I'm Shumon Huque. You can read more about me here.

Don't Go Unsigned

At the ICANN 79 DNSSEC & Security Workshop, I gave a talk, with Eric Osterweil, on why you shouldn’t unsign your DNS zone during algorithm rollovers and/or operator changes.

RFC 9471 published

DNS Glue Requirements in Referral Responses has just been published as RFC 9471. Co-authored with Mark Andrews, Paul Wouters, and Duane Wessels.

Website Reboot

It’s finally time to redo my website a bit.

DANE library in Go

I’ve developed a DANE TLS authentication library in Go recently, which is available on Github:

Iterative DNS resolution testing tool

Since I’ve been trapped at home due to the pandemic and have more free time, I’ve recently enhanced my command line iterative DNS resolution testing tool, “resolve.py” to fully support DNSSEC validation. It was quite a bit of work, but I’m pleased with the results so far.

Multi-Signer DNSSEC Models approved as RFC

The Multi-Signer DNSSEC Models draft that I’ve been working on for the past couple of years, has been approved by the IESG (Internet Engineering Steering Group - the overall management arm of the IETF).

NS1 Press Release on Multi-Signer DNSSEC

DNS Company, NS1 today issued a press release on their collaboration with Salesforce (my employer) on the specification and implementation of Multi-Signer DNSSEC, and which has a quotation from me:

APNIC DANE blog

APNIC invited me to write a guest article for their blog, elaborating on my ‘Whither DANE’ lighting talk at the DNS-OARC 30 workshop in May. It just went up yesterday, and you can read it at the following link: