@gregr Hmmm, DNSviz https://dnsviz.net/d/hlaor.realtor/aTEk-A/dnssec/ et Zonemaster https://zonemaster.fr/en/result/4a67792402b3ec73 ne voient pas de problème non plus. Il faut les accuser de laxisme ?
Thanks to @jpmens we now have documentation for Cascade describing how to integrate with a Nitrokey NetHSM to store your DNSSEC keys.
Thanks a lot! 🧡
Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4
https://technotes.seastrom.com/2025/11/23/passing-the-torch.html
#HackerNews #PassingTheTorch #DNSSEC #KSK #Ceremony #CryptoOfficer #InternetSecurity #Cybersecurity
We're excited to send you into the weekend with Cascade 0.1.0-alpha5 ‘Colline de la Croix’.
This release of our #DNSSEC signer prints information about keys and rollovers across all known zones. It will prioritize keys with the soonest rollover actions. It also changes how information is logged at runtime, which is a useful debugging aid.
As always, many thanks to everyone who provided us with feedback and bug reports. We love being on this journey with you! 🧡 #DNS
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-alpha5
Say, @bortzmeyer , we're well on the way to becoming rich and famous!
From the NLnet Labs blog:
> Unveiling a new product to the world is a proud and nerve wracking moment, made wondrous by the enthusiastic and prolific feedback of the community whom we cannot thank enough, with special shout outs to Stéphane Bortzmeyer and JP Mens.
We conclude #IETF week with a new release of Cascade, 0.1.0-alpha4 'Mont-Royal'.
@terts has taken on the brunt of the work, with quality-of-life improvements that make our #DNSSEC signer easier to use and understand.
As always, we appreciate your continued testing and feedback. We're well on our way to our first production release in the first half of 2026.
#IETF124 #DNS #OpenSource #rustlang
https://github.com/NLnetLabs/cascade/releases/tag/v0.1.0-alpha4
As we worked towards the first alpha release of Cascade, we kept an internal backlog of items we want to implement over the next months.
We’ve now made them all public, so you can follow along with our plans and progress:
https://github.com/NLnetLabs/cascade/issues?q=is%3Aissue%20state%3Aopen%20type%3AFeature
Our initial goal until Q1 2026 is to make our #DNSSEC signer as reliable as possible. First, every action in every scenario should be rigorously testable for us and completely understandable for you.
We’ll do a production release in Q2 2026 at the latest, and then build out the functionality from there. We want to hear from you which features are the highest on your wish list. Tell us!
As we worked towards the first alpha release of Cascade, we kept an internal backlog of items we want to implement over the next months.
We’ve now made them all public, so you can follow along with our plans and progress:
https://github.com/NLnetLabs/cascade/issues?q=is%3Aissue%20state%3Aopen%20type%3AFeature
Our initial goal until Q1 2026 is to make our #DNSSEC signer as reliable as possible. First, every action in every scenario should be rigorously testable for us and completely understandable for you.
We’ll do a production release in Q2 2026 at the latest, and then build out the functionality from there. We want to hear from you which features are the highest on your wish list. Tell us!
FOSDEM 2026 DNS Devroom Call For Presentations
https://blog.powerdns.com/2025/11/04/fosdem-2026-dns-devroom-call-for-presentations
FOSDEM 2026 DNS Devroom Call For Presentations
https://blog.powerdns.com/2025/11/04/fosdem-2026-dns-devroom-call-for-presentations
Le rappel du jour que, si vous faites du #DNSSEC, il n'est pas indispensable d'avoir ZSK et KSK. Une seule clé, c'est parfaitement possible et sûr. https://dnsviz.net/d/xn--potamochre-66a.fr/aQnuZg/dnssec/
J'ai déjà parlé de #Cascade, un logiciel de @nlnetlabs actuellement en développement, qui automatise un certain nombre de tâches nécessaires pour #DNSSEC comme la re-signature ou le remplacement des clés. Le projet avance vite donc voyons quelques nouveaux essais.
https://www.bortzmeyer.org/cascade-deux.html
J'ai déjà parlé de #Cascade, un logiciel de @nlnetlabs actuellement en développement, qui automatise un certain nombre de tâches nécessaires pour #DNSSEC comme la re-signature ou le remplacement des clés. Le projet avance vite donc voyons quelques nouveaux essais.
https://www.bortzmeyer.org/cascade-deux.html
Looking forward to present @nlnetlabs’ research on TLD operations in the #DNSSEC and Security Workshop at #ICANN84, starting today at 13:15 hrs UTC.
Looking forward to present @nlnetlabs’ research on TLD operations in the #DNSSEC and Security Workshop at #ICANN84, starting today at 13:15 hrs UTC.