto de.net as well since de.net uses nic.de for nameservers.

              rysiek@mstdn.socialR 1 Reply Last reply
              0
              • packetcat@tenforward.socialP packetcat@tenforward.social

                @rysiek its causing a cascading failure onto de.net as well since de.net uses nic.de for nameservers.

                rysiek@mstdn.socialR This user is from outside of this forum
                rysiek@mstdn.socialR This user is from outside of this forum
                rysiek@mstdn.social
                wrote last edited by
                #7

                @packetcat ooof.

                There is going to be a lot of stuff to learn from the post-mortem.

                dalias@hachyderm.ioD 1 Reply Last reply
                0
                • R relay@relay.mycrowd.ca shared this topic
                • rysiek@mstdn.socialR rysiek@mstdn.social

                  Looks like DE ccTLD is unresolvable due to DNSSEC issue:
                  https://dnsviz.net/d/nic.de/dnssec/

                  😬

                  #InfoSec #DNSSEC #DNS #Germany

                  dwm@mastodon.socialD This user is from outside of this forum
                  dwm@mastodon.socialD This user is from outside of this forum
                  dwm@mastodon.social
                  wrote last edited by
                  #8

                  @rysiek Also looks like dnsviz.net has been hugged to death by everyone hitting it.

                  1 Reply Last reply
                  0
                  • rysiek@mstdn.socialR rysiek@mstdn.social

                    At this moment, please send #HugOps to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

                    #DNS #DENIC

                    rysiek@mstdn.socialR This user is from outside of this forum
                    rysiek@mstdn.socialR This user is from outside of this forum
                    rysiek@mstdn.social
                    wrote last edited by
                    #9

                    Because it is DNS, everything is cached on multiple levels. Because there are nameservers in different TLDs (which is the correct thing to do!), combined with cache invalidation fun, this will keep looking like intermittent failures for a while most probably.

                    sqrt2@chaos.socialS rysiek@mstdn.socialR 2 Replies Last reply
                    0
                    • rysiek@mstdn.socialR rysiek@mstdn.social

                      And that's why it doesn't make it much better:

                      ;; ANSWER SECTION:
                      de. 86400 IN NS a.nic.de.
                      de. 86400 IN NS f.nic.de.
                      de. 86400 IN NS l.de.net.
                      de. 86400 IN NS n.de.net.
                      de. 86400 IN NS s.de.net.
                      de. 86400 IN NS z.nic.de.

                      If nic.de. is down, nameservers in nic.de. are down. Which will cause issues for DE.

                      domi@donotsta.reD This user is from outside of this forum
                      domi@donotsta.reD This user is from outside of this forum
                      domi@donotsta.re
                      wrote last edited by
                      #10

                      @rysiek@mstdn.social i mean, they do have de.net, so it's not an irrepairable level of a fuckup

                      don't look at dig NS pl now...

                      rysiek@mstdn.socialR 1 Reply Last reply
                      0
                      • rysiek@mstdn.socialR rysiek@mstdn.social

                        At this moment, please send #HugOps to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

                        #DNS #DENIC

                        wall_e@ioc.exchangeW This user is from outside of this forum
                        wall_e@ioc.exchangeW This user is from outside of this forum
                        wall_e@ioc.exchange
                        wrote last edited by
                        #11

                        @rysiek while I'm taking this as a cue to just go to bed and leave computering for tomorrow... RIP to all the shoddily written automations and batch jobs that will fail tonight 🫡
                        May their knock-on effects be mild tomorrow

                        rysiek@mstdn.socialR 1 Reply Last reply
                        0
                        • rysiek@mstdn.socialR This user is from outside of this forum
                          rysiek@mstdn.socialR This user is from outside of this forum
                          rysiek@mstdn.social
                          wrote last edited by
                          #12

                          @varbin yeah, this might keep looking like an intermittent failure for a while

                          1 Reply Last reply
                          0
                          • wall_e@ioc.exchangeW wall_e@ioc.exchange

                            @rysiek while I'm taking this as a cue to just go to bed and leave computering for tomorrow... RIP to all the shoddily written automations and batch jobs that will fail tonight 🫡
                            May their knock-on effects be mild tomorrow

                            rysiek@mstdn.socialR This user is from outside of this forum
                            rysiek@mstdn.socialR This user is from outside of this forum
                            rysiek@mstdn.social
                            wrote last edited by
                            #13

                            @wall_e

                            1 Reply Last reply
                            0
                            • domi@donotsta.reD domi@donotsta.re

                              @rysiek@mstdn.social i mean, they do have de.net, so it's not an irrepairable level of a fuckup

                              don't look at dig NS pl now...

                              rysiek@mstdn.socialR This user is from outside of this forum
                              rysiek@mstdn.socialR This user is from outside of this forum
                              rysiek@mstdn.social
                              wrote last edited by
                              #14

                              @domi guess what are the NSes for de.net. though…

                              ;; ANSWER SECTION:
                              de.net. 86400 IN NS ns1.denic.de.
                              de.net. 86400 IN NS ns2.denic.de.
                              de.net. 86400 IN NS ns3.denic.de.
                              de.net. 86400 IN NS ns4.denic.net.

                              domi@donotsta.reD 1 Reply Last reply
                              0
                              • rysiek@mstdn.socialR rysiek@mstdn.social

                                Because it is DNS, everything is cached on multiple levels. Because there are nameservers in different TLDs (which is the correct thing to do!), combined with cache invalidation fun, this will keep looking like intermittent failures for a while most probably.

                                sqrt2@chaos.socialS This user is from outside of this forum
                                sqrt2@chaos.socialS This user is from outside of this forum
                                sqrt2@chaos.social
                                wrote last edited by
                                #15

                                @rysiek Why are the nic.de servers' addresses not glued to the root zone? I thought that was standard practice even if you have nameservers in other zones, too

                                1 Reply Last reply
                                0
                                • rysiek@mstdn.socialR rysiek@mstdn.social

                                  @domi guess what are the NSes for de.net. though…

                                  ;; ANSWER SECTION:
                                  de.net. 86400 IN NS ns1.denic.de.
                                  de.net. 86400 IN NS ns2.denic.de.
                                  de.net. 86400 IN NS ns3.denic.de.
                                  de.net. 86400 IN NS ns4.denic.net.

                                  domi@donotsta.reD This user is from outside of this forum
                                  domi@donotsta.reD This user is from outside of this forum
                                  domi@donotsta.re
                                  wrote last edited by
                                  #16

                                  @rysiek@mstdn.social well, but denic.net has glue records. and so does de.net. so those fields don't really matter much, it's still resolvable

                                  rysiek@mstdn.socialR 1 Reply Last reply
                                  0
                                  • rysiek@mstdn.socialR rysiek@mstdn.social

                                    Looks like DE ccTLD is unresolvable due to DNSSEC issue:
                                    https://dnsviz.net/d/nic.de/dnssec/

                                    😬

                                    #InfoSec #DNSSEC #DNS #Germany

                                    tris@chaos.socialT This user is from outside of this forum
                                    tris@chaos.socialT This user is from outside of this forum
                                    tris@chaos.social
                                    wrote last edited by
                                    #17

                                    @rysiek cc: @Tutanota

                                    1 Reply Last reply
                                    0
                                    • domi@donotsta.reD domi@donotsta.re

                                      @rysiek@mstdn.social well, but denic.net has glue records. and so does de.net. so those fields don't really matter much, it's still resolvable

                                      rysiek@mstdn.socialR This user is from outside of this forum
                                      rysiek@mstdn.socialR This user is from outside of this forum
                                      rysiek@mstdn.social
                                      wrote last edited by
                                      #18

                                      @domi fair enough

                                      1 Reply Last reply
                                      0
                                      • rysiek@mstdn.socialR rysiek@mstdn.social

                                        Because it is DNS, everything is cached on multiple levels. Because there are nameservers in different TLDs (which is the correct thing to do!), combined with cache invalidation fun, this will keep looking like intermittent failures for a while most probably.

                                        rysiek@mstdn.socialR This user is from outside of this forum
                                        rysiek@mstdn.socialR This user is from outside of this forum
                                        rysiek@mstdn.social
                                        wrote last edited by
                                        #19

                                        DENIC's status page:
                                        https://status.denic.de/

                                        Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                        #DNS #DENIC #DNSSEC #InfoSec #SysAdmin

                                        Link Preview Image
                                        rysiek@mstdn.socialR tsia_@chaos.socialT 2 Replies Last reply
                                        1
                                        0
                                        • rysiek@mstdn.socialR rysiek@mstdn.social

                                          DENIC's status page:
                                          https://status.denic.de/

                                          Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                          #DNS #DENIC #DNSSEC #InfoSec #SysAdmin

                                          Link Preview Image
                                          rysiek@mstdn.socialR This user is from outside of this forum
                                          rysiek@mstdn.socialR This user is from outside of this forum
                                          rysiek@mstdn.social
                                          wrote last edited by
                                          #20

                                          Here's a thought:

                                          The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                                          #DNS #InfoSec #SysAdmin

                                          vincent@knuddelweide.deV jpmens@mastodon.socialJ yetzt@social.yetzt.meY emily@mastodon.deE 4 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups