Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. It seems

It seems

Scheduled Pinned Locked Moved Uncategorized
denic
10 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • anthropy@mastodon.derg.nzA This user is from outside of this forum
    anthropy@mastodon.derg.nzA This user is from outside of this forum
    anthropy@mastodon.derg.nz
    wrote last edited by
    #1

    It seems .de is having DNSSEC (and potentially other) issues because nic.de is having issues, which appears to host all their root nameservers. I wish the nic.de peoples much hugs and good luck.

    I wonder what implications this has for other critical infra that may now suddenly be getting DNS failures. I hope it doesn't cascade.

    It really goes to show how fragile the internet is. which is scary given how much we've come to rely on it.

    I think we need more backup infra. meshtastic/etc?

    #denic

    Link Preview Image
    anthropy@mastodon.derg.nzA 1 Reply Last reply
    0
    • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

      It seems .de is having DNSSEC (and potentially other) issues because nic.de is having issues, which appears to host all their root nameservers. I wish the nic.de peoples much hugs and good luck.

      I wonder what implications this has for other critical infra that may now suddenly be getting DNS failures. I hope it doesn't cascade.

      It really goes to show how fragile the internet is. which is scary given how much we've come to rely on it.

      I think we need more backup infra. meshtastic/etc?

      #denic

      Link Preview Image
      anthropy@mastodon.derg.nzA This user is from outside of this forum
      anthropy@mastodon.derg.nzA This user is from outside of this forum
      anthropy@mastodon.derg.nz
      wrote last edited by
      #2

      note that from what I heard it *should* just be DNSSEC related issues, but as far as I can tell entire domains are down, like google.de and amazon.de are completely unreachable even for me.

      edit: it makes sense for domains that use DNSSEC to not reply anything right now. All properly configured domains will have issues as such, whereas non-DNSSEC domains should still be fine (although some people reported issues there too- but I suspect they're all actually DNSSEC-enabled)

      #denic

      Link Preview ImageLink Preview Image
      anthropy@mastodon.derg.nzA sebastian@schottkydio.deS 2 Replies Last reply
      0
      • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

        note that from what I heard it *should* just be DNSSEC related issues, but as far as I can tell entire domains are down, like google.de and amazon.de are completely unreachable even for me.

        edit: it makes sense for domains that use DNSSEC to not reply anything right now. All properly configured domains will have issues as such, whereas non-DNSSEC domains should still be fine (although some people reported issues there too- but I suspect they're all actually DNSSEC-enabled)

        #denic

        Link Preview ImageLink Preview Image
        anthropy@mastodon.derg.nzA This user is from outside of this forum
        anthropy@mastodon.derg.nzA This user is from outside of this forum
        anthropy@mastodon.derg.nz
        wrote last edited by
        #3

        text from status.denic.de (their official statuspage) is saying that they're still investigating and haven't fully identified the root cause yet.

        Link Preview Image
        erik@gnurfl.deE macer@his.macer.lifeM anthropy@mastodon.derg.nzA 3 Replies Last reply
        0
        • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

          note that from what I heard it *should* just be DNSSEC related issues, but as far as I can tell entire domains are down, like google.de and amazon.de are completely unreachable even for me.

          edit: it makes sense for domains that use DNSSEC to not reply anything right now. All properly configured domains will have issues as such, whereas non-DNSSEC domains should still be fine (although some people reported issues there too- but I suspect they're all actually DNSSEC-enabled)

          #denic

          Link Preview ImageLink Preview Image
          sebastian@schottkydio.deS This user is from outside of this forum
          sebastian@schottkydio.deS This user is from outside of this forum
          sebastian@schottkydio.de
          wrote last edited by
          #4

          @anthropy It is just a DNSSEC thing. As far as I have debugged it on my setup every validating resolver (that is every DNS server that actually checks the DNSSEC stuff before replying to you) stumbles upon the broken stuff for .de and returns servfail instead.

          anthropy@mastodon.derg.nzA 1 Reply Last reply
          0
          • sebastian@schottkydio.deS sebastian@schottkydio.de

            @anthropy It is just a DNSSEC thing. As far as I have debugged it on my setup every validating resolver (that is every DNS server that actually checks the DNSSEC stuff before replying to you) stumbles upon the broken stuff for .de and returns servfail instead.

            anthropy@mastodon.derg.nzA This user is from outside of this forum
            anthropy@mastodon.derg.nzA This user is from outside of this forum
            anthropy@mastodon.derg.nz
            wrote last edited by
            #5

            @sebastian yea I was actually about to update the message heh, it makes sense, though some people reported issues beyond dnssec domains, but I suspect those were just secretly actually dnssec-enabled

            sebastian@schottkydio.deS 1 Reply Last reply
            0
            • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

              text from status.denic.de (their official statuspage) is saying that they're still investigating and haven't fully identified the root cause yet.

              Link Preview Image
              erik@gnurfl.deE This user is from outside of this forum
              erik@gnurfl.deE This user is from outside of this forum
              erik@gnurfl.de
              wrote last edited by
              #6

              @anthropy This sounds ... very bad... I thought they had to either rollback an update or deploy certs

              1 Reply Last reply
              0
              • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

                @sebastian yea I was actually about to update the message heh, it makes sense, though some people reported issues beyond dnssec domains, but I suspect those were just secretly actually dnssec-enabled

                sebastian@schottkydio.deS This user is from outside of this forum
                sebastian@schottkydio.deS This user is from outside of this forum
                sebastian@schottkydio.de
                wrote last edited by
                #7

                @anthropy The resolver validates DNSSEC for all the zones in the chain.
                So for www.sebastians-site.de it first checks .de then the zone sebastian-site and www is just a A record in that zone. sebastian-site does not have DNSSEC enabled. Never got around to figuring that out.
                However the de zone pointing the validating resolver to the name server that has the sebastians-site zone, has it's DNSSEC messed up. So the resolver can not trust anything in the .de zone and stops there.

                See https://dnsviz.net/d/sebastians-site.de/dnssec/

                1 Reply Last reply
                0
                • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

                  text from status.denic.de (their official statuspage) is saying that they're still investigating and haven't fully identified the root cause yet.

                  Link Preview Image
                  macer@his.macer.lifeM This user is from outside of this forum
                  macer@his.macer.lifeM This user is from outside of this forum
                  macer@his.macer.life
                  wrote last edited by
                  #8

                  @anthropy some intern who missed patching copyfail on one of the servers is sweating bullets right now.

                  1 Reply Last reply
                  0
                  • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

                    text from status.denic.de (their official statuspage) is saying that they're still investigating and haven't fully identified the root cause yet.

                    Link Preview Image
                    anthropy@mastodon.derg.nzA This user is from outside of this forum
                    anthropy@mastodon.derg.nzA This user is from outside of this forum
                    anthropy@mastodon.derg.nz
                    wrote last edited by
                    #9

                    did.. anyone ever hear what the root cause was of the denic root dns outage? they just kinda removed their status page and I can't find much more about it, it'd be interesting to know, even if I can imagine it's uncomfortable for them to share

                    pileofoxides@critter.cafeP 1 Reply Last reply
                    1
                    0
                    • R relay@relay.infosec.exchange shared this topic
                    • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

                      did.. anyone ever hear what the root cause was of the denic root dns outage? they just kinda removed their status page and I can't find much more about it, it'd be interesting to know, even if I can imagine it's uncomfortable for them to share

                      pileofoxides@critter.cafeP This user is from outside of this forum
                      pileofoxides@critter.cafeP This user is from outside of this forum
                      pileofoxides@critter.cafe
                      wrote last edited by
                      #10

                      @anthropy
                      So far they have this:
                      https://blog.denic.de/en/analysis-of-the-dns-outage-on-5-may-2026/

                      1 Reply Last reply
                      1
                      0
                      • R relay@relay.mycrowd.ca shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups