DNS/DNSSEC/DPRIV E IETF 96 Hackathon Problem Solved – DNS security and privacy enhancements and interoperabilty Method of Solution – multiple user stories,

Slides:



Advertisements
Similar presentations
12 October 2011 Andrew Brown IMu Technology EMu Global Users Group 12 October 2011 IMu Technology.
Advertisements

Copyright Hub Software Engineering Ltd 2010All rights reserved Hub Workflow Product Overview.
Copyright Hub Software Engineering Ltd 2010All rights reserved Hub Document Manager Product Overview.
Martin Winter & Ondrej Filip RIPE 68, Wed May 14, :00-10:30.
State of DNS Security Extensions Edward Lewis February 26, 2001 APRICOT 2001 Panel.
Project Implementation for COSC 5050 Distributed Database Applications Lab1.
Host Identity Protocol
Olaf M. Kolkman. Apricot 2003, February 2003, Amsterdam. /disi Steps towards a secured DNS Olaf M. Kolkman, Henk Uijterwaal, Daniel.
Data You Can Trust: The Key to Information Security Dr. Burt Kaliski, Jr. Senior Vice President and CTO, Verisign 25 th HP Information Security Colloquium.
- The Event Intelligence Platform Smarter Events for Exhibitors, Organizers & Attendees Making the most out of Zerista Company Confidential – Do Not Reproduce.
1 A Common API for Transparent Hybrid Multicast (draft-waehlisch-sam-common-api-04) Matthias Wählisch, Thomas C. Schmidt Stig Venaas {waehlisch,
Fall, Privacy&Security - Virginia Tech – Computer Science Click to edit Master title style Design Extensions to Google+ CS6204 Privacy and Security.
DIRAC Web User Interface A.Casajus (Universitat de Barcelona) M.Sapunov (CPPM Marseille) On behalf of the LHCb DIRAC Team.
Project Proposal: CTS2 SDK Presentation to OHT Steering Committee.
Database Update Kaveh Ranjbar Database Department Manager, RIPE NCC.
Software for the SAM RG Community IETF 83 Thomas Schmidt
Root Zone KSK: The Road Ahead Edward Lewis | DNS-OARC & RIPE DNSWG | May 2015
FP6−2004−Infrastructures−6-SSA IPv6 in the EGEE Related Projects: the EUChinaGRID experience Gabriella Paolini – GARR.
BTW ”If you go, my advice to you” - Distributed Software Development.
Joint Techs, Albuquerque Feb © 8 Feb 2006 Stichting NLnet Labs DNS Risks, DNSSEC Olaf M. Kolkman and Allison Mankin
6to4 Provider Managed Tunnels draft-kuarsingh-v6ops-6to4-provider-managed-tunnel-02 Victor Kuarsingh, Rogers Communications Inc.
AU, March 2, DNSSEC, APNIC, & how EPP might play a Role Ed Lewis DNS SIG APNIC 21.
DGC Paris WP2 Summary of Discussions and Plans Peter Z. Kunszt And the WP2 team.
BTW ”If you go, my advice to you” - Distributed Software Development.
1. 2 Google Session 1.About MIT’s Google Search Appliance (GSA) 2.Adding Google search to your web site 3.Customizing search results 4.Tips on improving.
Engineering Report Mark Kosters. Staffing Operations – 7 operations engineers + 2 managers (AT FULL STRENGTH) Development – 8 programmers + manager (AT.
18-1 Summary (Day 2) Learning Summary – What is JXTA ? – Understand the fundamental concepts of JXTA – Learn about the various implementations of.
Google Code Libraries Dima Ionut Daniel. Contents What is Google Code? LDAPBeans Object-ldap-mapping Ldap-ODM Bug4j jOOR Rapa jongo Conclusion Bibliography.
Lab 301 Populating Template Data from a Third Party Data Source Justin Pava, Software Release Manager Andrew Schoonmaker, Software QA Engineer.
Thinking of Drupal 8? Get started with the resources.
Prepare for Liftoff Jetpack & the Future of Add-on Development.
D-Bus and Friends: Making Linux “Just Work” on the Desktop John (J5) Palmieri Desktop Engineer
DNS Risks, DNSSEC Olaf M. Kolkman and Allison Mankin
Gridpp37 – 31/08/2016 George Ryall David Meredith
Top 8 Best Programming Languages To Learn
DNS Team IETF 99 Hackathon.
CAcert A Communities Way To Professionalism
Google Web Toolkit Tutorial
Line of Business Solutions in SharePoint Online
IETF 97th SUPA Working Group
BOSS: the CMS interface for job summission, monitoring and bookkeeping
BOSS: the CMS interface for job summission, monitoring and bookkeeping
DNS Privacy: Problem and solutions
IETF 55 IPv6 Working Group IPv6 Node Requirements
Living on the Edge: (Re)focus DNS Efforts on the End-Points
The Importance of Being an Earnest stub
BOSS: the CMS interface for job summission, monitoring and bookkeeping
Lesson 11: Web Services & API's
Steering Group Member, Link Digital
AppArmor Update 2014 Linux Security Summit
Amplitude 2017 #cashlessbanoindia
CZ.NIC in a nutshell Domain, DNSSEC, Turris Project and others
RFC 7706: Decreasing Access Time to Root Servers by Running One on Loopback A good idea or not? Petr Špaček • •
draft-ietf-ecrit-rough-loc
DHCP Anonymity Profile Update
Scaling up DNS-based service discovery
Senior Project, Spring 2018 To-do List Optimizer 1.0 Problem Solution
MEAN stack L. Grewe.
.edu DNSSEC Testbed Lessons Learned
OpenID Connect Working Group
2. Updates from the Last Meeting
Root KSK Roll Update DNS-OARC 27 Matt Larson, VP of Research
Chapter 2: The Linux System Part 1
Measuring KSK Roll Readiness
Introduction of Week 11 Return assignment 9-1 Collect assignment 10-1
IETF DNSOP WG Update – and some DPRIVE
“DNS Flag day” A tale of five ccTLDs Hugo Salgado, .CL
DirectAccess with Unified Access Gateway (UAG)
Hackathon AIS’19 Measurement group DNS over HTTPS/TLS team
Socket Extensions for OnDemand Mobility Management
Presentation transcript:

DNS/DNSSEC/DPRIV E IETF 96 Hackathon Problem Solved – DNS security and privacy enhancements and interoperabilty Method of Solution – multiple user stories, multiple open source prototypes

Highlight 1: DNSSEC Transparency Like Certificate Transparency, but with DS posts instead of X.509 draft-zhang-trans-ct-dnssec Server running as of 5AM (see Linus’ tweet) Client is talking to the server (Go and Miek’s DNS library) Server is Erlang with getdns Linus, Daniel & MC

Highlight 2: DNS64 A v6-only endpoint now has support for DNS64 Addressing issues identified by Jen Linkova (Google) presentation at RIPE 72 Coming soon: test this from getdnsapi.net/query.html Identified several high-profile DNSSEC-signed sites from Alexa 1M that do not support IPv6 (including mail.com)

Highlight 3: Universal Access reviews getdns: Good support but not 100% compliant yet (solution identified for next release) systemd-resolved service hmm.. first experiments with D-Bus interface show it doesn’t work, even though is documented that it should..needs investigation

Team Participants John Dickinson, SINODUN Sara Dickinson, SINODUN Daniel Kahn Gillmore, ACLU Jim Hague, SINODUN Shumon Huque, Verisign Shane Kerr, BII Rick Lamb, ICANN Ed Lewis, ICANN David Lawrence, Akamai Jerry Lundström, OARC Allison Mankin, Salesforce Linus Nordberg, NORDUnet Joel Purra, Consultant Benno Overeinder, NLnet Labs Melinda Shore, No Mountain Andrew Sullivan, DYN Ondřej Surý, CZ.NIC Willem Toorop, NLNet Labs Paul Wouters, Red Hat Mohammad Hassan Zahraee, University of Paderborn Daniel & MC, Netno GREEN – first Hackathon, new to IETF Daniel & MC, Netnod

Project List Continued work on dnssec-chain-query in BIND Full implementation (Javascript) of Shane’s dns-http draft Implementation of draft-pauly-ipsecme-split-dns, will interop with Apple implementation this week Python module for query triggering the IPSEC tunnel Implementation of DNS64 in getdns Multiple getdns bindings (Perl, Python updates, node.js, Go) Universal Access reviews RFC 7858 (DNS-over-TLS) engineering and interop (getdns, Unbound, Knot) Review and re-design of getdns Universal Access functions Soft HSM

More Highlights (not presented)

getdns Bindings More work on node.js and Python Perl bindings started here and almost finished! Go binding started…basics are working! Also, start of native Go implementation of the getdns API functions

Perl Bindings for getdns Net::GetDNS 0.01 released Contains Net::GetDNS::XS with >70% implemented getdns interfaces Async lookups to anonymous Perl sub’s works

Go Bindings for getdns Go wrapper in the style of Python Why? Way quicker solution to produce than native implementation (with a performance hit?) Basic queries working, output from getdns response dict in Go Lists and Maps will be available here: Relative Go newbie managed this during Hackathon!

DNS-over-TLS Security work on better socket privilege management in debian for DNS-over-TLS servers Knot resolver DNS-over-TLS support almost ready for merge into main code kdig tool is getting DNS-over-TLS added as we speak