<div dir="ltr"><div class="gmail_extra">Hi Niels,</div><div class="gmail_extra"><br></div><div class="gmail_extra">ICANN organizes regularly for many years now in each ICANN meeting 2 DNSSec sessions related:</div><div class="gmail_extra"><ul><li>DNSSEC Workshop<br></li><li>DNSSEC for Everybody: A Beginner's Guide <br></li></ul></div><div class="gmail_extra">there are also also DNSSec session during conferences like African Internet Summit (<a href="https://internetsummitafrica.org/programme/agenda">https://internetsummitafrica.org/programme/agenda</a>), <a href="https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/">https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/</a> or  ICANN DNS forum . my understanding is that ICANN tech team helped some ccTLD operators <a href="http://dnssec-africa.org/">http://dnssec-africa.org/</a> </div><div class="gmail_extra"><br></div><div class="gmail_extra">I don't think there are specific activities toward registrars per se.</div><div class="gmail_extra"><br></div><div class="gmail_extra">Best,</div><div class="gmail_extra"><br></div><div class="gmail_extra">Rafik</div><div class="gmail_extra"><br></div><div class="gmail_extra"><div class="gmail_quote">2016-05-27 20:21 GMT+09:00 Niels ten Oever <span dir="ltr"><<a href="mailto:lists@digitaldissidents.org" target="_blank">lists@digitaldissidents.org</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">Hi James,<br>
<span class=""><br>
On 05/26/2016 12:12 PM, James Gannon wrote:<br>
> No sorry what are the specific issues, i.e. In understanding the KSK<br>
> and ZSK keys, in documentation etc? Do DNS engineers at hosting<br>
> companies really not understand it?<br>
><br>
> Because there is a large amount of documentation out there for<br>
> example on configuring DNSSEC in Bind and while yes deploying at<br>
> scale is a risk that registrars would need to analysise and take an<br>
> internal risk position on Im not sure I understand the ‘even the most<br>
> experienced engineers don’t understand it’ part of the question.<br>
><br>
> The rest I do for sure, adoption of DNSSEC is a big topic, but there<br>
> is huge amount son work going on in both ICANN and ISOC supporting<br>
> registrars who wish to move down that path in a stable and secure<br>
> path. ISOC has documentation specifically targeting at registrars<br>
> <a href="http://www.internetsociety.org/deploy360/resources/dnssec-registrars/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/resources/dnssec-registrars/</a><br>
> I know the RrSG has done some work for ones that are involved in<br>
> that, there is also Deplay360 from ISOC<br>
> <a href="http://www.internetsociety.org/deploy360/dnssec/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/dnssec/</a> and a lot of<br>
> community support behind it from a technical perspective for those<br>
> interested.<br>
><br>
<br>
</span>Have been clicking through the ISOC site, but I cannot find a proper<br>
how-to or documentation for an indepdendent registrar anywhere.<br>
<br>
I think we should push harder for DNSSEC adoption, and ICANN can and<br>
should play a role in this imho, why would it be more of an ISOC task<br>
than a ICANN task?<br>
<span class=""><br>
<br>
> My question would be what is the thing that needs to be done to<br>
> promote adoption, and from what I have seen so far its usually risk<br>
> aversion on the business side, and that’s not something that we can<br>
> do much about from the ICANN side of things, something I feel ISOC<br>
> should focus on more tho.<br>
<br>
</span>Business aversion is also because it's hard, and thus will cost more<br>
time. Also: more risk because it might break. This does not balance well<br>
with the increased trust gained with DNSSEC. We can help tip this scale<br>
by making implementation easier through good documentation, no? Looks<br>
like an ICANN task par excellence to me!<br>
<br>
Cheers,<br>
<br>
Niels<br>
<div class=""><div class="h5"><br>
<br>
><br>
> -J<br>
><br>
><br>
><br>
><br>
> On 26/05/2016, 11:03, "Niels ten Oever" <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>><br>
> wrote:<br>
><br>
>> Do you mean you would like to hear names of registrars that are<br>
>> not offering DNSSEC ? Am afraid it is the majority of the SME<br>
>> registrars / hosting providers.<br>
>><br>
>> Cheers,<br>
>><br>
>> Niels<br>
>><br>
>> On 05/26/2016 11:57 AM, James Gannon wrote:<br>
>>> Have you got any specific examples?<br>
>>><br>
>>><br>
>>><br>
>>><br>
>>> On 26/05/2016, 10:50, "NCSG-Discuss on behalf of Niels ten Oever"<br>
>>> <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a> on behalf of<br>
>>> <a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a>> wrote:<br>
>>><br>
>>>> Hi all,<br>
>>>><br>
>>>> I have been talking to several registrars (especially smaller<br>
>>>> ones that provide a lot of support to NGOs), that do not<br>
>>>> provide DNSSEC yet as part of their service.<br>
>>>><br>
>>>> The story that I keep on hearing is that even the most<br>
>>>> experienced engineers have issues with understanding the<br>
>>>> configuration of the KSK and Zone signing keys and the key<br>
>>>> rollover, inconsistencies in documentation and therefore lack<br>
>>>> of adoption, because in case of a mistake this might seriously<br>
>>>> impact the production environment.<br>
>>>><br>
>>>> I think the adoption of DNSSEC is an issue we should care about<br>
>>>> because it has the potential to radically increase trust in the<br>
>>>> DNS system.<br>
>>>><br>
>>>> Is this an issue you all recognize, and do you know how / if<br>
>>>> ICANN makes (or can make) this easier?<br>
>>>><br>
>>>> Best,<br>
>>>><br>
>>>> Niels<br>
>>>><br>
>>>><br>
>>>> -- Niels ten Oever Head of Digital<br>
>>>><br>
>>>> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
>>>><br>
>>>> PGP fingerprint    8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>>>> 68E9<br>
>>>><br>
>><br>
>> -- Niels ten Oever Head of Digital<br>
>><br>
>> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
>><br>
>> PGP fingerprint    8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>> 68E9<br>
<br>
--<br>
Niels ten Oever<br>
Head of Digital<br>
<br>
Article 19<br>
<a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
<br>
PGP fingerprint    8D9F C567 BEE4 A431 56C4<br>
                   678B 08B5 A0F2 636D 68E9<br>
</div></div></blockquote></div><br></div></div>