SlideShare a Scribd company logo
1 of 41
Download to read offline
©!Men!&!Mice!!http://menandmice.com!
IETF!93!Review


30st!July!2015
1
©!Men!&!Mice!!http://menandmice.com!
before!we!start
…!please!note:!BIND!9!security!issue!
!
CVE-2015-5477:!An!error!in!handling!TKEY!
queries!can!cause!named!to!exit!with!a!REQUIRE!
assertion!failure!
all!BIND!9!DNS!Server!should!be!updated!to!the!
latest!9.10.2-P3!or!9.9.7-P2!versions!
2
©!Men!&!Mice!!http://menandmice.com!
Agenda
IETF!93!in!Prague!!
DNS,!DNSSEC,!DANE,!DHCP,!IPv6!
the!following!information!is!an!excerpt!of!the!IETF!
working!group!activities!
for!a!full!overview!of!all!activities!at!IETF!93,!see!

https://datatracker.ietf.org/meeting/93/materials.html
3
©!Men!&!Mice!!http://menandmice.com!
DNS
4
©!Men!&!Mice!!http://menandmice.com!
new!DNS!related!RFCs!

published!since!last!IETF
5
RFC Title Category
7505
A "Null MX" No Service Resource Record for Domains That
Accept No Mail
Standards Track
7534 AS112 Nameserver Operations Informational
7535 AS112 Redirection Using DNAME Informational
7553
The Uniform Resource Identifier (URI) DNS Resource
Record
Informational
7558
Requirements for Scalable DNS-Based Service Discovery
(DNS-SD) / Multicast DNS (mDNS) Extensions
Informational
©!Men!&!Mice!!http://menandmice.com!
RFC!7505!-!

A!"Null!MX"!No!Service!Resource!Record!for!Domains!
That!Accept!No!Mail
sending!mail!server!will!lookup!MX-Records!for!the!
recipients!domain,!without!MX!it!will!fallback!to!A/
AAAA-Address!records!
the!"null!MX"!record!indicates!that!a!host/domain!
cannot!receive!SMTP!mail!
Example:!
www.menandmice.com. 3600 IN MX 0 .
6
©!Men!&!Mice!!http://menandmice.com!
RFC!7553

The!Uniform!Resource!Identifier!(URI)!DNS!Resource!
Record
maps!a!service!name!and!a!domain!to!an!Uniform!
Resource!Identifier!(URI)!
similar!to!SRV,!but!returns!a!full!URI!instead!
hostname!+!port!
Example:!
_http._tcp.menandmice.com. 3600 IN URI 10 50 "http://www.menandmice.com"

_http._tcp.menandmice.com. 3600 IN URI 10 50 "http://www.menandmice.com"

_http._tcp.menandmice.com. 3600 IN URI 20 00 "http://www.menandmice.com"
7
priority
weight
URI
©!Men!&!Mice!!http://menandmice.com!
DNS!Transport!over!TCP!-!Implementation!Requirements

draft-ietf-dnsop-5966bis
update!of!RFC!5966!
make!TCP!a!requirement!for!the!DNS!protocol!
Benefits!of!DNS!over!TCP:!
•!prevents!amplification!attacks!
•!privacy/encryption!(TLS)!
•!no!fragmentation!issues!
Clients!should!pipeline!their!queries!over!TCP!
with!keep-alive,!persistent!connections!and!pipelining,!
DNS!over!TCP!can!be!as!fast!as!traditional!DNS!over!UDP
8
©!Men!&!Mice!!http://menandmice.com!
The!edns-tcp-keepalive!EDNS0!Option!
draft-ietf-dnsop-edns-tcp-keepalive
it!is!expected!to!see!more!DNS-TCP!traffic!in!the!
future!
enables!DNS!clients,!DNS!resolver!and!authoritative!
DNS-Server!to!negotiate!a!keep!alive!for!TCP!
sessions!
clients!can!send!multiple!queries!over!an!
established!TCP!session!
9
©!Men!&!Mice!!http://menandmice.com!
KSK!rollover!in!the!root-zone
the!Internet!DNS!root!zone!has!been!signed!5!years!
ago!(July!2010)!
the!root!KSK!should!be!rolled!
•HSMs!are!getting!old!and!out!of!support!
several!issues!have!been!identified:!
•the!publication!format!of!the!KSK!trust!anchor!is!not!standardised!
•(secure)!bootstrapping!of!DNSSEC!DNS-resolvers!
•devices!might!"miss"!the!KSK!roll!(via!RFC!5011)!while!being!"on!the!
shelf",!no!standard!way!to!re-bootstrap
10
©!Men!&!Mice!!http://menandmice.com!
Yeti-DNS!project
experimental,!IPv6!only!DNS-root-server

system!
Large-scale!testbed!
Yeti!Participants:!
•!Operators!of!Yeti!components,!or!experimenters!
•!DNS!experts,!with!varied!backgrounds!and!interests
11
©!Men!&!Mice!!http://menandmice.com!
Yeti-DNS!project
Planned!Experiments!&!Other!Investigations!
•Impacts!of!IPv6-only!DNS!
•Bigger!minimum!packet!size,!no!IP-fragmentation!
•KSK!rollover,!KSK/ZSK!rollover!frequency,!algorithm,!signature!size!
•Changes!in!DNSSEC!
•Changes!to!root!servers

Lots/few!of!root!servers,!churn!in!root!server!set!
the!project!is!looking!for!volunteers!

running!DNS!resolvers!against!

the!Yeti-DNS!root!(informed!users!

in!non-critical!environments)
12
http://yeti-dns.org/
©!Men!&!Mice!!http://menandmice.com!
RFC!6761!"special!use!domain-names"
request!for!Special!Use!Domain!Names!of!P2P!
Systems:!
•!!.bit!=!Namecoin!
•!!.exit!=!Tor!Project!
•!!.gnu!and!.zkey!=!GNUnet!
•!!.i2p!=!I2P!System!
•!!.tor!=!consensus!among!Tor!routes
13
©!Men!&!Mice!!http://menandmice.com!
RFC6761bis!Problem!Space

Input!to!the!Design!Team
future!of!the!special!names!registry!
namespace!!=!DNS!
one-off!protocol!switch!or!general!solution!
(.alt,!.ext,!.external)?!
separate!protocol!design!from!policy?!
heated!debate!during!IETF!93,!no!conclusions,!
discussion!will!continue!on!the!mailing!list(s)
14
©!Men!&!Mice!!http://menandmice.com!
DANE
15
©!Men!&!Mice!!http://menandmice.com!
A!DANE!Record!and!DNSSEC!Authentication!Chain!
Extension!for!TLS

!draft-shore-tls-dnssec-chain-extension
new!TLS!extension!for!transport!of!a!DNS!record!set!
serialised!with!the!DNSSEC!signatures!needed!to!
authenticate!that!record!set!
•without!performing!perform!additional!DNS!record!lookups!
(latency)!
•avoid!potential!problems!with!TLS!clients!being!unable!to!
look!up!DANE!records!
•allows!a!TLS!client!to!validate!DANE!records!itself!without!a!
validating!DNS!resolver
16
©!Men!&!Mice!!http://menandmice.com!
A!DANE!Record!and!DNSSEC!Authentication!Chain!
Extension!for!TLS

!draft-shore-tls-dnssec-chain-extension
the!TLS!client!requests!the!DNSSEC!validation!chain!
be!returned!
the!server!performs!the!appropriate!DNS!queries,!
builds!the!validation!chain,!and!returns!it!to!the!
client!(as!part!of!the!TLS!handshake)!
The!client!then!authenticates!the!chain!using!a!pre-
configured!trust!anchor!
17
©!Men!&!Mice!!http://menandmice.com!
Client!Certificates!in!DANE!TLSA!Records

draft-huque-dane-client-cert
extension!to!the!existing!TLSA!record!
_smtp-client.device1.example.com. IN TLSA (

3 1 1 d2abde240d7cd3ee6b4b28c54df034b9

7983a1d16e8a410e4561cb106618e971 )
•Client!has!an!identity!assigned!corresponding!to!a!DNS!domain!
name.!!
•Client!has!a!private/public!key!pair!and!a!certificate!binding!the!
domain!name!to!the!public!key.!!
•Domain!Name!+!Certificate!has!a!corresponding!signed!DNS!
TLSA!record!
•a!new!TLS!extension!is!proposed!to!convey!the!DNS!client!identity
18
©!Men!&!Mice!!http://menandmice.com!
SMIMEA!and!OPENPGPKEY
Discussion!of!how!to!store!the!key!holders!email!
address!
! hash!vs.!base32!
no!consensus!reached!during!the!meeting,!discussion!on!
the!mailing!list!until!1st!of!August!
seperator!label!"_at"!proposed!instead!of!"_smimecert"!
and!"_openpgpkey"!
Working!Group!Last!Call!(WGLC)!planned!before!IETF!94!
(November)!
19
©!Men!&!Mice!!http://menandmice.com!
DPRIVE
20
©!Men!&!Mice!!http://menandmice.com!
DNS!over!DTLS!

draft-ietf-dprive-dnsodtls
•Advantages!
•avoid!head-of-line!blocking!
•fast!session!resumption!
•supports!Anycast!
•Problems!
•DPI!Firewalls!->!use!different!port!for!DNS/DTLS!
•DNS!Server!authentication!->!x509!cert!
•private!server!do!not!have!CA!certs!->!self-signed!cert!fingerprint!
•configured!in!/etc/resolv.conf!(or!similar)!
•!discovery!of!DNSoD!->!downgrade!attack!possible
21
©!Men!&!Mice!!http://menandmice.com!
TCP-TLS!for!DNS
•!discussion!about!no!STARTTLS!
•consensus:!use!new!port!for!DNS!over!TLS!
•DNS!over!TLS!should!follow!TLS!BCP!(best!current!practice)!
document!
•available!implementations:!!
•Unbound!
•ldns/drill!
•digit!
•getdns-api
22
©!Men!&!Mice!!http://menandmice.com!
IPSec!AUTH_NULL!opportunistic!DNS
•client!to!resolver!path!encryption!
•why!not!encrypt!all!traffic!instead!of!only!DNS?!
•IPSec!encryption!without!authentication!
•coffee-shop!scenario!
•optionally!limited!to!DNS!traffic!only!
•proposed!alternative!to!"in-DNS-protocol"!solution!
•already!available!and!working!with!current!implementations
23
©!Men!&!Mice!!http://menandmice.com!
DHCP
24
©!Men!&!Mice!!http://menandmice.com!
published!new!RFCs!since!last!IETF
25
RFC Title Category
RFC 7550 Issues and Recommendations with Multiple Stateful DHCPv6 Options Standards Track
©!Men!&!Mice!!http://menandmice.com!
Update!!of!Secure!DHCPv6!
&!Secure!!DHCPv4
draft-ietf-dhc-sedhcpv6!
draft-jiang-dhc-sedhcpv4!
DHCPv6!client/server!authentication!mechanism!
based!on!sender's!public/private!key!pairs!
!!!or!certificates!with!associated!private!keys!
IETF!hackathon!did!an!(successful)!interoperability!
test!of!two!implementations!(ISC!KEA!and!WIDE!
DHCPv6,!support!for!ISC!DHCP!is!"work!in!progress")
26
©!Men!&!Mice!!http://menandmice.com!
DHCP!Anonymity!Profile
draft-ietf-dhc-anonymity-profile!
DHCPv4!and!DHCPv6!clients!disclose!many!identifiers!that!can!be!used!to!track!
clients.!This!work!seeks!to!eliminate!that!information!leak!by!defining!an!
anonymity!profile,!a!set!of!DHCP!behaviours!
•Randomising!MAC!address!+!client-id/DUID!
•Not!disclosing!client!hostname!
•Changing!identity!
•Limiting!information!disclosure!when!changing!networks!
Prototype!implementation:!Windows!10!(Microsoft)!
! implementation!choice:!does!not!send!hostname!option!
Microsoft!did!a!field!trial!using!the!prototype!implementation,!only!minor!issues!
found
27
©!Men!&!Mice!!http://menandmice.com!
DHCP!v4/v6!Relay!Initiated!Release
draft-gandhewar-dhc-relay-initiated-release-00!
draft-gandhewar-dhc-v6-relay-initiated-release-00!
Issue:!clients!sometimes!do!not!release!a!lease!when!leaving!the!network!
(in!some!networks)!the!DHCP!lease!is!used!to!keep!state!beyond!the!IP-
address:!
•various!routes!e.g.!access,!framed!routes!
•various!services!e.g.!data,!voice,!video!
•policy!
•QoS!setup!
DHCP!relay!might!be!able!to!detect!client!leaving,!releasing!the!lease!on!
behalf!of!the!client
28
©!Men!&!Mice!!http://menandmice.com!
IPv6/IPv4-sunset
29
©!Men!&!Mice!!http://menandmice.com!
published!new!RFCs!since!last!IETF
30
RFC Title Category
RFC 7445 Analysis of Failure Cases in IPv6 Roaming Scenarios Informational
RFC 7506
IPv6 Router Alert Option for MPLS Operations, Administration, and
Maintenance (OAM)
Standards Track
RFC 7526 Deprecating the Anycast Prefix for 6to4 Relay Routers
Best Current
Practice
RFC 7527 Enhanced Duplicate Address Detection Standards Track
RFC 7559 Packet-Loss Resiliency for Router Solicitations Standards Track
RFC 7600 IPv4 Residual Deployment via IPv6 - A Stateless Solution (4rd) Experimental
RFC 7608 IPv6 Prefix Length Recommendation for Forwarding
Best Current
Practice
©!Men!&!Mice!!http://menandmice.com!
IPv6!to!"internet!standard"
RFC!2460

(and!many!other

RFCs!are!still!a!

"draft!standard"!
•RFC!6410!"Requirements!for!Internet!Standards"!
•!forward!"draft"!to!"proposed!standard"!
•!WG!discussion!of!"re-write!update!RFC!vs.!pushing!
RFC!unchanged"
31
©!Men!&!Mice!!http://menandmice.com!
Randomised!MAC!Addresses!and!

IPv6!Address!Assignment
enhance!privacy!of!users!
•users!can!hide!from!the!network!
•prevent!location!tracing!
•implemented!using!standard!IEEE!802!rules!(Preferred!!Format:!
U/L=1,!G=0,!46!random!bits)!
•!conflict!with!RFC!7217!(A!Method!for!Generating!Semantically!
Opaque!Interface!Identifiers!with!IPv6!Stateless!Address!Auto-
configuration!(SLAAC))!
•!conflict!with!SAVI!"Source!Address!Validation!Improvement!
(SAVI)!Solution!for!DHCP"
32
©!Men!&!Mice!!http://menandmice.com!
IPv6!news!from!Apple
all!iOS!apps!MUST!support!native!IPv6!(starting!
with!iOS!9)!
Happy!Eyeballs!in!iOS!9!and!MacOS!X!10.11!will!
prefer!IPv6!99%!of!the!time!
NAT64!internet!sharing!uses!2001::/64!(Teredo!
prefix)
33
©!Men!&!Mice!!http://menandmice.com!
IPv6!news!from!Apple
NAT64/DNS64!"IPv6-only"!network!via!MacOS!X!
Internet!Sharing!in!MacOS!X!10.11!"El!Capitan"



NAT64/DNS64!

can!break!local!

DNSSEC!

validation!!
34
©!Men!&!Mice!!http://menandmice.com!
Some!Design!Choices!for!IPv6!
Networks
draft-ietf-v6ops-design-choices!
includes!now!Enterprise!environments!and!their!use!
cases!(in!addition!to!service!providers)!
new!IGP!choice!section!
!now!covers!EIGRP!and!RIPng!
new!section!on!address!choices
35
©!Men!&!Mice!!http://menandmice.com!
draft-yc-v6ops-solicited-ra-unicast
multicast!router!advertisements!in!large!wireless!networks!
•every!device!joining!the!network!sends!a!router!solicitation!
•router!sends!multicast!RA,!all!devices!in!the!network!awake!
•drains!device!battery!
Recommendations!
•Router!manufacturers!SHOULD!allow!network!administrators!to!
configure!the!routers!to!respond!to!Router!Solicitations!with!unicast!
Router!Advertisements.!
•Networks!that!serve!large!numbers!(tens!or!hundreds)!of!mobile!
devices!SHOULD!enable!this!behaviour.
36
©!Men!&!Mice!!http://menandmice.com!
Host!address!availability!recommendations

draft-colitti-v6ops-host-addr-availability
Addressing!practices!that!make!sense!in!IPv4!may!not!be!
appropriate!in!IPv6!
•/64!per!link!allows!“unlimited”!host!addressing!
•No!longer!forced!to!assign!one!address!per!host!due!to!address!scarcity!
•Many!benefits!provided!by!assigning!multiple!addresses!to!each!host!
Recommendations!
•Provide!multiple!IPv6!addresses!from!each!prefix!to!general-purpose!hosts!
when!they!attach!to!the!network!
•Don’t!impose!a!hard!limit!on!the!size!of!the!address!pool!assigned!to!a!host!
•If!the!network!requires!explicit!requests,!assign!a!/64!via!DHCPv6!PD
37
©!Men!&!Mice!!http://menandmice.com!
RFC!7511

Scenic!Routing!for!IPv6
•incorporates!the!green-ness!of!

a!network!path!into!the!routing!

decision!
•routing!algorithms!SHOULD!!

calculate!the!optimal!paths!providing!

the!most!fresh-air!time!for!a!packet!
•should!therefore!choose!paths!based!on!

Avian!IP!Carriers![RFC1149]!and/or!wireless!technologies!
room!for!"live"!implementation:!CCC!Camp!

13-17!Aug!2015!https://events.ccc.de/camp/2015/wiki/Main
38
Zelte!und!ein!„Datenklo“!auf!dem!Chaos!Communication!Camp,!Finowfurt!2007!
"RobotSkirts"/Eliot!Phillips,!CC-by-sa-2.0
©!Men!&!Mice!!http://menandmice.com!
don't!miss!our!next!webinar
•"PowerDNS",!Monday,!31st!August!2015!
•overview:!the!PowerDNS!open!source!DNS!server!
•manage!a!DNS!zone!via!SQL!backend!
•manage!a!DNS!zone!via!BIND!backend!
•remote!zone!Backend!
•DNSSEC!signing!with!PowerDNS!
•the!Men!&!Mice!Suite!controller!for!PowerDNS!
•Signup!@!

https://www.menandmice.com/resources/educational-resources/webinars/
39
©!Men!&!Mice!!http://menandmice.com!
upcoming!Men!&!Mice!trainings
•Upcoming!Trainings:!
•September!8!–!11,!2015,!Special!4!days:!IPv6!Introduction!+!Advanced!Topics!Hands-On!
Workshop,!San!Francisco!area!(CA),!USA!!
•September!28!–!29,!2015,!Introduction!to!DNS!&!BIND!Hands!on,!Arlington!(VA),!USA!
•September!30!–!October!2,!2015,!DNSSEC!Technical!Workshop!–!Implementation!and!
Deployment,!Arlington!(VA),!USA! !
•September!28!–!October!2,!2015,!Introduction!&!Advanced!DNS!and!BIND!Hands!on,!
Arlington!(VA),!USA!
•November!16!–!17,!2015,!Introduction!to!DNS!&!BIND!Hands!on,!Redwood!City!(CA),!USA!
•November!16!–!20,!2015,!Introduction!&!Advanced!DNS!and!BIND!Hands!on,!Redwood!City!
(CA),!USA



more!training!classes!on!

!!!!https://www.menandmice.com/support-training/training/
40
©!Men!&!Mice!!http://menandmice.com!
Q/A
41
?
2015!Schedule,!Slides,!Links,!Recording!and!errata!
can!be!found!@

https://www.menandmice.com/resources/educational-resources/webinars/

More Related Content

Viewers also liked

Living Learning Programs for Gender Non-Conforming Students
Living Learning Programs for Gender Non-Conforming StudentsLiving Learning Programs for Gender Non-Conforming Students
Living Learning Programs for Gender Non-Conforming StudentsPaul Brown
 
Vishnu Sen true.net
Vishnu Sen true.netVishnu Sen true.net
Vishnu Sen true.netvishnu sen
 
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blog
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blogPresentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blog
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blogPedro De Bruyckere
 
9.1.2017 Verkostotapaamisen esitys
9.1.2017 Verkostotapaamisen esitys 9.1.2017 Verkostotapaamisen esitys
9.1.2017 Verkostotapaamisen esitys Työterveyslaitos
 
Developing a World Class Customer Success Organization
Developing a World Class Customer Success Organization Developing a World Class Customer Success Organization
Developing a World Class Customer Success Organization Gainsight
 
Joyt edgar dale's cone of experience
Joyt edgar dale's cone of experienceJoyt edgar dale's cone of experience
Joyt edgar dale's cone of experiencejoygtablante
 
세바시에 보낸 [서대웅브랜드] 스토리텔링
세바시에 보낸 [서대웅브랜드] 스토리텔링세바시에 보낸 [서대웅브랜드] 스토리텔링
세바시에 보낸 [서대웅브랜드] 스토리텔링대웅 서
 
20 Blog Title Cliches That Work!
20 Blog Title Cliches That Work!20 Blog Title Cliches That Work!
20 Blog Title Cliches That Work!Paul Brown
 
¿Cómo y por qué cuidar tus datos personales?
¿Cómo y por qué cuidar tus datos personales? ¿Cómo y por qué cuidar tus datos personales?
¿Cómo y por qué cuidar tus datos personales? ESET Latinoamérica
 

Viewers also liked (11)

THE KINGDOM
THE KINGDOMTHE KINGDOM
THE KINGDOM
 
Living Learning Programs for Gender Non-Conforming Students
Living Learning Programs for Gender Non-Conforming StudentsLiving Learning Programs for Gender Non-Conforming Students
Living Learning Programs for Gender Non-Conforming Students
 
Vishnu Sen true.net
Vishnu Sen true.netVishnu Sen true.net
Vishnu Sen true.net
 
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blog
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blogPresentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blog
Presentatie door Dirk Van Damme - niet van mij, hier geplaatst voor mijn blog
 
9.1.2017 Verkostotapaamisen esitys
9.1.2017 Verkostotapaamisen esitys 9.1.2017 Verkostotapaamisen esitys
9.1.2017 Verkostotapaamisen esitys
 
Developing a World Class Customer Success Organization
Developing a World Class Customer Success Organization Developing a World Class Customer Success Organization
Developing a World Class Customer Success Organization
 
Joyt edgar dale's cone of experience
Joyt edgar dale's cone of experienceJoyt edgar dale's cone of experience
Joyt edgar dale's cone of experience
 
세바시에 보낸 [서대웅브랜드] 스토리텔링
세바시에 보낸 [서대웅브랜드] 스토리텔링세바시에 보낸 [서대웅브랜드] 스토리텔링
세바시에 보낸 [서대웅브랜드] 스토리텔링
 
X ray film
X ray film X ray film
X ray film
 
20 Blog Title Cliches That Work!
20 Blog Title Cliches That Work!20 Blog Title Cliches That Work!
20 Blog Title Cliches That Work!
 
¿Cómo y por qué cuidar tus datos personales?
¿Cómo y por qué cuidar tus datos personales? ¿Cómo y por qué cuidar tus datos personales?
¿Cómo y por qué cuidar tus datos personales?
 

Similar to IETF 93 Review Webinar

IETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANEIETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANEMen and Mice
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report WebinarMen and Mice
 
Report from IETF 89 in London - DNS, DHCP and IPv6
Report from IETF 89 in London - DNS, DHCP and IPv6Report from IETF 89 in London - DNS, DHCP and IPv6
Report from IETF 89 in London - DNS, DHCP and IPv6Men and Mice
 
Imola informatica - cloud computing and software development
Imola informatica - cloud computing and software developmentImola informatica - cloud computing and software development
Imola informatica - cloud computing and software developmentFilippo Bosi
 
Aerogear Java User Group Presentation
Aerogear Java User Group PresentationAerogear Java User Group Presentation
Aerogear Java User Group Presentationhwilming
 
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...CODE BLUE
 
Rackspace Cloud Monitoring - Strata NYC
Rackspace Cloud Monitoring - Strata NYCRackspace Cloud Monitoring - Strata NYC
Rackspace Cloud Monitoring - Strata NYCgdusbabek
 
Node-RED workshop at IoT Toulouse
Node-RED workshop at IoT ToulouseNode-RED workshop at IoT Toulouse
Node-RED workshop at IoT ToulouseBoris Adryan
 
The KNOT DNS Server
The KNOT DNS ServerThe KNOT DNS Server
The KNOT DNS ServerMen and Mice
 
A DevOps Perspective: MongoDB & MMF
A DevOps Perspective: MongoDB & MMFA DevOps Perspective: MongoDB & MMF
A DevOps Perspective: MongoDB & MMFMapMyFitness
 
OSGi and Other Technologies - P Kriens
OSGi and Other Technologies - P KriensOSGi and Other Technologies - P Kriens
OSGi and Other Technologies - P Kriensmfrancis
 
Japan Market for Korean Dev
Japan Market for Korean DevJapan Market for Korean Dev
Japan Market for Korean Dev01Booster
 
DNS fragmentation attacks - the dangers of not validating DNSSEC
DNS fragmentation attacks - the dangers of not validating DNSSEC DNS fragmentation attacks - the dangers of not validating DNSSEC
DNS fragmentation attacks - the dangers of not validating DNSSEC Men and Mice
 
IPv6 IAB/IETF Activities Report from ARIN 32
IPv6 IAB/IETF Activities Report from ARIN 32IPv6 IAB/IETF Activities Report from ARIN 32
IPv6 IAB/IETF Activities Report from ARIN 32ARIN
 
Google Cloud Lightning Talk
Google Cloud Lightning TalkGoogle Cloud Lightning Talk
Google Cloud Lightning TalkDMI
 
Javaland 2014 / GWT architectures and lessons learned
Javaland 2014 / GWT architectures and lessons learnedJavaland 2014 / GWT architectures and lessons learned
Javaland 2014 / GWT architectures and lessons learnedpgt technology scouting GmbH
 
Improve the User Experience in the Engineering Change Process
Improve the User Experience in the Engineering Change ProcessImprove the User Experience in the Engineering Change Process
Improve the User Experience in the Engineering Change ProcessDeeDee Kato
 
Speech-Enabling Web Apps
Speech-Enabling Web AppsSpeech-Enabling Web Apps
Speech-Enabling Web AppsMojo Lingo
 
I時代的工作術
I時代的工作術I時代的工作術
I時代的工作術Vista Cheng
 

Similar to IETF 93 Review Webinar (20)

IETF 92 Webinar
IETF 92 WebinarIETF 92 Webinar
IETF 92 Webinar
 
IETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANEIETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANE
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report Webinar
 
Report from IETF 89 in London - DNS, DHCP and IPv6
Report from IETF 89 in London - DNS, DHCP and IPv6Report from IETF 89 in London - DNS, DHCP and IPv6
Report from IETF 89 in London - DNS, DHCP and IPv6
 
Imola informatica - cloud computing and software development
Imola informatica - cloud computing and software developmentImola informatica - cloud computing and software development
Imola informatica - cloud computing and software development
 
Aerogear Java User Group Presentation
Aerogear Java User Group PresentationAerogear Java User Group Presentation
Aerogear Java User Group Presentation
 
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...
CODE BLUE 2014 : マイクロソフトの脆弱性調査 : ベンダーでありながら発見者となるために by デイヴィッド・シードマン David Se...
 
Rackspace Cloud Monitoring - Strata NYC
Rackspace Cloud Monitoring - Strata NYCRackspace Cloud Monitoring - Strata NYC
Rackspace Cloud Monitoring - Strata NYC
 
Node-RED workshop at IoT Toulouse
Node-RED workshop at IoT ToulouseNode-RED workshop at IoT Toulouse
Node-RED workshop at IoT Toulouse
 
The KNOT DNS Server
The KNOT DNS ServerThe KNOT DNS Server
The KNOT DNS Server
 
A DevOps Perspective: MongoDB & MMF
A DevOps Perspective: MongoDB & MMFA DevOps Perspective: MongoDB & MMF
A DevOps Perspective: MongoDB & MMF
 
OSGi and Other Technologies - P Kriens
OSGi and Other Technologies - P KriensOSGi and Other Technologies - P Kriens
OSGi and Other Technologies - P Kriens
 
Japan Market for Korean Dev
Japan Market for Korean DevJapan Market for Korean Dev
Japan Market for Korean Dev
 
DNS fragmentation attacks - the dangers of not validating DNSSEC
DNS fragmentation attacks - the dangers of not validating DNSSEC DNS fragmentation attacks - the dangers of not validating DNSSEC
DNS fragmentation attacks - the dangers of not validating DNSSEC
 
IPv6 IAB/IETF Activities Report from ARIN 32
IPv6 IAB/IETF Activities Report from ARIN 32IPv6 IAB/IETF Activities Report from ARIN 32
IPv6 IAB/IETF Activities Report from ARIN 32
 
Google Cloud Lightning Talk
Google Cloud Lightning TalkGoogle Cloud Lightning Talk
Google Cloud Lightning Talk
 
Javaland 2014 / GWT architectures and lessons learned
Javaland 2014 / GWT architectures and lessons learnedJavaland 2014 / GWT architectures and lessons learned
Javaland 2014 / GWT architectures and lessons learned
 
Improve the User Experience in the Engineering Change Process
Improve the User Experience in the Engineering Change ProcessImprove the User Experience in the Engineering Change Process
Improve the User Experience in the Engineering Change Process
 
Speech-Enabling Web Apps
Speech-Enabling Web AppsSpeech-Enabling Web Apps
Speech-Enabling Web Apps
 
I時代的工作術
I時代的工作術I時代的工作術
I時代的工作術
 

More from Men and Mice

Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network StrategiesCisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network StrategiesMen and Mice
 
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOS
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOSPart 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOS
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOSMen and Mice
 
Part 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows NetworksPart 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows NetworksMen and Mice
 
Namespaces for Local Networks
Namespaces for Local NetworksNamespaces for Local Networks
Namespaces for Local NetworksMen and Mice
 
How to send DNS over anything encrypted
How to send DNS over anything encryptedHow to send DNS over anything encrypted
How to send DNS over anything encryptedMen and Mice
 
The DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rollsThe DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rollsMen and Mice
 
The CAA-Record for increased encryption security
The CAA-Record for increased encryption securityThe CAA-Record for increased encryption security
The CAA-Record for increased encryption securityMen and Mice
 
SMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANESMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANEMen and Mice
 
DNSSEC signing Tutorial
DNSSEC signing Tutorial DNSSEC signing Tutorial
DNSSEC signing Tutorial Men and Mice
 
BIND 9 logging best practices
BIND 9 logging best practicesBIND 9 logging best practices
BIND 9 logging best practicesMen and Mice
 
DNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing SolutionsDNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing SolutionsMen and Mice
 
Fighting Abuse with DNS
Fighting Abuse with DNSFighting Abuse with DNS
Fighting Abuse with DNSMen and Mice
 
What is new in BIND 9.11?
What is new in BIND 9.11?What is new in BIND 9.11?
What is new in BIND 9.11?Men and Mice
 
Yeti DNS - Experimenting at the root
Yeti DNS - Experimenting at the rootYeti DNS - Experimenting at the root
Yeti DNS - Experimenting at the rootMen and Mice
 
Windows Server 2016 Webinar
Windows Server 2016 WebinarWindows Server 2016 Webinar
Windows Server 2016 WebinarMen and Mice
 
Kea DHCP – the new open source DHCP server from ISC
Kea DHCP – the new open source DHCP server from ISCKea DHCP – the new open source DHCP server from ISC
Kea DHCP – the new open source DHCP server from ISCMen and Mice
 
RIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarRIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarMen and Mice
 
Keeping DNS server up-and-running with “runit
Keeping DNS server up-and-running with “runitKeeping DNS server up-and-running with “runit
Keeping DNS server up-and-running with “runitMen and Mice
 
PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2Men and Mice
 

More from Men and Mice (20)

Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network StrategiesCisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
 
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOS
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOSPart 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOS
Part 3 - Local Name Resolution in Linux, FreeBSD and macOS/iOS
 
Part 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows NetworksPart 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows Networks
 
Namespaces for Local Networks
Namespaces for Local NetworksNamespaces for Local Networks
Namespaces for Local Networks
 
How to send DNS over anything encrypted
How to send DNS over anything encryptedHow to send DNS over anything encrypted
How to send DNS over anything encrypted
 
The DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rollsThe DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rolls
 
The CAA-Record for increased encryption security
The CAA-Record for increased encryption securityThe CAA-Record for increased encryption security
The CAA-Record for increased encryption security
 
SMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANESMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANE
 
DNSSEC signing Tutorial
DNSSEC signing Tutorial DNSSEC signing Tutorial
DNSSEC signing Tutorial
 
BIND 9 logging best practices
BIND 9 logging best practicesBIND 9 logging best practices
BIND 9 logging best practices
 
DNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing SolutionsDNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing Solutions
 
Fighting Abuse with DNS
Fighting Abuse with DNSFighting Abuse with DNS
Fighting Abuse with DNS
 
What is new in BIND 9.11?
What is new in BIND 9.11?What is new in BIND 9.11?
What is new in BIND 9.11?
 
Yeti DNS - Experimenting at the root
Yeti DNS - Experimenting at the rootYeti DNS - Experimenting at the root
Yeti DNS - Experimenting at the root
 
Windows Server 2016 Webinar
Windows Server 2016 WebinarWindows Server 2016 Webinar
Windows Server 2016 Webinar
 
Kea DHCP – the new open source DHCP server from ISC
Kea DHCP – the new open source DHCP server from ISCKea DHCP – the new open source DHCP server from ISC
Kea DHCP – the new open source DHCP server from ISC
 
DNSTap Webinar
DNSTap WebinarDNSTap Webinar
DNSTap Webinar
 
RIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarRIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinar
 
Keeping DNS server up-and-running with “runit
Keeping DNS server up-and-running with “runitKeeping DNS server up-and-running with “runit
Keeping DNS server up-and-running with “runit
 
PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2
 

Recently uploaded

Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 

Recently uploaded (20)

Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 

IETF 93 Review Webinar