Posts by Tag

dnssec

Don’t Go Unsigned

less than 1 minute read

At the ICANN 79 DNSSEC & Security Workshop, I gave a talk, with Eric Osterweil, on why you shouldn’t unsign your DNS zone during algorithm rollovers and...

RFC 9471 published

less than 1 minute read

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

DNS-OARC talk on DNSSEC Experience

less than 1 minute read

I just returned from the 40th DNS-OARC Workshop in Atlanta, Georgia, a small DNS focussed conference, run by DNS-OARC.

OARC Talk on DANE

less than 1 minute read

I was in Philadelphia for the 38th DNS-OARC Workshop.

RFC 9102 Published (TLS DNSSEC Chain)

less than 1 minute read

RFC 9102: “TLS DNSSEC Chain Extension”, was finally published as “experimental” – a few years after a long, acrimonious battle in the IETF TLS WG to get it p...

Swedish Internet Foundation on Multi-Signer

less than 1 minute read

The Swedish Internet Foundation published an article yesterday, “Solving the decade old problem with Multi-Signer DNSSEC”, mentioning my work and collaborat...

ICANN70 DNSSEC Panel

less than 1 minute read

Recording of the ICANN70 DNSSEC Panel, in which I participated.

RFC 8901 published

less than 1 minute read

Multi-Signer DNSSEC Models has just been published as RFC 8901.

DANE library in Go

less than 1 minute read

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

Iterative DNS resolution testing tool

1 minute read

Since I’ve been trapped at home due to the pandemic and have more free time, I’ve recently enhanced my command line iterative DNS resolution testing tool, “r...

Multi-Signer DNSSEC Models approved as RFC

1 minute read

The Multi-Signer DNSSEC Models draft that I’ve been working on for the past couple of years, has been approved by the IESG (Internet Engineering Steering Gro...

NS1 Press Release on Multi-Signer DNSSEC

less than 1 minute read

DNS Company, NS1 today issued a press release on their collaboration with Salesforce (my employer) on the specification and implementation of Multi-Signer DN...

APNIC DANE blog

less than 1 minute read

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up ...

Whither DANE?

11 minute read

At the recent DNS-OARC workshop, I gave a short talk on current prospects for DANE adoption. This generated a fair amount of subsequent discusion and comment...

Key Transparency for DNSSEC?

6 minute read

At the recent IETF meeting in Toronto, there was an interesting discussion in the trans working group on DNSSEC certificate transparency, and there is a (ver...

EDU Top Level Domain statistics

3 minute read

Some DNS Top Level Domain (TLD) operators publish statistics about their DNS zones. Some others have a zone file access program that allows others to examine...

USENIX interviews - IPv6 and DNSSEC

less than 1 minute read

I’m giving full day tutorials on IPv6 and DNSSEC at the upcoming USENIX LISA conference in Washington DC in November. Matt Simmons interviewed me about both ...

ISC DLV registry usage

5 minute read

On a LinkedIn forum, Dan York of the Internet Society recently asked a question about who still uses the ISC DNSSEC Lookaside Validation (DLV) registry. Whil...

ISOC ION Panel - Advancing the Network

1 minute read

“I tend to think of IPv6 & DNSSEC both a little bit like global warming … something that is developing kind of slowly … they’re both inevitable, it’s a j...

DNSSEC and Certificates

7 minute read

DNSSEC is a system to verify the authenticity of DNS data using public key signatures. With increasing deployment of DNSSEC comes the possibility of applicat...

Back to Top ↑

dns

Don’t Go Unsigned

less than 1 minute read

At the ICANN 79 DNSSEC & Security Workshop, I gave a talk, with Eric Osterweil, on why you shouldn’t unsign your DNS zone during algorithm rollovers and...

Greasing DNS Extension Points

less than 1 minute read

Mark Andrews (ISC) and I have published an initial version of a new Internet Draft on Greasing Protocol Extension Points in the DNS.

RFC 9471 published

less than 1 minute read

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

DNS-OARC talk on DNSSEC Experience

less than 1 minute read

I just returned from the 40th DNS-OARC Workshop in Atlanta, Georgia, a small DNS focussed conference, run by DNS-OARC.

OARC Talk on DANE

less than 1 minute read

I was in Philadelphia for the 38th DNS-OARC Workshop.

RFC 8901 published

less than 1 minute read

Multi-Signer DNSSEC Models has just been published as RFC 8901.

Iterative DNS resolution testing tool

1 minute read

Since I’ve been trapped at home due to the pandemic and have more free time, I’ve recently enhanced my command line iterative DNS resolution testing tool, “r...

Delegation Revalidation by DNS Resolvers

1 minute read

I’ve been working recently on a new IETF draft document on Delegation Revalidation by DNS Resolvers, with collaborators Paul Vixie, CEO of Farsight Security,...

Multi-Signer DNSSEC Models approved as RFC

1 minute read

The Multi-Signer DNSSEC Models draft that I’ve been working on for the past couple of years, has been approved by the IESG (Internet Engineering Steering Gro...

Talks at Fall 2015 DNS-OARC Workshop

less than 1 minute read

I attended the Fall 2015 DNS-OARC workshop in Montreal, Canada earlier this month. DNS-OARC is the “DNS Operations, Analysis, and Research Center”, and the p...

Key Transparency for DNSSEC?

6 minute read

At the recent IETF meeting in Toronto, there was an interesting discussion in the trans working group on DNSSEC certificate transparency, and there is a (ver...

EDU Top Level Domain statistics

3 minute read

Some DNS Top Level Domain (TLD) operators publish statistics about their DNS zones. Some others have a zone file access program that allows others to examine...

DNS Amplification Attacks

10 minute read

There has been a lot of talk recently about DNS amplification attacks (with prominent news reports of high bandwidth attacks targeted at anti-spam services, ...

Penn’s DNS Zone

3 minute read

Some data from a quick analysis of the contents of the University of Pennsylvania’s primary DNS zone (upenn.edu):

IPv6 and DNS Classes I’m Teaching

1 minute read

I’m teaching two half day classes on IPv6 and DNS/DNSSEC at the LOPSA PICC conference (Professional IT Community Conference), being held May 11-12, 2012 in N...

Back to Top ↑

ipv6

An IPv6 Success Story – Galois

2 minute read

The following article was contributed by Paul Heinlein, a systems administrator at Galois. Paul attended my full day IPv6 training course at USENIX LISA 2013...

USENIX interviews - IPv6 and DNSSEC

less than 1 minute read

I’m giving full day tutorials on IPv6 and DNSSEC at the upcoming USENIX LISA conference in Washington DC in November. Matt Simmons interviewed me about both ...

ISOC ION Panel - Advancing the Network

1 minute read

“I tend to think of IPv6 & DNSSEC both a little bit like global warming … something that is developing kind of slowly … they’re both inevitable, it’s a j...

Internet2 IPv6 Panel recap

6 minute read

A few notes from last month’s IPv6 deployment panel at the Fall Internet2 Member Meeting in Philadelphia, which I moderated (October 2nd 2012). Watch the ent...

A Look at World IPv6 Launch Traffic

2 minute read

The World IPv6 Launch website has compiled a set of measurements at http://www.worldipv6launch.org/measurements/. I’ll take a quick look at some of them here...

IPv6 at Penn

8 minute read

World IPv6 Launch (June 6th 2012) is fast approaching, so I thought I’d share some details about IPv6 deployment at the University of Pennsylvania and what w...

IPv6 and DNS Classes I’m Teaching

1 minute read

I’m teaching two half day classes on IPv6 and DNS/DNSSEC at the LOPSA PICC conference (Professional IT Community Conference), being held May 11-12, 2012 in N...

Back to Top ↑

ietf

RFC 9471 published

less than 1 minute read

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

RFC 8901 published

less than 1 minute read

Multi-Signer DNSSEC Models has just been published as RFC 8901.

Multi-Signer DNSSEC Models approved as RFC

1 minute read

The Multi-Signer DNSSEC Models draft that I’ve been working on for the past couple of years, has been approved by the IESG (Internet Engineering Steering Gro...

APNIC DANE blog

less than 1 minute read

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up ...

Whither DANE?

11 minute read

At the recent DNS-OARC workshop, I gave a short talk on current prospects for DANE adoption. This generated a fair amount of subsequent discusion and comment...

IETF102 and Montreal

less than 1 minute read

I was in Montreal this month to attend IETF102 and several side meetings just before it.

Back to Top ↑

dane

OARC Talk on DANE

less than 1 minute read

I was in Philadelphia for the 38th DNS-OARC Workshop.

DANE library in Go

less than 1 minute read

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

APNIC DANE blog

less than 1 minute read

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up ...

Whither DANE?

11 minute read

At the recent DNS-OARC workshop, I gave a short talk on current prospects for DANE adoption. This generated a fair amount of subsequent discusion and comment...

Back to Top ↑

tls

RFC 9102 Published (TLS DNSSEC Chain)

less than 1 minute read

RFC 9102: “TLS DNSSEC Chain Extension”, was finally published as “experimental” – a few years after a long, acrimonious battle in the IETF TLS WG to get it p...

DANE library in Go

less than 1 minute read

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

APNIC DANE blog

less than 1 minute read

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up ...

Whither DANE?

11 minute read

At the recent DNS-OARC workshop, I gave a short talk on current prospects for DANE adoption. This generated a fair amount of subsequent discusion and comment...

Back to Top ↑

upenn

I’ve left Penn for a new job

3 minute read

After more than 20 years of working at Penn (University of Pennsylvania), I’ve decided to take a new job as Principal Research Scientist at Verisign Labs, th...

IPv6 at Penn

8 minute read

World IPv6 Launch (June 6th 2012) is fast approaching, so I thought I’d share some details about IPv6 deployment at the University of Pennsylvania and what w...

Penn’s DNS Zone

3 minute read

Some data from a quick analysis of the contents of the University of Pennsylvania’s primary DNS zone (upenn.edu):

Back to Top ↑

photos

Photos from Rocky Mountains

less than 1 minute read

We went on vacation earlier this month to visit two US National Parks renowned for their spectacular natural scenery: Rocky Mountain National Park in Colorad...

Philadelphia Skyline Photos

less than 1 minute read

My colleague Deke Kassabian posted an older photo of the Philly skyline (that I’d taken a number of years ago) on his Facebook page. So I thought I’d post a ...

Back to Top ↑

national park

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Photos from Rocky Mountains

less than 1 minute read

We went on vacation earlier this month to visit two US National Parks renowned for their spectacular natural scenery: Rocky Mountain National Park in Colorad...

Back to Top ↑

dns-oarc

DNS-OARC talk on DNSSEC Experience

less than 1 minute read

I just returned from the 40th DNS-OARC Workshop in Atlanta, Georgia, a small DNS focussed conference, run by DNS-OARC.

OARC Talk on DANE

less than 1 minute read

I was in Philadelphia for the 38th DNS-OARC Workshop.

Back to Top ↑

networking

IPv6 at Penn

8 minute read

World IPv6 Launch (June 6th 2012) is fast approaching, so I thought I’d share some details about IPv6 deployment at the University of Pennsylvania and what w...

Back to Top ↑

internet2

Internet2 IPv6 Panel recap

6 minute read

A few notes from last month’s IPv6 deployment panel at the Fall Internet2 Member Meeting in Philadelphia, which I moderated (October 2nd 2012). Watch the ent...

Back to Top ↑

privacy

Back to Top ↑

zoo

San Diego Trip

less than 1 minute read

I was in San Diego for a few days. The first day I visited the San Diego zoo, widely considered to be one the best. The second day I rented a car and drove o...

Singapore Zoo

less than 1 minute read

Photos from the Singapore Zoo, which I visited with some IETF100 colleagues, on Nov 17th 2017.

Back to Top ↑

website

Website Reboot

less than 1 minute read

It’s finally time to redo my website a bit.

Website reboot

less than 1 minute read

I’ve redone my website, something I’ve been planning to do for quite a while. I’m now using the Pelican static site generator. Over the next few days, I will...

Back to Top ↑

web

APNIC DANE blog

less than 1 minute read

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up ...

Whither DANE?

11 minute read

At the recent DNS-OARC workshop, I gave a short talk on current prospects for DANE adoption. This generated a fair amount of subsequent discusion and comment...

Back to Top ↑

salesforce

DNS-OARC talk on DNSSEC Experience

less than 1 minute read

I just returned from the 40th DNS-OARC Workshop in Atlanta, Georgia, a small DNS focussed conference, run by DNS-OARC.

NS1 Press Release on Multi-Signer DNSSEC

less than 1 minute read

DNS Company, NS1 today issued a press release on their collaboration with Salesforce (my employer) on the specification and implementation of Multi-Signer DN...

Back to Top ↑

software

DANE library in Go

less than 1 minute read

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

Iterative DNS resolution testing tool

1 minute read

Since I’ve been trapped at home due to the pandemic and have more free time, I’ve recently enhanced my command line iterative DNS resolution testing tool, “r...

Back to Top ↑

job

Back to Top ↑

stanford

Stanford Linear Accelerator Tour

1 minute read

At the recent Joint Techs conference, our host Stanford University arranged a lunch time tour of the Stanford Linear Accelerator Center (SLAC) for a small gr...

Back to Top ↑

accelerator

Stanford Linear Accelerator Tour

1 minute read

At the recent Joint Techs conference, our host Stanford University arranged a lunch time tour of the Stanford Linear Accelerator Center (SLAC) for a small gr...

Back to Top ↑

physics

Stanford Linear Accelerator Tour

1 minute read

At the recent Joint Techs conference, our host Stanford University arranged a lunch time tour of the Stanford Linear Accelerator Center (SLAC) for a small gr...

Back to Top ↑

pki

DNSSEC and Certificates

7 minute read

DNSSEC is a system to verify the authenticity of DNS data using public key signatures. With increasing deployment of DNSSEC comes the possibility of applicat...

Back to Top ↑

philadelphia

Philadelphia Skyline Photos

less than 1 minute read

My colleague Deke Kassabian posted an older photo of the Philly skyline (that I’d taken a number of years ago) on his Facebook page. So I thought I’d post a ...

Back to Top ↑

amplification

DNS Amplification Attacks

10 minute read

There has been a lot of talk recently about DNS amplification attacks (with prominent news reports of high bandwidth attacks targeted at anti-spam services, ...

Back to Top ↑

dlv

ISC DLV registry usage

5 minute read

On a LinkedIn forum, Dan York of the Internet Society recently asked a question about who still uses the ISC DNSSEC Lookaside Validation (DLV) registry. Whil...

Back to Top ↑

usenix

USENIX interviews - IPv6 and DNSSEC

less than 1 minute read

I’m giving full day tutorials on IPv6 and DNSSEC at the upcoming USENIX LISA conference in Washington DC in November. Matt Simmons interviewed me about both ...

Back to Top ↑

verisign

I’ve left Penn for a new job

3 minute read

After more than 20 years of working at Penn (University of Pennsylvania), I’ve decided to take a new job as Principal Research Scientist at Verisign Labs, th...

Back to Top ↑

oarc

Talks at Fall 2015 DNS-OARC Workshop

less than 1 minute read

I attended the Fall 2015 DNS-OARC workshop in Montreal, Canada earlier this month. DNS-OARC is the “DNS Operations, Analysis, and Research Center”, and the p...

Back to Top ↑

singapore

Singapore Zoo

less than 1 minute read

Photos from the Singapore Zoo, which I visited with some IETF100 colleagues, on Nov 17th 2017.

Back to Top ↑

village

Srimongol Village visit

less than 1 minute read

We visited (completely unannounced) a small village in Srimongol, Bangladesh on this day. The locals (and especially the kids) were delighted to see us. And ...

Back to Top ↑

bangladesh

Srimongol Village visit

less than 1 minute read

We visited (completely unannounced) a small village in Srimongol, Bangladesh on this day. The locals (and especially the kids) were delighted to see us. And ...

Back to Top ↑

arecibo

Arecibo Observatory

less than 1 minute read

I’m in Puerto Rico for the DNS-OARC Workshop and ICANN 61 meeting. Yesterday, with some conference friends, we visited the world famous Arecibo Observatory. ...

Back to Top ↑

observatory

Arecibo Observatory

less than 1 minute read

I’m in Puerto Rico for the DNS-OARC Workshop and ICANN 61 meeting. Yesterday, with some conference friends, we visited the world famous Arecibo Observatory. ...

Back to Top ↑

puerto rico

Arecibo Observatory

less than 1 minute read

I’m in Puerto Rico for the DNS-OARC Workshop and ICANN 61 meeting. Yesterday, with some conference friends, we visited the world famous Arecibo Observatory. ...

Back to Top ↑

astronomy

Arecibo Observatory

less than 1 minute read

I’m in Puerto Rico for the DNS-OARC Workshop and ICANN 61 meeting. Yesterday, with some conference friends, we visited the world famous Arecibo Observatory. ...

Back to Top ↑

london

Around London with my brother

less than 1 minute read

I’ve been in London for nearly a week and a half for the IETF 101 meeting, and stayed the weekend after to visit and catch up with my (many) relatives here. ...

Back to Top ↑

sightseeing

Around London with my brother

less than 1 minute read

I’ve been in London for nearly a week and a half for the IETF 101 meeting, and stayed the weekend after to visit and catch up with my (many) relatives here. ...

Back to Top ↑

volunteering

Volunteer Time at Spirit Open Equestrian

less than 1 minute read

With work colleagues, I recently did some volunteering work at a local non-profit, Spirit Open Equestrian, which offers numerous healing programs involving t...

Back to Top ↑

equestrian

Volunteer Time at Spirit Open Equestrian

less than 1 minute read

With work colleagues, I recently did some volunteering work at a local non-profit, Spirit Open Equestrian, which offers numerous healing programs involving t...

Back to Top ↑

horses

Volunteer Time at Spirit Open Equestrian

less than 1 minute read

With work colleagues, I recently did some volunteering work at a local non-profit, Spirit Open Equestrian, which offers numerous healing programs involving t...

Back to Top ↑

montreal

IETF102 and Montreal

less than 1 minute read

I was in Montreal this month to attend IETF102 and several side meetings just before it.

Back to Top ↑

vacation

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Back to Top ↑

canada

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Back to Top ↑

rockies

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Back to Top ↑

banff

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Back to Top ↑

jasper

Banff and Jasper Vacation

less than 1 minute read

We visited Banff and Jasper National Parks in the Canadian Rockies earlier this month. It was unusually cool for this time of year, even for the Canadian Roc...

Back to Top ↑

san diego

San Diego Trip

less than 1 minute read

I was in San Diego for a few days. The first day I visited the San Diego zoo, widely considered to be one the best. The second day I rented a car and drove o...

Back to Top ↑

anza borrego desert

San Diego Trip

less than 1 minute read

I was in San Diego for a few days. The first day I visited the San Diego zoo, widely considered to be one the best. The second day I rented a car and drove o...

Back to Top ↑

state park

San Diego Trip

less than 1 minute read

I was in San Diego for a few days. The first day I visited the San Diego zoo, widely considered to be one the best. The second day I rented a car and drove o...

Back to Top ↑

ns1

NS1 Press Release on Multi-Signer DNSSEC

less than 1 minute read

DNS Company, NS1 today issued a press release on their collaboration with Salesforce (my employer) on the specification and implementation of Multi-Signer DN...

Back to Top ↑

resolver

Delegation Revalidation by DNS Resolvers

1 minute read

I’ve been working recently on a new IETF draft document on Delegation Revalidation by DNS Resolvers, with collaborators Paul Vixie, CEO of Farsight Security,...

Back to Top ↑

delegation

Delegation Revalidation by DNS Resolvers

1 minute read

I’ve been working recently on a new IETF draft document on Delegation Revalidation by DNS Resolvers, with collaborators Paul Vixie, CEO of Farsight Security,...

Back to Top ↑

revalidation

Delegation Revalidation by DNS Resolvers

1 minute read

I’ve been working recently on a new IETF draft document on Delegation Revalidation by DNS Resolvers, with collaborators Paul Vixie, CEO of Farsight Security,...

Back to Top ↑

golang

DANE library in Go

less than 1 minute read

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

Back to Top ↑

evolution

Back to Top ↑

rfc

RFC 9471 published

less than 1 minute read

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

Back to Top ↑

glue

RFC 9471 published

less than 1 minute read

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

Back to Top ↑

provisioning

Back to Top ↑

automation

Back to Top ↑

extension

Greasing DNS Extension Points

less than 1 minute read

Mark Andrews (ISC) and I have published an initial version of a new Internet Draft on Greasing Protocol Extension Points in the DNS.

Back to Top ↑

points

Greasing DNS Extension Points

less than 1 minute read

Mark Andrews (ISC) and I have published an initial version of a new Internet Draft on Greasing Protocol Extension Points in the DNS.

Back to Top ↑

greasing

Greasing DNS Extension Points

less than 1 minute read

Mark Andrews (ISC) and I have published an initial version of a new Internet Draft on Greasing Protocol Extension Points in the DNS.

Back to Top ↑

unsigning

Don’t Go Unsigned

less than 1 minute read

At the ICANN 79 DNSSEC & Security Workshop, I gave a talk, with Eric Osterweil, on why you shouldn’t unsign your DNS zone during algorithm rollovers and...

Back to Top ↑