[dns-operations] How much trouble am in in on May 5?

Stephane Bortzmeyer bortzmeyer at nic.fr
Tue May 4 07:38:18 UTC 2010


On Mon, May 03, 2010 at 06:53:25PM -0700,
 Calvin Richards <cal73142 at yahoo.com> wrote 
 a message of 438 lines which said:

> I am not worried that much about our caching servers being able to
> do lookups.  I am worried about is the servers that are acting as
> authorative name servers

You're wrong because it is exactly the opposite. DNSSEC is opt-in so,
if you don't want to (or cannot) sign your zones, fine, nothing will
break and the signing of the root does not mean you have to sign.

But, on the other hand, the only (very small) risk on May 5th is for
the caching servers. _Some_ (probably a very little percentage)
caching name servers will stop to work tomorrow so you still have time
to test:

https://www.dns-oarc.net/oarc/services/replysizetest
http://labs.ripe.net/content/testing-your-resolver-dns-reply-size-issues
http://netalyzr.icsi.berkeley.edu/



More information about the dns-operations mailing list