From dknight at dns-oarc.net Wed Aug 5 21:18:49 2026 From: dknight at dns-oarc.net (Dave Knight) Date: Wed, 5 Aug 2026 17:18:49 -0400 Subject: [dns-operations] Job opportunity: President, DNS-OARC Message-ID: The Domain Name System Operations Analysis and Research Center is seeking its next President. DNS-OARC is a nonprofit membership organization dedicated to improving the security, stability, and understanding of the Internet?s Domain Name System infrastructure. We serve as a trusted and neutral organization within the global DNS community, bringing together technical experts, developing open tools and services, supporting research, and enabling collaboration and incident coordination. The President serves as Chief Executive Officer of OARC Inc. and reports to the Board of Directors. This is a broad executive role combining: ? Organizational and governance leadership ? Technical strategy and infrastructure oversight ? Global community and membership engagement ? Staff and contractor leadership ? Financial sustainability and resource development ? Research and program oversight We are particularly interested in candidates with senior leadership experience who have successfully led fully remote or internationally distributed teams. Strong candidates will also bring experience working with a governing board and within a nonprofit, membership, research, public-interest, or community-led organization. Technical credibility within DNS, Internet infrastructure, networking, cybersecurity, open-source technology, or a related field is important. The successful candidate must be able to lead highly technical personnel, establish strategic direction, and make informed decisions. Position Details ? Location: Fully remote ? Engagement: Full-time independent contractor ? Compensation: Up to $14,000 USD per month, approximately $170,000 annually ? Travel: Regular US and international travel, generally five or more trips per year Some corporate officer and administrative responsibilities need to be US-based. However, all applicants will be considered regardless of nationality or location. Read the complete role description and person specification here: https://www.dns-oarc.net/president-job How to Apply: Please submit a CV or r?sum?, and cover letter to Your cover letter should describe: ? Your interest in DNS-OARC?s mission ? Your relevant leadership and technical experience ? Your experience leading remote or distributed teams ? Your experience working with boards, nonprofits, membership organizations, or international communities ? Your approach to balancing executive accountability with effective delegation Application deadline: Wednesday, August 26, 2026, at 8:00 a.m. EDT. DNS-OARC values diversity and inclusion and welcomes applicants of all ages, ethnicities, orientations, genders, beliefs, abilities, cultures, and backgrounds. From travis.milum+dns-ops at gmail.com Fri Aug 7 05:30:41 2026 From: travis.milum+dns-ops at gmail.com (Travis Milum) Date: Thu, 6 Aug 2026 22:30:41 -0700 Subject: [dns-operations] Contradictory online-signed NSEC3 denials from Akamai Edge DNS (www.shoppersdrugmart.ca) Message-ID: Hello, While debugging resolution failures on my validating resolver (Technitium v14/v15), I isolated a severe protocol anomaly where Akamai Edge DNS emits flatly contradictory cryptographic proofs for the same hostname. I have heavily leveraged AI assistance to help parse the DNSSEC specifications and accelerate this analysis. To eliminate the risk of hallucinations, I have manually cross-verified every cryptographic claim, raw hash, and packet behavior across multiple independent diagnostic tools (dig, delv, and custom verification scripts). The data below is fully verified. Multiple tools confirm that www.shoppersdrugmart.ca returns signed DNSSEC records that fail strict protocol validation because the A and HTTPS queries yield incompatible NSEC3 maps. Zone: shoppersdrugmart.ca (algorithm 13, NSEC3 1 0 0 -, online signing, SOA a9-66.akam.net). Affected name: www.shoppersdrugmart.ca only. The zone makes four signed claims about this name: 1) A query: parent-signed A RRset at the name (RRSIG by ZSK 22808, labels=3, validates; Google and Quad9 both serve it with AD). 2) HTTPS (TYPE65) query: NODATA, proven by an NSEC3 whose owner is the exact hash of the qname, with type bitmap "NS" only: i1pqk8g0qpc0ajvjoi8i2cuqc1d56s37.shoppersdrugmart.ca. IN NSEC3 1 0 0 - I1VMU2GHT898MU6OLU2IKC19Q7368E1M NS (RRSIG NSEC3 13 3 3600, ZSK 22808) Hash check (SHA-1, 0 iterations, empty salt): python3 -c "import hashlib,base64; print(base64.b32hexencode( hashlib.sha1(b'\x03www\x10shoppersdrugmart\x02ca\x00') .digest()).decode().lower())" -> i1pqk8g0qpc0ajvjoi8i2cuqc1d56s37 An NS-only bitmap marks the name as a delegation; RFC 6840 4.4 forbids this NSEC3 as a non-existence proof for non-DS types. It also asserts the name has no A RRset, contradicting (1). 3) NS query (the one type the bitmap claims exists): fails validation. Quad9 returns SERVFAIL with EDE 6 (DNSSEC Bogus). 4) DS query: NODATA via the same NSEC3. For DS this proof is permitted, and Quad9 validates it (AD) -- i.e. "insecure delegation", which (1) and (3) each contradict. The records are regenerated each day. On 2026-08-04 and 2026-08-06 each have fresh RRSIGs. Resolver behavior on the TYPE65 denial diverges across implementations: Technitium rejects it (correctly); Quad9 serves it without AD; Google 8.8.8.8/8.8.4.4 varied across days but started by sending a minimal NODATA with the authority section absent (52 bytes) and then the next day as full proof with AD set, which RFC 6840 4.4 seems to disallow. The operator's 13 sibling domains all CNAME www to unsigned edgekey.net and are unaffected; this is their only in-zone-signed hostname. I probed apex and www TYPE65 denials for all 66 DNSSEC-signed Akamai-hosted domains in the Tranco top 10k and found no second instance. End-user impact is currently limited (browsers fall back from TYPE65), but Technitium's (v14) validating resolver turned this into full unreachability by rejecting all resolutions to the domain outright. The latest version (15.3) allows the A records through, but still logs this as a possible attack. Full dig outputs and the survey script are available on request. I haven't submitted a support ticket to the Shoppersdrugmart.ca website as I highly doubt this would gain traction there. It seems like the right target would be Akamai, but I have no idea how to notify them. Regards, Travis From cathya at isc.org Tue Aug 11 16:29:36 2026 From: cathya at isc.org (Cathy Almond) Date: Tue, 11 Aug 2026 17:29:36 +0100 Subject: [dns-operations] OARC 47 Call for Contribution - less than two weeks to go before the CfP closes on 24th August! Message-ID: <80a4c4b0-45f6-4ce4-95c6-41b2dc9fecea@isc.org> The OARC 47 Call for Contributions is open but is closing soon - if you are planning to submit a talk, please don't leave it too late and miss the deadling! This workshop will be a hybrid event. Date - 09-10 November 2026 Location - Vancouver, British Columbia Times - approximately 10:00-17:00 PDT (Local time PDT is UTC -7) * note that British Columbia has opted to remain on PDT all year round Deadline for Submissions - 2026-08-24 23:59 UTC https://indico.dns-oarc.net/event/58/abstracts/ All DNS-related subjects and discussion topics are welcome although we're particularly keen to hear more about operational and security related experiences, best practices and practical advice; both for newcomers to the DNS arena and those who have been around for longer who want to learn more about new features and opportunities to improve resilience, security and privacy. (These topics we think will complement the usual high-quality data-based research submissions we always hope to receive!) If you have something interesting to share with the community that lies outside of the focus above, please don't be put off - if it's good, we'll be happy to include it. You can also contact us directly at submissions at dns-oarc.net if you would like to ask about the suitability of a potential presentation submission topic. If you'd like to offer a talk, but are not quite sure what to pick, here's a non-exhaustive list of ideas: 1. Operations & Deployment - Configuration management, deployment processes, and interoperability expeiences. - Tools, tips, and making effective use of DNS software features. 2. Performance, Resilience & Scaling - Provisioning, load-balancing, and planning for resilience. - DNS performance management, efficiency improvements, and metrics. - Monitoring infrastructure: log pipelines, analytics, and anomaly detection. 3. Security, Privacy & Policy - DoS attacks, DNS abuse, DNSSEC signing and validation. - Privacy considerations, for example: encrypted transport, qname minimization, data anonymization. - Relevant global and regional policies, legislation, and compliance. 4. Research & Innovation - Data-driven testing, measurement, and analysis. - New protocols, protocol extensions, and next-generation namespace management. 5. Lessons & Learnings - Outage experiences, recovery stories, and cautionary tales For further details please see https://www.dns-oarc.net/oarc47 Cathy Almond, for the DNS-OARC Programme Committee