<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Patrick is a good resource. I support that he be invited.<br><br><div><hr id="stopSpelling">Date: Fri, 27 May 2016 15:05:08 +0200<br>From: farzaneh.badii@GMAIL.COM<br>Subject: Re: DNSSEC key rollover issues<br>To: NCSG-DISCUSS@LISTSERV.SYR.EDU<br><br><div dir="ltr">We can invite Patrik Falstrom and have a training session. </div><div class="ecxgmail_extra"><br><div class="ecxgmail_quote">On 27 May 2016 at 14:56, James Gannon <span dir="ltr"><<a href="mailto:james@cyberinvasion.net" target="_blank">james@cyberinvasion.net</a>></span> wrote:<br><blockquote class="ecxgmail_quote" style="border-left:1px #ccc solid;padding-left:1ex;">I like that idea. Lets try and gather some info before Helsinki and see if this is something we need to put time into and where our time is best spent.<br>
<span class="ecxHOEnZb"><font color="#888888"><br>
-jg<br>
</font></span><div class="ecxHOEnZb"><div class="h5"><br>
<br>
<br>
<br>
On 27/05/2016, 13:55, "Niels ten Oever" <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>> wrote:<br>
<br>
>Perhaps we can reach out to Michele and see where this is on their<br>
>agenda? Shall I do so? Do other people share this concern?<br>
><br>
>Cheers,<br>
><br>
>Niels<br>
><br>
>On 05/27/2016 02:38 PM, James Gannon wrote:<br>
>> Agreed, so do I see you volunteering to lead this effort? =)<br>
>> Happy to assist/help out where I can!<br>
>><br>
>> -JG<br>
>><br>
>><br>
>><br>
>> On 27/05/2016, 12:46, "NCSG-Discuss on behalf of Niels ten Oever" <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a> on behalf of <a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a>> wrote:<br>
>><br>
>>> Hi Rafik,<br>
>>><br>
>>> The DNSSEC for Everybody is great and fun, but it's more a very rough<br>
>>> 101. The DNSSEC workshop is also great, but it doesn't help you when you<br>
>>> are behind a production terminal. Good documentation is needed. Or we<br>
>>> need to find out better why adoption levels are so low.<br>
>>><br>
>>> Is this something we can bring up?<br>
>>><br>
>>> I think this is especially an issue for the NCSG because NGO's,<br>
>>> activists and individual users will greatly benefit from increased<br>
>>> trust, and more protection against DNS poisoining. With the enormous<br>
>>> success of Let's Encrypt (1 milltion certs distributed, covering >2.5<br>
>>> million domains) DNSSEC is the next logical step, and adoption is still<br>
>>> _very_ low.<br>
>>><br>
>>> Cheers,<br>
>>><br>
>>> Niels<br>
>>><br>
>>><br>
>>> On 05/27/2016 01:34 PM, Rafik Dammak wrote:<br>
>>>> Hi Niels,<br>
>>>><br>
>>>> ICANN organizes regularly for many years now in each ICANN meeting 2<br>
>>>> DNSSec sessions related:<br>
>>>><br>
>>>>   * DNSSEC Workshop<br>
>>>>   * DNSSEC for Everybody: A Beginner's Guide<br>
>>>><br>
>>>> there are also also DNSSec session during conferences like African<br>
>>>> Internet Summit (<a href="https://internetsummitafrica.org/programme/agenda" rel="noreferrer" target="_blank">https://internetsummitafrica.org/programme/agenda</a>),<br>
>>>> <a href="https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/" rel="noreferrer" target="_blank">https://nsrc.org/workshops/2013/nsrc-ati-tn-dnssec/</a> or  ICANN DNS forum<br>
>>>> . my understanding is that ICANN tech team helped some ccTLD<br>
>>>> operators <a href="http://dnssec-africa.org/" rel="noreferrer" target="_blank">http://dnssec-africa.org/</a><br>
>>>><br>
>>>> I don't think there are specific activities toward registrars per se.<br>
>>>><br>
>>>> Best,<br>
>>>><br>
>>>> Rafik<br>
>>>><br>
>>>> 2016-05-27 20:21 GMT+09:00 Niels ten Oever <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a><br>
>>>> <mailto:<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>>>:<br>
>>>><br>
>>>>     Hi James,<br>
>>>><br>
>>>>     On 05/26/2016 12:12 PM, James Gannon wrote:<br>
>>>>     > No sorry what are the specific issues, i.e. In understanding the KSK<br>
>>>>     > and ZSK keys, in documentation etc? Do DNS engineers at hosting<br>
>>>>     > companies really not understand it?<br>
>>>>     ><br>
>>>>     > Because there is a large amount of documentation out there for<br>
>>>>     > example on configuring DNSSEC in Bind and while yes deploying at<br>
>>>>     > scale is a risk that registrars would need to analysise and take an<br>
>>>>     > internal risk position on Im not sure I understand the ‘even the most<br>
>>>>     > experienced engineers don’t understand it’ part of the question.<br>
>>>>     ><br>
>>>>     > The rest I do for sure, adoption of DNSSEC is a big topic, but there<br>
>>>>     > is huge amount son work going on in both ICANN and ISOC supporting<br>
>>>>     > registrars who wish to move down that path in a stable and secure<br>
>>>>     > path. ISOC has documentation specifically targeting at registrars<br>
>>>>     > <a href="http://www.internetsociety.org/deploy360/resources/dnssec-registrars/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/resources/dnssec-registrars/</a><br>
>>>>     > I know the RrSG has done some work for ones that are involved in<br>
>>>>     > that, there is also Deplay360 from ISOC<br>
>>>>     > <a href="http://www.internetsociety.org/deploy360/dnssec/" rel="noreferrer" target="_blank">http://www.internetsociety.org/deploy360/dnssec/</a> and a lot of<br>
>>>>     > community support behind it from a technical perspective for those<br>
>>>>     > interested.<br>
>>>>     ><br>
>>>><br>
>>>>     Have been clicking through the ISOC site, but I cannot find a proper<br>
>>>>     how-to or documentation for an indepdendent registrar anywhere.<br>
>>>><br>
>>>>     I think we should push harder for DNSSEC adoption, and ICANN can and<br>
>>>>     should play a role in this imho, why would it be more of an ISOC task<br>
>>>>     than a ICANN task?<br>
>>>><br>
>>>><br>
>>>>     > My question would be what is the thing that needs to be done to<br>
>>>>     > promote adoption, and from what I have seen so far its usually risk<br>
>>>>     > aversion on the business side, and that’s not something that we can<br>
>>>>     > do much about from the ICANN side of things, something I feel ISOC<br>
>>>>     > should focus on more tho.<br>
>>>><br>
>>>>     Business aversion is also because it's hard, and thus will cost more<br>
>>>>     time. Also: more risk because it might break. This does not balance well<br>
>>>>     with the increased trust gained with DNSSEC. We can help tip this scale<br>
>>>>     by making implementation easier through good documentation, no? Looks<br>
>>>>     like an ICANN task par excellence to me!<br>
>>>><br>
>>>>     Cheers,<br>
>>>><br>
>>>>     Niels<br>
>>>><br>
>>>><br>
>>>>     ><br>
>>>>     > -J<br>
>>>>     ><br>
>>>>     ><br>
>>>>     ><br>
>>>>     ><br>
>>>>     > On 26/05/2016, 11:03, "Niels ten Oever"<br>
>>>>     <<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a> <mailto:<a href="mailto:lists@digitaldissidents.org">lists@digitaldissidents.org</a>>><br>
>>>>     > wrote:<br>
>>>>     ><br>
>>>>     >> Do you mean you would like to hear names of registrars that are<br>
>>>>     >> not offering DNSSEC ? Am afraid it is the majority of the SME<br>
>>>>     >> registrars / hosting providers.<br>
>>>>     >><br>
>>>>     >> Cheers,<br>
>>>>     >><br>
>>>>     >> Niels<br>
>>>>     >><br>
>>>>     >> On 05/26/2016 11:57 AM, James Gannon wrote:<br>
>>>>     >>> Have you got any specific examples?<br>
>>>>     >>><br>
>>>>     >>><br>
>>>>     >>><br>
>>>>     >>><br>
>>>>     >>> On 26/05/2016, 10:50, "NCSG-Discuss on behalf of Niels ten Oever"<br>
>>>>     >>> <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br>
>>>>     <mailto:<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>> on behalf of<br>
>>>>     >>> <a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a><br>
>>>>     <mailto:<a href="mailto:lists@DIGITALDISSIDENTS.ORG">lists@DIGITALDISSIDENTS.ORG</a>>> wrote:<br>
>>>>     >>><br>
>>>>     >>>> Hi all,<br>
>>>>     >>>><br>
>>>>     >>>> I have been talking to several registrars (especially smaller<br>
>>>>     >>>> ones that provide a lot of support to NGOs), that do not<br>
>>>>     >>>> provide DNSSEC yet as part of their service.<br>
>>>>     >>>><br>
>>>>     >>>> The story that I keep on hearing is that even the most<br>
>>>>     >>>> experienced engineers have issues with understanding the<br>
>>>>     >>>> configuration of the KSK and Zone signing keys and the key<br>
>>>>     >>>> rollover, inconsistencies in documentation and therefore lack<br>
>>>>     >>>> of adoption, because in case of a mistake this might seriously<br>
>>>>     >>>> impact the production environment.<br>
>>>>     >>>><br>
>>>>     >>>> I think the adoption of DNSSEC is an issue we should care about<br>
>>>>     >>>> because it has the potential to radically increase trust in the<br>
>>>>     >>>> DNS system.<br>
>>>>     >>>><br>
>>>>     >>>> Is this an issue you all recognize, and do you know how / if<br>
>>>>     >>>> ICANN makes (or can make) this easier?<br>
>>>>     >>>><br>
>>>>     >>>> Best,<br>
>>>>     >>>><br>
>>>>     >>>> Niels<br>
>>>>     >>>><br>
>>>>     >>>><br>
>>>>     >>>> -- Niels ten Oever Head of Digital<br>
>>>>     >>>><br>
>>>>     >>>> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>>     >>>><br>
>>>>     >>>> PGP fingerprint    8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>>>>     >>>> 68E9<br>
>>>>     >>>><br>
>>>>     >><br>
>>>>     >> -- Niels ten Oever Head of Digital<br>
>>>>     >><br>
>>>>     >> Article 19 <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>>     >><br>
>>>>     >> PGP fingerprint    8D9F C567 BEE4 A431 56C4 678B 08B5 A0F2 636D<br>
>>>>     >> 68E9<br>
>>>><br>
>>>>     --<br>
>>>>     Niels ten Oever<br>
>>>>     Head of Digital<br>
>>>><br>
>>>>     Article 19<br>
>>>>     <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a> <<a href="http://www.article19.org" rel="noreferrer" target="_blank">http://www.article19.org</a>><br>
>>>><br>
>>>>     PGP fingerprint    8D9F C567 BEE4 A431 56C4<br>
>>>>                        678B 08B5 A0F2 636D 68E9<br>
>>>><br>
>>>><br>
>>><br>
>>> --<br>
>>> Niels ten Oever<br>
>>> Head of Digital<br>
>>><br>
>>> Article 19<br>
>>> <a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
>>><br>
>>> PGP fingerprint    8D9F C567 BEE4 A431 56C4<br>
>>>                   678B 08B5 A0F2 636D 68E9<br>
><br>
>--<br>
>Niels ten Oever<br>
>Head of Digital<br>
><br>
>Article 19<br>
><a href="http://www.article19.org" rel="noreferrer" target="_blank">www.article19.org</a><br>
><br>
>PGP fingerprint    8D9F C567 BEE4 A431 56C4<br>
>                   678B 08B5 A0F2 636D 68E9<br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="ecxgmail_signature" data-smartmail="gmail_signature">Farzaneh </div>
</div></div>                                          </div></body>
</html>