SlideShare a Scribd company logo
© Men & Mice http://menandmice.com
IETF 94 Review


10th December 2015
1
IETF 94 Yokohama
November 1-6, 2015
© Men & Mice http://menandmice.com
before we start
… please note: Windows DNS security issue
December 8, 2015
MS15-127: Security update for Microsoft
Windows DNS to address remote code execution:
https://support.microsoft.com/en-us/kb/3100465
2
© Men & Mice http://menandmice.com
Agenda
DNS, DNSSEC, DANE, IPv6
IETF 94 in Yokohama
RIPE 71 in Bucharest
the following information is an excerpt of the IETF
working group activities
for a full overview of all activities at IETF 94, see 

https://datatracker.ietf.org/meeting/94/materials.html	
3
© Men & Mice http://menandmice.com
DNS
4
© Men & Mice http://menandmice.com
new DNS related RFCs 

published since last IETF
5
RFC Title Category
7720
DNS Root Name Service Protocol and Deployment
Requirements
BCP
7712
Domain Name Associations (DNA) in the Extensible
Messaging and Presence Protocol (XMPP)
Proposed
Standard
7706
Decreasing Access Time to Root Servers by Running One
on Loopback
Informational
7686 The ".onion" Special-Use Domain Name
Proposed
Standard
7673
Using DNS-Based Authentication of Named Entities
(DANE) TLSA Records with SRV Records
Proposed
Standard
© Men & Mice http://menandmice.com
new DNS related RFCs 

published since last IETF
6
RFC Title Category
7672
SMTP Security via Opportunistic DNS-Based
Authentication of Named Entities (DANE) Transport Layer
Security (TLS)
Proposed
Standard
7671
The DNS-Based Authentication of Named Entities (DANE)
Protocol: Updates and Operational Guidance
Proposed
Standard
7646 Definition and Use of DNSSEC Negative Trust Anchors Informational
7626 DNS Privacy Considerations Informational
© Men & Mice http://menandmice.com
DNS Record Type for SMIMEA
SMIMEA-Records now have a dedicated DNS record
type (Type 53)
!
SMIMEA - store x509 Certificate information for 

S/MIME in DNSSEC secured DNS
7
© Men & Mice http://menandmice.com
draft-jabley-dnsop-ordered-answers
do resource records in a DNS section have an order
some WinDNS expects OPT as first record(?)
TSIG/SIG(0) need order
some DNS resolver need Data-Records and RRSIG
to be in order (first data, then RRSIG)
document was rejected by the working group, but
interesting discussion
8
© Men & Mice http://menandmice.com
draft-ogud-dnsop-maintain-ds
Paul Wouters

presented a new 

draft on how the

management of DS-

Records can be auto-

mated
•how to publish the initial DS-record
•how to remove an existing DS-record
9
© Men & Mice http://menandmice.com
draft-wessels-edns-key-tag
Goal: measure RFC 5011 Root-KSK-

Rollover trust-anchor updates
DNS resolver send KSK-

Trust-Anchor-Keytags to 

authoritative server
•only for QTYPE=DNSKEY, SHOULD for configured trust
anchors
•DNS forwarding is tricky (can be different trust anchors)
•privacy/security considerations
10
© Men & Mice http://menandmice.com
DNAME in the Root?/
NXDOMAIN = NXDOMAIN
DNAME in the Root?
• ".local" is 2nd or 3rd popular TLD
• redirect ".local" with DNAME to AS112



NXDOMAIN means NXDOMAIN
• DNS resolver should stop domain search when encountering a
NXDOMAIN in the cache tree
• helps with QNAME minimisation and with some random
qname attack
• breaks Split-Horizon setups
11
© Men & Mice http://menandmice.com
IPv6
12
© Men & Mice http://menandmice.com
published new RFCs since last IETF
13
RFC Title Category
RFC 7610 DHCPv6-Shield: Protecting against Rogue DHCPv6 Servers BCP
RFC 7653 DHCPv6 Active Leasequery
Proposed
Standard
RFC 7668 IPv6 over BLUETOOTH(R) Low Energy
Proposed
Standard
RFC 7676 IPv6 Support for Generic Routing Encapsulation (GRE)
Proposed
Standard
© Men & Mice http://menandmice.com
draft-jjmb-v6ops-unique-ipv6-prefix-
per-host
•ComCast public WIFI trial
• /64 Prefix for each WIFI access device
• solves DAD, isolation between devices
14
© Men & Mice http://menandmice.com
draft-ietf-v6ops-design-choices
•Enterprise IPv6 

networks are in scope of the document
• all options for enterprises today have issues
• long discussion on ULA and "NPT66" (Option 3 of
the "how to get IPv6 address space" section)
15
© Men & Mice http://menandmice.com
Temporal and Spatial Classification of
Active IPv6 Addresses
• IPv6 operational study by Akamai
•classifies IPv6 addresses seen by their
CDN network
•temporal - how long are IPv6 addresses/
prefixes used
•spatial - location of IPv6 addresses
• almost no EUI48 Host-Identifier (good)
• > 90 % IPv6 are privacy addresses
• maps the IPv6 address space in use
16
© Men & Mice http://menandmice.com
RIPE 71
17
© Men & Mice http://menandmice.com
Impact of DNS over TCP

a Resolver Point of View
•study made with an medium 

size ISP (200-400 qps)
•TCP timeout management

is important
•message sizes due to 

DNSSEC no problem, most 

DNSSEC answers are below Ethernet MTU < 1500 byte
• connection reuse only beneficial for certain servers
(DNS resolver for a mail server)
18
https://ripe71.ripe.net/archives/video/1209/
© Men & Mice http://menandmice.com
Preparing the Root-Zone KSK Roll
•Root-KSK roll with 

use RFC 5011 

protocol
•KSK roll will probably 

take 6-9 month in total
•KSK rollover plan not

yet final
• announce mailing list

https://mm.icann.org/mailman/listinfo/root-dnssec-announce
19
https://ripe71.ripe.net/archives/video/1225/
© Men & Mice http://menandmice.com
DNSSEC for legacy applications
•getdns nsswitch module to 

replace default OS stub resolver
• works on nsswitch enabled

applications, but not with 

Chrome and related browsers

(or application with an internal

DNS resolver)
• configuration web-ui
• supports caching and DNS 

over TLS
• checks process name, 

rewrites answer in case a known web browser is detected
• only proof of concept, not production code
• SIDN is working on a similar signalling with Unbound
20
https://ripe71.ripe.net/archives/video/1221/
© Men & Mice http://menandmice.com
Implementation Challenges of
Geographic Split-Horizon
•overview of DNS-GeoIP 

implementations available in

open source DNS servers today
•APIs and Databases
•Motivation: GeoIP in Knot-DNS
•discusses EDNS Client ID Subnet option
• available in PowerDNS
• will be in Knot-DNS
• Remark from Vicky Risk (ISC): Client ID Subnet will be in BIND 9.11
21
https://ripe71.ripe.net/archives/video/1223/
© Men & Mice http://menandmice.com
Turris Router / Turris Omnia
• open source router software and
hardware
• motivation: probe for security research
• automatic quick updates
• check outgoing traffic - find IoT devices
that "talk home"
• can run honeypots (telnet and ssh),
tunneled to central servers
• attacker similarity analysis
• container virtualisation for own
application (e.g. OwnCloud, Mailserver
…)
• based on OpenWRT Linux
• https://www.turris.cz
22
https://ripe71.ripe.net/archives/video/1178/
© Men & Mice http://menandmice.com
Turris Router / Turris Omnia
•Turris Omnia - Indiegogo
Crowdfounded Turris Router for
everyone
• powerful home router with VLAN
support
• Fiber support on WAN port
• Hardware RNG
• programmable LEDs
• runs Knot-Resolver for DNSSEC
validation
•https://www.indiegogo.com/projects/
turris-omnia-hi-performance-open-source-
router#/
23
© Men & Mice http://menandmice.com
A Measurement of SMTP over TLS
•Measurement of TLS
use between mail
servers
•motivated by DANE
•"there’s no secure e-
mail without DNSSEC"
24
https://ripe71.ripe.net/archives/video/1344/
© Men & Mice http://menandmice.com
Automatic Certificate Issuance
•Let's encrypt - CA
• ACME Protocol - can be used
with any CA
• Internet Draft 

"draft-ietf-acme-acme"
•Alternative ACME clients
•BASH Shell Script:

https://github.com/lukas2511/letsencrypt.sh
•Tiny (200 Lines) Python Script:

https://github.com/diafygi/acme-tiny
•Let's encrypt statistics

https://letsencrypt.org/stats/
25
https://ripe71.ripe.net/archives/video/4/
© Men & Mice http://menandmice.com
Todays mobile internet
•Mobile devices are 40% of the
Internet hosts
•Desktop/Laptop devices are on
the decline
• Mobile world is build on NAT
and CGN, a different Internet as
we know it
• no End-to-End
• Dual-Stack costs double in
Mobile
• IPv6 in the mobile device market
26
https://ripe71.ripe.net/archives/video/1343/
© Men & Mice http://menandmice.com
IPv6 Performance
•another online ad measurement
• TCPv6 reliability
• IPv6 vs IPv4 performance
• comparison 2011 vs 2015
• 2011 - 40% IPv6 failure rate - tunnels
• 2015 - 4.1% IPv6 failure rate - still 6to4
• 2015 - 2% failure without tunnel
• IPv6 failure still not good
• 48% of connections IPv6 is faster
(unicast)
• 52% of connections IPv4 is faster
(unicast)
27
https://ripe71.ripe.net/archives/video/1219/
© Men & Mice http://menandmice.com
A look under the Hood at
Devices, Networks and IPv6
•another APNIC Advertisement-
Network-measurement story
• AD network measurements
switch from Flash to HTML5 (Sep
11 2015)
• since then, more mobile devices
in the data set
• 464XLAT = Android and iOS (no
XLAT464)

(comparison of different provider)
• 25% of devices in the US are
IPv6 capable
28
https://ripe71.ripe.net/archives/video/1123/
© Men & Mice http://menandmice.com
don't miss our next webinar
•"DNSTap", Wednesday,December 16th, 2015
•Time: 4:00 CET/ 3:00 GMT / 10 EDT / 7 PDT
•DNSTAP- have a deep look into DNS server operations (featuring Unbound and Knot-
DNS).
•Administrators want to know about the queries their DNS server is working on, and
about the responses sent back to clients. Using traditional logging (to file or syslog) is
resource intensive and can slow down the whole DNS server.
•DNSTAP is a new open technology, reading DNS server state events directly from the
core of the DNS server, and making sure that performance loss is minimal while
instrumentation is enabled.
•The webinar will show DNSTAP implementation in Knot-DNS and Unbound,together with
available tools to analyze the DNSTAP datastream.



Signup @ 

https://www.menandmice.com/resources/educational-resources/webinars/
29
© Men & Mice http://menandmice.com
Q/A
30
?
2015 Schedule, Slides, Links, Recording and errata
can be found @

https://www.menandmice.com/resources/educational-resources/webinars/

More Related Content

What's hot

DNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing SolutionsDNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing Solutions
Men and Mice
 
The CAA-Record for increased encryption security
The CAA-Record for increased encryption securityThe CAA-Record for increased encryption security
The CAA-Record for increased encryption security
Men and Mice
 
How to send DNS over anything encrypted
How to send DNS over anything encryptedHow to send DNS over anything encrypted
How to send DNS over anything encrypted
Men and Mice
 
The DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rollsThe DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rolls
Men and Mice
 
Namespaces for Local Networks
Namespaces for Local NetworksNamespaces for Local Networks
Namespaces for Local Networks
Men and Mice
 
Part 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows NetworksPart 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows Networks
Men and Mice
 
DNSSEC signing Tutorial
DNSSEC signing Tutorial DNSSEC signing Tutorial
DNSSEC signing Tutorial
Men and Mice
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report Webinar
Men and Mice
 
The KNOT DNS Server
The KNOT DNS ServerThe KNOT DNS Server
The KNOT DNS Server
Men and Mice
 
Why Managed Service Providers Should Embrace Container Technology
Why Managed Service Providers Should Embrace Container TechnologyWhy Managed Service Providers Should Embrace Container Technology
Why Managed Service Providers Should Embrace Container Technology
Sagi Brody
 
HAProxy scale out using open source
HAProxy scale out using open sourceHAProxy scale out using open source
HAProxy scale out using open source
Ingo Walz
 
Observability with HAProxy
Observability with HAProxyObservability with HAProxy
Observability with HAProxy
HAProxy Technologies
 
SMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANESMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANE
Men and Mice
 
HTTP2:新的机遇与挑战
HTTP2:新的机遇与挑战HTTP2:新的机遇与挑战
HTTP2:新的机遇与挑战
Jerry Qu
 
Oracle Sandbox
Oracle SandboxOracle Sandbox
Oracle SandboxDatavail
 
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
APNIC
 
Apache Httpd and TLS certificates validations
Apache Httpd and TLS certificates validationsApache Httpd and TLS certificates validations
Apache Httpd and TLS certificates validations
Jean-Frederic Clere
 
Windows 2012 and DNSSEC
Windows 2012 and DNSSECWindows 2012 and DNSSEC
Windows 2012 and DNSSEC
Men and Mice
 
NGINX: Basics & Best Practices - EMEA Broadcast
NGINX: Basics & Best Practices - EMEA BroadcastNGINX: Basics & Best Practices - EMEA Broadcast
NGINX: Basics & Best Practices - EMEA Broadcast
NGINX, Inc.
 

What's hot (20)

DNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing SolutionsDNS High-Availability Tools - Open-Source Load Balancing Solutions
DNS High-Availability Tools - Open-Source Load Balancing Solutions
 
The CAA-Record for increased encryption security
The CAA-Record for increased encryption securityThe CAA-Record for increased encryption security
The CAA-Record for increased encryption security
 
How to send DNS over anything encrypted
How to send DNS over anything encryptedHow to send DNS over anything encrypted
How to send DNS over anything encrypted
 
The DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rollsThe DNSSEC KSK of the root rolls
The DNSSEC KSK of the root rolls
 
Namespaces for Local Networks
Namespaces for Local NetworksNamespaces for Local Networks
Namespaces for Local Networks
 
Part 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows NetworksPart 2 - Local Name Resolution in Windows Networks
Part 2 - Local Name Resolution in Windows Networks
 
DNSSEC signing Tutorial
DNSSEC signing Tutorial DNSSEC signing Tutorial
DNSSEC signing Tutorial
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report Webinar
 
The KNOT DNS Server
The KNOT DNS ServerThe KNOT DNS Server
The KNOT DNS Server
 
Why Managed Service Providers Should Embrace Container Technology
Why Managed Service Providers Should Embrace Container TechnologyWhy Managed Service Providers Should Embrace Container Technology
Why Managed Service Providers Should Embrace Container Technology
 
HAProxy scale out using open source
HAProxy scale out using open sourceHAProxy scale out using open source
HAProxy scale out using open source
 
Observability with HAProxy
Observability with HAProxyObservability with HAProxy
Observability with HAProxy
 
SMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANESMTP STS (Strict Transport Security) vs. SMTP with DANE
SMTP STS (Strict Transport Security) vs. SMTP with DANE
 
HTTP2:新的机遇与挑战
HTTP2:新的机遇与挑战HTTP2:新的机遇与挑战
HTTP2:新的机遇与挑战
 
Oracle Sandbox
Oracle SandboxOracle Sandbox
Oracle Sandbox
 
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
 
Apache Httpd and TLS certificates validations
Apache Httpd and TLS certificates validationsApache Httpd and TLS certificates validations
Apache Httpd and TLS certificates validations
 
Dnssec
DnssecDnssec
Dnssec
 
Windows 2012 and DNSSEC
Windows 2012 and DNSSECWindows 2012 and DNSSEC
Windows 2012 and DNSSEC
 
NGINX: Basics & Best Practices - EMEA Broadcast
NGINX: Basics & Best Practices - EMEA BroadcastNGINX: Basics & Best Practices - EMEA Broadcast
NGINX: Basics & Best Practices - EMEA Broadcast
 

Similar to RIPE 71 and IETF 94 reports webinar

Panel with IPv6 CE Vendors
Panel with IPv6 CE VendorsPanel with IPv6 CE Vendors
Panel with IPv6 CE Vendors
APNIC
 
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenchesInternet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
APNIC
 
Encrypted DNS - DNS over TLS / DNS over HTTPS
Encrypted DNS - DNS over TLS / DNS over HTTPSEncrypted DNS - DNS over TLS / DNS over HTTPS
Encrypted DNS - DNS over TLS / DNS over HTTPS
Alex Mayrhofer
 
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
APNIC
 
WebRTC Standards & Implementation Q&A - IP address privacy revisited
WebRTC Standards & Implementation Q&A - IP address privacy revisitedWebRTC Standards & Implementation Q&A - IP address privacy revisited
WebRTC Standards & Implementation Q&A - IP address privacy revisited
Amir Zmora
 
Fb i pv6-sparchimanv1.0
Fb i pv6-sparchimanv1.0Fb i pv6-sparchimanv1.0
Fb i pv6-sparchimanv1.0
Fred Bovy
 
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSECMAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
Shumon Huque
 
Dead Men Walking: IPv6 and DNSSEC
Dead Men Walking: IPv6 and DNSSECDead Men Walking: IPv6 and DNSSEC
Dead Men Walking: IPv6 and DNSSEC
Deploy360 Programme (Internet Society)
 
Phifer 3 30_04
Phifer 3 30_04Phifer 3 30_04
Phifer 3 30_04
Ayano Midakso
 
Hadoop operations-2014-strata-new-york-v5
Hadoop operations-2014-strata-new-york-v5Hadoop operations-2014-strata-new-york-v5
Hadoop operations-2014-strata-new-york-v5
Chris Nauroth
 
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
Cloud Native Day Tel Aviv
 
Oracle E-Business Suite On Oracle Cloud
Oracle E-Business Suite On Oracle CloudOracle E-Business Suite On Oracle Cloud
Oracle E-Business Suite On Oracle Cloud
pasalapudi
 
Rolling the Root Zone DNSSEC Key Signing Key
Rolling the Root Zone DNSSEC Key Signing KeyRolling the Root Zone DNSSEC Key Signing Key
Rolling the Root Zone DNSSEC Key Signing Key
APNIC
 
8 technical-dns-workshop-day4
8 technical-dns-workshop-day48 technical-dns-workshop-day4
8 technical-dns-workshop-day4
DNS Entrepreneurship Center
 
APNIC Update
APNIC Update APNIC Update
APNIC Update
APNIC
 
Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?
APNIC
 
Oracle RAC and Docker: The Why and How
Oracle RAC and Docker: The Why and HowOracle RAC and Docker: The Why and How
Oracle RAC and Docker: The Why and How
Seth Miller
 
IBM Aspera overview
IBM Aspera overview IBM Aspera overview
IBM Aspera overview
Carlos Martin Hernandez
 

Similar to RIPE 71 and IETF 94 reports webinar (20)

Panel with IPv6 CE Vendors
Panel with IPv6 CE VendorsPanel with IPv6 CE Vendors
Panel with IPv6 CE Vendors
 
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenchesInternet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
 
Encrypted DNS - DNS over TLS / DNS over HTTPS
Encrypted DNS - DNS over TLS / DNS over HTTPSEncrypted DNS - DNS over TLS / DNS over HTTPS
Encrypted DNS - DNS over TLS / DNS over HTTPS
 
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
 
WebRTC Standards & Implementation Q&A - IP address privacy revisited
WebRTC Standards & Implementation Q&A - IP address privacy revisitedWebRTC Standards & Implementation Q&A - IP address privacy revisited
WebRTC Standards & Implementation Q&A - IP address privacy revisited
 
Presd1 09
Presd1 09Presd1 09
Presd1 09
 
Fb i pv6-sparchimanv1.0
Fb i pv6-sparchimanv1.0Fb i pv6-sparchimanv1.0
Fb i pv6-sparchimanv1.0
 
guna_2015.DOC
guna_2015.DOCguna_2015.DOC
guna_2015.DOC
 
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSECMAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
 
Dead Men Walking: IPv6 and DNSSEC
Dead Men Walking: IPv6 and DNSSECDead Men Walking: IPv6 and DNSSEC
Dead Men Walking: IPv6 and DNSSEC
 
Phifer 3 30_04
Phifer 3 30_04Phifer 3 30_04
Phifer 3 30_04
 
Hadoop operations-2014-strata-new-york-v5
Hadoop operations-2014-strata-new-york-v5Hadoop operations-2014-strata-new-york-v5
Hadoop operations-2014-strata-new-york-v5
 
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
Born to be fast! - Aviram Bar Haim - OpenStack Israel 2017
 
Oracle E-Business Suite On Oracle Cloud
Oracle E-Business Suite On Oracle CloudOracle E-Business Suite On Oracle Cloud
Oracle E-Business Suite On Oracle Cloud
 
Rolling the Root Zone DNSSEC Key Signing Key
Rolling the Root Zone DNSSEC Key Signing KeyRolling the Root Zone DNSSEC Key Signing Key
Rolling the Root Zone DNSSEC Key Signing Key
 
8 technical-dns-workshop-day4
8 technical-dns-workshop-day48 technical-dns-workshop-day4
8 technical-dns-workshop-day4
 
APNIC Update
APNIC Update APNIC Update
APNIC Update
 
Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?
 
Oracle RAC and Docker: The Why and How
Oracle RAC and Docker: The Why and HowOracle RAC and Docker: The Why and How
Oracle RAC and Docker: The Why and How
 
IBM Aspera overview
IBM Aspera overview IBM Aspera overview
IBM Aspera overview
 

More from Men and Mice

Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network StrategiesCisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Men and Mice
 
Fighting Abuse with DNS
Fighting Abuse with DNSFighting Abuse with DNS
Fighting Abuse with DNS
Men and Mice
 
PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2
Men and Mice
 
PowerDNS Webinar
PowerDNS Webinar PowerDNS Webinar
PowerDNS Webinar
Men and Mice
 
IETF 93 Review Webinar
IETF 93 Review WebinarIETF 93 Review Webinar
IETF 93 Review Webinar
Men and Mice
 
DNSSEC best practices Webinar
DNSSEC best practices WebinarDNSSEC best practices Webinar
DNSSEC best practices Webinar
Men and Mice
 
IETF 92 Webinar
IETF 92 WebinarIETF 92 Webinar
IETF 92 Webinar
Men and Mice
 
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
Men and Mice
 
DNSSEC and DANE – E-Mail security reloaded
DNSSEC and DANE – E-Mail security reloadedDNSSEC and DANE – E-Mail security reloaded
DNSSEC and DANE – E-Mail security reloaded
Men and Mice
 
IETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANEIETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANE
Men and Mice
 
RIPE 68 Webinar
RIPE 68 WebinarRIPE 68 Webinar
RIPE 68 Webinar
Men and Mice
 
Scripting and automation with the Men & Mice Suite
Scripting and automation with the Men & Mice SuiteScripting and automation with the Men & Mice Suite
Scripting and automation with the Men & Mice Suite
Men and Mice
 

More from Men and Mice (12)

Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network StrategiesCisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
Cisco Live 2019: New Best Practices for Hybrid and Multicloud Network Strategies
 
Fighting Abuse with DNS
Fighting Abuse with DNSFighting Abuse with DNS
Fighting Abuse with DNS
 
PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2PowerDNS Webinar - Part 2
PowerDNS Webinar - Part 2
 
PowerDNS Webinar
PowerDNS Webinar PowerDNS Webinar
PowerDNS Webinar
 
IETF 93 Review Webinar
IETF 93 Review WebinarIETF 93 Review Webinar
IETF 93 Review Webinar
 
DNSSEC best practices Webinar
DNSSEC best practices WebinarDNSSEC best practices Webinar
DNSSEC best practices Webinar
 
IETF 92 Webinar
IETF 92 WebinarIETF 92 Webinar
IETF 92 Webinar
 
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
RIPE 69 & IETF 91 Webinar - DNS-Privacy, IPv6, DANE and DHCP(v6)
 
DNSSEC and DANE – E-Mail security reloaded
DNSSEC and DANE – E-Mail security reloadedDNSSEC and DANE – E-Mail security reloaded
DNSSEC and DANE – E-Mail security reloaded
 
IETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANEIETF 90 Report – DNS, DHCP, IPv6 and DANE
IETF 90 Report – DNS, DHCP, IPv6 and DANE
 
RIPE 68 Webinar
RIPE 68 WebinarRIPE 68 Webinar
RIPE 68 Webinar
 
Scripting and automation with the Men & Mice Suite
Scripting and automation with the Men & Mice SuiteScripting and automation with the Men & Mice Suite
Scripting and automation with the Men & Mice Suite
 

Recently uploaded

20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
KAMESHS29
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
Rohit Gautam
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
ThomasParaiso2
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
mikeeftimakis1
 
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex ProofszkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
Alex Pruden
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
Neo4j
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Aggregage
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 

Recently uploaded (20)

20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
 
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex ProofszkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
zkStudyClub - Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex Proofs
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 

RIPE 71 and IETF 94 reports webinar

  • 1. © Men & Mice http://menandmice.com IETF 94 Review 
 10th December 2015 1 IETF 94 Yokohama November 1-6, 2015
  • 2. © Men & Mice http://menandmice.com before we start … please note: Windows DNS security issue December 8, 2015 MS15-127: Security update for Microsoft Windows DNS to address remote code execution: https://support.microsoft.com/en-us/kb/3100465 2
  • 3. © Men & Mice http://menandmice.com Agenda DNS, DNSSEC, DANE, IPv6 IETF 94 in Yokohama RIPE 71 in Bucharest the following information is an excerpt of the IETF working group activities for a full overview of all activities at IETF 94, see 
 https://datatracker.ietf.org/meeting/94/materials.html 3
  • 4. © Men & Mice http://menandmice.com DNS 4
  • 5. © Men & Mice http://menandmice.com new DNS related RFCs 
 published since last IETF 5 RFC Title Category 7720 DNS Root Name Service Protocol and Deployment Requirements BCP 7712 Domain Name Associations (DNA) in the Extensible Messaging and Presence Protocol (XMPP) Proposed Standard 7706 Decreasing Access Time to Root Servers by Running One on Loopback Informational 7686 The ".onion" Special-Use Domain Name Proposed Standard 7673 Using DNS-Based Authentication of Named Entities (DANE) TLSA Records with SRV Records Proposed Standard
  • 6. © Men & Mice http://menandmice.com new DNS related RFCs 
 published since last IETF 6 RFC Title Category 7672 SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Proposed Standard 7671 The DNS-Based Authentication of Named Entities (DANE) Protocol: Updates and Operational Guidance Proposed Standard 7646 Definition and Use of DNSSEC Negative Trust Anchors Informational 7626 DNS Privacy Considerations Informational
  • 7. © Men & Mice http://menandmice.com DNS Record Type for SMIMEA SMIMEA-Records now have a dedicated DNS record type (Type 53) ! SMIMEA - store x509 Certificate information for 
 S/MIME in DNSSEC secured DNS 7
  • 8. © Men & Mice http://menandmice.com draft-jabley-dnsop-ordered-answers do resource records in a DNS section have an order some WinDNS expects OPT as first record(?) TSIG/SIG(0) need order some DNS resolver need Data-Records and RRSIG to be in order (first data, then RRSIG) document was rejected by the working group, but interesting discussion 8
  • 9. © Men & Mice http://menandmice.com draft-ogud-dnsop-maintain-ds Paul Wouters
 presented a new 
 draft on how the
 management of DS-
 Records can be auto-
 mated •how to publish the initial DS-record •how to remove an existing DS-record 9
  • 10. © Men & Mice http://menandmice.com draft-wessels-edns-key-tag Goal: measure RFC 5011 Root-KSK-
 Rollover trust-anchor updates DNS resolver send KSK-
 Trust-Anchor-Keytags to 
 authoritative server •only for QTYPE=DNSKEY, SHOULD for configured trust anchors •DNS forwarding is tricky (can be different trust anchors) •privacy/security considerations 10
  • 11. © Men & Mice http://menandmice.com DNAME in the Root?/ NXDOMAIN = NXDOMAIN DNAME in the Root? • ".local" is 2nd or 3rd popular TLD • redirect ".local" with DNAME to AS112
 
 NXDOMAIN means NXDOMAIN • DNS resolver should stop domain search when encountering a NXDOMAIN in the cache tree • helps with QNAME minimisation and with some random qname attack • breaks Split-Horizon setups 11
  • 12. © Men & Mice http://menandmice.com IPv6 12
  • 13. © Men & Mice http://menandmice.com published new RFCs since last IETF 13 RFC Title Category RFC 7610 DHCPv6-Shield: Protecting against Rogue DHCPv6 Servers BCP RFC 7653 DHCPv6 Active Leasequery Proposed Standard RFC 7668 IPv6 over BLUETOOTH(R) Low Energy Proposed Standard RFC 7676 IPv6 Support for Generic Routing Encapsulation (GRE) Proposed Standard
  • 14. © Men & Mice http://menandmice.com draft-jjmb-v6ops-unique-ipv6-prefix- per-host •ComCast public WIFI trial • /64 Prefix for each WIFI access device • solves DAD, isolation between devices 14
  • 15. © Men & Mice http://menandmice.com draft-ietf-v6ops-design-choices •Enterprise IPv6 
 networks are in scope of the document • all options for enterprises today have issues • long discussion on ULA and "NPT66" (Option 3 of the "how to get IPv6 address space" section) 15
  • 16. © Men & Mice http://menandmice.com Temporal and Spatial Classification of Active IPv6 Addresses • IPv6 operational study by Akamai •classifies IPv6 addresses seen by their CDN network •temporal - how long are IPv6 addresses/ prefixes used •spatial - location of IPv6 addresses • almost no EUI48 Host-Identifier (good) • > 90 % IPv6 are privacy addresses • maps the IPv6 address space in use 16
  • 17. © Men & Mice http://menandmice.com RIPE 71 17
  • 18. © Men & Mice http://menandmice.com Impact of DNS over TCP
 a Resolver Point of View •study made with an medium 
 size ISP (200-400 qps) •TCP timeout management
 is important •message sizes due to 
 DNSSEC no problem, most 
 DNSSEC answers are below Ethernet MTU < 1500 byte • connection reuse only beneficial for certain servers (DNS resolver for a mail server) 18 https://ripe71.ripe.net/archives/video/1209/
  • 19. © Men & Mice http://menandmice.com Preparing the Root-Zone KSK Roll •Root-KSK roll with 
 use RFC 5011 
 protocol •KSK roll will probably 
 take 6-9 month in total •KSK rollover plan not
 yet final • announce mailing list
 https://mm.icann.org/mailman/listinfo/root-dnssec-announce 19 https://ripe71.ripe.net/archives/video/1225/
  • 20. © Men & Mice http://menandmice.com DNSSEC for legacy applications •getdns nsswitch module to 
 replace default OS stub resolver • works on nsswitch enabled
 applications, but not with 
 Chrome and related browsers
 (or application with an internal
 DNS resolver) • configuration web-ui • supports caching and DNS 
 over TLS • checks process name, 
 rewrites answer in case a known web browser is detected • only proof of concept, not production code • SIDN is working on a similar signalling with Unbound 20 https://ripe71.ripe.net/archives/video/1221/
  • 21. © Men & Mice http://menandmice.com Implementation Challenges of Geographic Split-Horizon •overview of DNS-GeoIP 
 implementations available in
 open source DNS servers today •APIs and Databases •Motivation: GeoIP in Knot-DNS •discusses EDNS Client ID Subnet option • available in PowerDNS • will be in Knot-DNS • Remark from Vicky Risk (ISC): Client ID Subnet will be in BIND 9.11 21 https://ripe71.ripe.net/archives/video/1223/
  • 22. © Men & Mice http://menandmice.com Turris Router / Turris Omnia • open source router software and hardware • motivation: probe for security research • automatic quick updates • check outgoing traffic - find IoT devices that "talk home" • can run honeypots (telnet and ssh), tunneled to central servers • attacker similarity analysis • container virtualisation for own application (e.g. OwnCloud, Mailserver …) • based on OpenWRT Linux • https://www.turris.cz 22 https://ripe71.ripe.net/archives/video/1178/
  • 23. © Men & Mice http://menandmice.com Turris Router / Turris Omnia •Turris Omnia - Indiegogo Crowdfounded Turris Router for everyone • powerful home router with VLAN support • Fiber support on WAN port • Hardware RNG • programmable LEDs • runs Knot-Resolver for DNSSEC validation •https://www.indiegogo.com/projects/ turris-omnia-hi-performance-open-source- router#/ 23
  • 24. © Men & Mice http://menandmice.com A Measurement of SMTP over TLS •Measurement of TLS use between mail servers •motivated by DANE •"there’s no secure e- mail without DNSSEC" 24 https://ripe71.ripe.net/archives/video/1344/
  • 25. © Men & Mice http://menandmice.com Automatic Certificate Issuance •Let's encrypt - CA • ACME Protocol - can be used with any CA • Internet Draft 
 "draft-ietf-acme-acme" •Alternative ACME clients •BASH Shell Script:
 https://github.com/lukas2511/letsencrypt.sh •Tiny (200 Lines) Python Script:
 https://github.com/diafygi/acme-tiny •Let's encrypt statistics
 https://letsencrypt.org/stats/ 25 https://ripe71.ripe.net/archives/video/4/
  • 26. © Men & Mice http://menandmice.com Todays mobile internet •Mobile devices are 40% of the Internet hosts •Desktop/Laptop devices are on the decline • Mobile world is build on NAT and CGN, a different Internet as we know it • no End-to-End • Dual-Stack costs double in Mobile • IPv6 in the mobile device market 26 https://ripe71.ripe.net/archives/video/1343/
  • 27. © Men & Mice http://menandmice.com IPv6 Performance •another online ad measurement • TCPv6 reliability • IPv6 vs IPv4 performance • comparison 2011 vs 2015 • 2011 - 40% IPv6 failure rate - tunnels • 2015 - 4.1% IPv6 failure rate - still 6to4 • 2015 - 2% failure without tunnel • IPv6 failure still not good • 48% of connections IPv6 is faster (unicast) • 52% of connections IPv4 is faster (unicast) 27 https://ripe71.ripe.net/archives/video/1219/
  • 28. © Men & Mice http://menandmice.com A look under the Hood at Devices, Networks and IPv6 •another APNIC Advertisement- Network-measurement story • AD network measurements switch from Flash to HTML5 (Sep 11 2015) • since then, more mobile devices in the data set • 464XLAT = Android and iOS (no XLAT464)
 (comparison of different provider) • 25% of devices in the US are IPv6 capable 28 https://ripe71.ripe.net/archives/video/1123/
  • 29. © Men & Mice http://menandmice.com don't miss our next webinar •"DNSTap", Wednesday,December 16th, 2015 •Time: 4:00 CET/ 3:00 GMT / 10 EDT / 7 PDT •DNSTAP- have a deep look into DNS server operations (featuring Unbound and Knot- DNS). •Administrators want to know about the queries their DNS server is working on, and about the responses sent back to clients. Using traditional logging (to file or syslog) is resource intensive and can slow down the whole DNS server. •DNSTAP is a new open technology, reading DNS server state events directly from the core of the DNS server, and making sure that performance loss is minimal while instrumentation is enabled. •The webinar will show DNSTAP implementation in Knot-DNS and Unbound,together with available tools to analyze the DNSTAP datastream.
 
 Signup @ 
 https://www.menandmice.com/resources/educational-resources/webinars/ 29
  • 30. © Men & Mice http://menandmice.com Q/A 30 ? 2015 Schedule, Slides, Links, Recording and errata can be found @
 https://www.menandmice.com/resources/educational-resources/webinars/