<div dir="ltr">We can invite Patrik Falstrom and have a training session. </div><div class="gmail_extra"><br><div class="gmail_quote">On 27 May 2016 at 14:56, James Gannon <span dir="ltr"><<a href="mailto:james@cyberinvasion.net" target="_blank">james@cyberinvasion.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I like that idea. Lets try and gather some info before Helsinki and see if this is something we need to put time into and where our time is best spent.<br>
<span class="HOEnZb"><font color="#888888"><br>
-jg<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
<br>
<br>
On 27/05/2016, 13:55, "Niels ten Oever" <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>> wrote:<br>
<br>
>Perhaps we can reach out to Michele and see where this is on their<br>
>agenda? Shall I do so? Do other people share this concern?<br>
><br>
>Cheers,<br>
><br>
>Niels<br>
><br>
>On 05/27/2016 02:38 PM, James Gannon wrote:<br>
>> Agreed, so do I see you volunteering to lead this effort? =)<br>
>> Happy to assist/help out where I can!<br>
>><br>
>> -JG<br>
>><br>
>><br>
>><br>
>> On 27/05/2016, 12:46, "NCSG-Discuss on behalf of Niels ten Oever" <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a> on behalf of <a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a>> wrote:<br>
>><br>
>>> Hi Rafik,<br>
>>><br>
>>> The DNSSEC for Everybody is great and fun, but it's more a very rough<br>
>>> 101. The DNSSEC workshop is also great, but it doesn't help you when you<br>
>>> are behind a production terminal. Good documentation is needed. Or we<br>
>>> need to find out better why adoption levels are so low.<br>
>>><br>
>>> Is this something we can bring up?<br>
>>><br>
>>> I think this is especially an issue for the NCSG because NGO's,<br>
>>> activists and individual users will greatly benefit from increased<br>
>>> trust, and more protection against DNS poisoining. With the enormous<br>
>>> success of Let's Encrypt (1 milltion certs distributed, covering >2.5<br>
>>> million domains) DNSSEC is the next logical step, and adoption is still<br>
>>> _very_ low.<br>
>>><br>
>>> Cheers,<br>
>>><br>
>>> Niels<br>
>>><br>
>>><br>
>>> On 05/27/2016 01:34 PM, Rafik Dammak wrote:<br>
>>>> Hi Niels,<br>
>>>><br>
>>>> ICANN organizes regularly for many years now in each ICANN meeting 2<br>
>>>> DNSSec sessions related:<br>
>>>><br>
>>>> * DNSSEC Workshop<br>
>>>> * DNSSEC for Everybody: A Beginner's Guide<br>
>>>><br>
>>>> there are also also DNSSec session during conferences like African<br>
>>>> Internet Summit (<a href="https://internetsummitafrica.org/programme/agenda" rel="noreferrer" target="_blank">https://internetsummitafrica.org/programme/agenda</a>),<br>
>>>> <a href="https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/" rel="noreferrer" target="_blank">https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/</a> or ICANN DNS forum<br>
>>>> . my understanding is that ICANN tech team helped some ccTLD<br>
>>>> operators <a href="http://dnssec-africa.org/" rel="noreferrer" target="_blank">http://dnssec-africa.org/</a><br>
>>>><br>
>>>> I don't think there are specific activities toward registrars per se.<br>
>>>><br>
>>>> Best,<br>
>>>><br>
>>>> Rafik<br>
>>>><br>
>>>> 2016-05-27 20:21 GMT+09:00 Niels ten Oever <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a><br>
>>>> <mailto:<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>>>:<br>
>>>><br>
>>>> Hi James,<br>
>>>><br>
>>>> On 05/26/2016 12:12 PM, James Gannon wrote:<br>
>>>> > No sorry what are the specific issues, i.e. In understanding the KSK<br>
>>>> > and ZSK keys, in documentation etc? Do DNS engineers at hosting<br>
>>>> > companies really not understand it?<br>
>>>> ><br>
>>>> > Because there is a large amount of documentation out there for<br>
>>>> > example on configuring DNSSEC in Bind and while yes deploying at<br>
>>>> > scale is a risk that registrars would need to analysise and take an<br>
>>>> > internal risk position on Im not sure I understand the ‘even the most<br>
>>>> > experienced engineers don’t understand it’ part of the question.<br>
>>>> ><br>
>>>> > The rest I do for sure, adoption of DNSSEC is a big topic, but there<br>
>>>> > is huge amount son work going on in both ICANN and ISOC supporting<br>
>>>> > registrars who wish to move down that path in a stable and secure<br>
>>>> > path. ISOC has documentation specifically targeting at registrars<br>
>>>> > <a href="http://www.internetsociety.org/deploy360/resources/dnssec-registrars/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/resources/dnssec-registrars/</a><br>
>>>> > I know the RrSG has done some work for ones that are involved in<br>
>>>> > that, there is also Deplay360 from ISOC<br>
>>>> > <a href="http://www.internetsociety.org/deploy360/dnssec/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/dnssec/</a> and a lot of<br>
>>>> > community support behind it from a technical perspective for those<br>
>>>> > interested.<br>
>>>> ><br>
>>>><br>
>>>> Have been clicking through the ISOC site, but I cannot find a proper<br>
>>>> how-to or documentation for an indepdendent registrar anywhere.<br>
>>>><br>
>>>> I think we should push harder for DNSSEC adoption, and ICANN can and<br>
>>>> should play a role in this imho, why would it be more of an ISOC task<br>
>>>> than a ICANN task?<br>
>>>><br>
>>>><br>
>>>> > My question would be what is the thing that needs to be done to<br>
>>>> > promote adoption, and from what I have seen so far its usually risk<br>
>>>> > aversion on the business side, and that’s not something that we can<br>
>>>> > do much about from the ICANN side of things, something I feel ISOC<br>
>>>> > should focus on more tho.<br>
>>>><br>
>>>> Business aversion is also because it's hard, and thus will cost more<br>
>>>> time. Also: more risk because it might break. This does not balance well<br>
>>>> with the increased trust gained with DNSSEC. We can help tip this scale<br>
>>>> by making implementation easier through good documentation, no? Looks<br>
>>>> like an ICANN task par excellence to me!<br>
>>>><br>
>>>> Cheers,<br>
>>>><br>
>>>> Niels<br>
>>>><br>
>>>><br>
>>>> ><br>
>>>> > -J<br>
>>>> ><br>
>>>> ><br>
>>>> ><br>
>>>> ><br>
>>>> > On 26/05/2016, 11:03, "Niels ten Oever"<br>
>>>> <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a> <mailto:<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>>><br>
>>>> > wrote:<br>
>>>> ><br>
>>>> >> Do you mean you would like to hear names of registrars that are<br>
>>>> >> not offering DNSSEC ? Am afraid it is the majority of the SME<br>
>>>> >> registrars / hosting providers.<br>
>>>> >><br>
>>>> >> Cheers,<br>
>>>> >><br>
>>>> >> Niels<br>
>>>> >><br>
>>>> >> On 05/26/2016 11:57 AM, James Gannon wrote:<br>
>>>> >>> Have you got any specific examples?<br>
>>>> >>><br>
>>>> >>><br>
>>>> >>><br>
>>>> >>><br>
>>>> >>> On 26/05/2016, 10:50, "NCSG-Discuss on behalf of Niels ten Oever"<br>
>>>> >>> <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br>
>>>> <mailto:<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>> on behalf of<br>
>>>> >>> <a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a><br>
>>>> <mailto:<a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a>>> wrote:<br>
>>>> >>><br>
>>>> >>>> Hi all,<br>
>>>> >>>><br>
>>>> >>>> I have been talking to several registrars (especially smaller<br>
>>>> >>>> ones that provide a lot of support to NGOs), that do not<br>
>>>> >>>> provide DNSSEC yet as part of their service.<br>
>>>> >>>><br>
>>>> >>>> The story that I keep on hearing is that even the most<br>
>>>> >>>> experienced engineers have issues with understanding the<br>
>>>> >>>> configuration of the KSK and Zone signing keys and the key<br>
>>>> >>>> rollover, inconsistencies in documentation and therefore lack<br>
>>>> >>>> of adoption, because in case of a mistake this might seriously<br>
>>>> >>>> impact the production environment.<br>
>>>> >>>><br>
>>>> >>>> I think the adoption of DNSSEC is an issue we should care about<br>
>>>> >>>> because it has the potential to radically increase trust in the<br>
>>>> >>>> DNS system.<br>
>>>> >>>><br>
>>>> >>>> Is this an issue you all recognize, and do you know how / if<br>
>>>> >>>> ICANN makes (or can make) this easier?<br>
>>>> >>>><br>
>>>> >>>> Best,<br>
>>>> >>>><br>
>>>> >>>> Niels<br>
>>>> >>>><br>
>>>> >>>><br>
>>>> >>>> -- Niels ten Oever Head of Digital<br>
>>>> >>>><br>
>>>> >>>> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>> >>>><br>
>>>> >>>> PGP fingerprint 8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>>>> >>>> 68E9<br>
>>>> >>>><br>
>>>> >><br>
>>>> >> -- Niels ten Oever Head of Digital<br>
>>>> >><br>
>>>> >> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>> >><br>
>>>> >> PGP fingerprint 8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>>>> >> 68E9<br>
>>>><br>
>>>> --<br>
>>>> Niels ten Oever<br>
>>>> Head of Digital<br>
>>>><br>
>>>> Article 19<br>
>>>> <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>><br>
>>>> PGP fingerprint 8D9F C567 BEE4 A431 56C4<br>
>>>> 678B 08B5 A0F2 636D 68E9<br>
>>>><br>
>>>><br>
>>><br>
>>> --<br>
>>> Niels ten Oever<br>
>>> Head of Digital<br>
>>><br>
>>> Article 19<br>
>>> <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
>>><br>
>>> PGP fingerprint 8D9F C567 BEE4 A431 56C4<br>
>>> 678B 08B5 A0F2 636D 68E9<br>
><br>
>--<br>
>Niels ten Oever<br>
>Head of Digital<br>
><br>
>Article 19<br>
><a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
><br>
>PGP fingerprint 8D9F C567 BEE4 A431 56C4<br>
> 678B 08B5 A0F2 636D 68E9<br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Farzaneh </div>
</div>