News « DNSSEC Deployment

<!-- header -->
<div id="header">
<div id="topnav" class="description"> Improving the security of the Internet's naming infrastructure</div>
<a id="logo" href=""><img src="" title="DNSSEC Deployment" alt="DNSSEC Deployment" /></a> href=""><span><span>About the DNSSEC History Project</span></span></a></li> <li class="page_item page-item-3217"><a href=""><span><span>Instigating Idea for DNSSEC History Project</span></span></a></li> <li class="page_item page-item-3208"><a href=""><span><span>Timeline</span></span></a></li> <li class="page_item page-item-3220"><a href=""><span><span>Archive</span></span></a></li> </ul> </li> <li class="page_item page-item-3250"><a href=""><span><span>Privacy Policy</span></span></a></li> <li class="page_item page-item-3308"><a href=""><span><span>Terms of Use</span></span></a></li> <li class="page_item page-item-184"><a href=""><span><span>About</span></span></a></li> <li class="page_item page-item-48 page_item_has_children"><a href=""><span><span>Papers, Presentations, &amp; Newsletters</span></span></a> <ul class='children'> <li class="page_item page-item-2092"><a href=""><span><span>DNSSEC at FOSE 2012</span></span></a></li> <li class="page_item page-item-1212"><a href=""><span><span>DNSSEC at FOSE 2011</span></span></a></li> <li class="page_item page-item-570"><a href=""><span><span>DNSSEC at FOSE 2010</span></span></a></li> <li class="page_item page-item-62"><a href=""><span><span>DNSSEC at GovSec 2009</span></span></a></li> <li class="page_item page-item-57"><a href=""><span><span>DNSSEC This Month newsletters</span></span></a></li> <li class="page_item page-item-19"><a href=""><span><span>Roadmap</span></span></a></li> <li class="page_item page-item-45"><a href=""><span><span>Guidelines</span></span></a></li> <li class="page_item page-item-1577"><a href=""><span><span>Various</span></span></a></li> <li class="page_item page-item-1717"><a href=""><span><span>Video</span></span></a></li> <li class="page_item page-item-1568"><a href=""><span><span>Overtaken by Events</span></span></a></li> </ul> </li> </ul> </div> <!-- /top tabs --> </div><!-- /header --> <!-- mid content --> <div id="mid-content"> <h1 class="pagetitle">Archive for category News</h1> <!-- post --> <div id="post-3167" class="post-3167 post type-post status-publish format-standard hentry category-news"> <h3><a href="" rel="bookmark" title="Permanent Link: Next Monthly DNSSEC Coordination Call On March 24, 2016">Next Monthly DNSSEC Coordination Call On March 24, 2016</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Dan York ">Dan York</a> in <a href="" rel="category tag">News</a> on March 2, 2016 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p>For those who participate in the monthly &#8220;DNSSEC Coordination&#8221; calls where we discuss activities around accelerating the deployment of DNSSEC, there will <strong>NOT</strong> be a call tomorrow, March 3, as there would normally be (the first Thursday of the month).</p> <p>On our last call in February we noted that:</p> <ul> <li>on March 3rd, many of us will be in transit to Marrakech for ICANN 55; and</li> <li>on April 7th, many of us will be in Buenos Aires for IETF 95.</li> </ul> <p>We therefore decided to:</p> <ol> <li>Cancel the monthly call on March 3.</li> <li>Cancel the monthly call on April 7.</li> <li>Hold instead a call on <strong>Thursday, March 24</strong>, at the usual time of <strong>11:00 US Eastern</strong> which will be <strong>15:00 UTC</strong>.</li> </ol> <p>Details for the conference call will be sent out as we get closer to March 24.</p> <p>Note: if you would like to participate in these monthly calls, <a href="">please join the dnssec-coord mailing list</a>. All who want to accelerate the deployment of DNSSEC and DANE are welcome to join.</p> </div> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2620" class="post-2620 post type-post status-publish format-standard hentry category-dnssec category-news"> <h3><a href="" rel="bookmark" title="Permanent Link: DNS Cache Poisoning Attack in Romania &#8211; Popular Sites Redirected.">DNS Cache Poisoning Attack in Romania &#8211; Popular Sites Redirected.</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Scott Rose ">Scott Rose</a> in <a href="" rel="category tag">DNSSEC</a>, <a href="" rel="category tag">News</a> on December 3, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p><a href="">Arstechnica</a> reports that a possible DNS cache poisoning attack was used against the Romanian (.ro) versions of popular sites like Google, PayPal and Microsoft. While the exact cause is unknown, cache poisoning is suspected since it involved multiple domain names, but not the whole of the .ro domain:</p> <blockquote><p>For a span of one to several hours on Wednesday morning, people typing <a href=""></a>, <a href=""></a>, and Romanian-specific addresses for other sites connected to a website that was purportedly run by an Algerian hacker, according to numerous security blog posts, including <a href="">this one</a> from Kaspersky Lab. Researchers said the most likely explanation for the redirection is a technique known as DNS poisoning, in which domain name system routing tables are tampered with, causing domain names to resolve to incorrect IP addresses.</p></blockquote> <p>More information from <a href="">Kaspersky Lab</a>.</p> </div> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2589" class="post-2589 post type-post status-publish format-standard hentry category-dnssec category-news tag-acm tag-anonymous"> <h3><a href="" rel="bookmark" title="Permanent Link: The Collateral Damage of Internet Censorship by DNS Injection">The Collateral Damage of Internet Censorship by DNS Injection</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Mark Feldman ">Mark Feldman</a> in <a href="" rel="category tag">DNSSEC</a>, <a href="" rel="category tag">News</a> on July 25, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p><a href="">The Collateral Damage of Internet Censorship by DNS Injection</a> (594KB PDF)  by Anonymous, published in <a href="">ACM SIGCOMM Computer Communication Review</a> (Volume 42, Number 3, July 2012), looks at  how</p> <blockquote><p>Some ISPs and governments (most notably the Great Firewall of China) use DNS injection to block access to “unwanted” websites. The censorship tools inspect DNS queries near the ISP’s boundary routers for sensitive domain keywords and inject forged DNS responses, blocking the users from accessing censored sites, such as twitter and facebook. Unfortunately this causes collateral damage, affecting communication beyond the censored networks when outside DNS traffic traverses censored links.</p></blockquote> <p>They point out that the techniques used are similar to Kaminsky-style attacks that can be perpetrated on non-DNSSEC-enabled systems:</p> <blockquote><p>In the absence of DNSSEC validation, the resolver will generally accept the faked answer because it arrives earlier than the real one, and, as a result, the access to the sensitive site will be blocked or redirected.</p></blockquote> <p>While DNSSEC is not able to guarantee transport of valid queries and responses, the paper goes on to say how it prevents the collateral damage associated with such machinations.</p> <p>&nbsp;</p> <p>&nbsp;</p> </div> <p class="tags"><a href="" rel="tag">ACM</a>, <a href="" rel="tag">Anonymous</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2529" class="post-2529 post type-post status-publish format-standard hentry category-news tag-sidn"> <h3><a href="" rel="bookmark" title="Permanent Link: DNSSEC Secure transfers: It can be done">DNSSEC Secure transfers: It can be done</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Mark Feldman ">Mark Feldman</a> in <a href="" rel="category tag">News</a> on July 3, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p>Certain administrative and operational changes &#8212; changing registrars, changing DNS servers and, if outsourced, DNS operators &#8212; have always had the potential to cause temporary name resolution failures. With some planning, usually involving lowering TTLs on some or all records in a zone in advance of the change, it has been possible to minimize if not obviate such failures.</p> <p>DNSSEC adds complexity in that signatures also have lifetimes and some administrative and operational changes require re-keying. If not done correctly, such changes can cause signed zones to fail to validate &#8212; to go dark &#8212; for longer than desired or expected.</p> <p>Internally, within the DNSSEC Deployment Coordination Initiative, we&#8217;ve described the goal as being a <em>ripple-free transfer</em>, and have made presentations on the topic  (e.g., <a href="">SATIN 2011</a> 180KB PDF).  Done properly, there is continuous, secure resolution throughout the process &#8212; no need to have a zone go unsigned/insecure or fail to validate at any point.</p> <p>Now, <a href="">Antoin Verschuren</a> from SIDN labs has published the article, <a href="">DNSSEC Secure transfers: Het kan well</a>.  We have an English translation <a href="/wp-content/uploads/2012/07/Secure-transfers-EN.pdf">here</a> (315KB PDF).</p> <p>&nbsp;</p> </div> <p class="tags"><a href="" rel="tag">SIDN</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2507" class="post-2507 post type-post status-publish format-standard hentry category-news category-tools tag-yadifa"> <h3><a href="" rel="bookmark" title="Permanent Link: EURid debuts YADIFA name server">EURid debuts YADIFA name server</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Mark Feldman ">Mark Feldman</a> in <a href="" rel="category tag">News</a>, <a href="" rel="category tag">Tools</a> on July 2, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p><a href="">The H Open reports</a> about a new, open-source (BSD license), DNSSEC-enabled DNS server:</p> <blockquote><p>An open source DNS name server that supports DNSSEC and is designed to be authoritative has been <a href="" target="_blank" rel="external">released</a> by <a href="" target="_blank" rel="external">EURid</a>, the European Registry of Internet Domain Names. <a href="" target="_blank" rel="external">YADIFA</a> is intended to be a lightweight alternative to more established projects; the developers say it was &#8220;built from scratch to face today’s DNS challenges, with no compromise on security, speed and stability&#8221;.</p></blockquote> </div> <p class="tags"><a href="" rel="tag">YADIFA</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2481" class="post-2481 post type-post status-publish format-standard hentry category-news category-tools tag-sidn"> <h3><a href="" rel="bookmark" title="Permanent Link: Authenticated Denial of Existence">Authenticated Denial of Existence</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Mark Feldman ">Mark Feldman</a> in <a href="" rel="category tag">News</a>, <a href="" rel="category tag">Tools</a> on June 28, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p style="text-align: left"><a href=""><img decoding="async" class="size-full wp-image-2314 aligncenter" title="logo-sidn-en" src="" alt="" width="403" height="62" /></a>Effective immediately, this site will be renamed <em>The .NL Gazette</em>.  Well, maybe not, but the folks at SIDN, the .NL registry, just keep producing good stuff.</p> <p>We&#8217;ve recently reported on their becoming DNSSEC <a href="/index.php/2012/05/sidn-announces-dnssec-operational-for-nl/">operational</a>  and their surpassing .COM in the <a href="/index.php/2012/06/nl-passeert-com-met-dnssec/">number of signed zones</a>.  A couple of months back we lauded their excellent DNSSEC <a href="/index.php/2012/04/2313/">tutorial</a>.  We&#8217;ve also mentioned several of the tools <del>they&#8217;ve</del> NLNet Labs produced (NSD, Unbound, Dnssec-Trigger) when talking about <a href="/index.php/2012/03/labs-around-the-world-enabling-dnssec/">labs</a> and in our articles on <a href="/index.php/2012/03/a-validating-recursive-resolver-on-a-70-home-router/">adding DNSSEC validation to a $70 router</a> and its <a href="/index.php/2012/03/is-a-70-router-fast-enough-for-dnssec/">performance</a>.</p> <p>[<strong>Correction 3 July 2012</strong>:  Why the strikeout above?  Olaf M. Kolkman of NLNet Labs points out that while SIDN and NLNet Labs have had a collaborative agreement since the beginning of this year, NSD, Unbound, and Dnssec-Trigger are products of NLNet Labs.   We&#8217;re just happy that both <a href="">SIDN</a> and <a href="">NLNet Labs</a> are helping advance DNSSEC and don&#8217;t for one second want to confuse the two just because they&#8217;re both in The Netherlands!   To further make things clear, neither SIDN nor NLNet Labs produce Koetjesreep, so don&#8217;t ask for a few bars.  Thanks for the correction, Olaf!]</p> <p>Now it&#8217;s time to let people know about one of their more technical articles,<br /> <a href=""><em>Authenticated Denial of Existence in the DNS</em> </a> (277KB PDF).  We ran across it while trying to debug some validation software.</p> <p>The article tells the story behind why negative responses must be signed and how they can state with security and certainty that a name/resource record type combination does not exist. The article augments RFCs <a href="">4033</a>, <a href="">4034</a>, <a href="">4035</a>, and <a href="">5155</a>.</p> <p>It provides the kinds of additional information in narrative and graphic format that helps with understanding.  If you want to now how authenticated denial of existence works, check out the article.</p> <p>&nbsp;</p> </div> <p class="tags"><a href="" rel="tag">SIDN</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-2472" class="post-2472 post type-post status-publish format-standard hentry category-news tag-sidn"> <h3><a href="" rel="bookmark" title="Permanent Link: .nl passeert .com met DNSSEC">.nl passeert .com met DNSSEC</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Mark Feldman ">Mark Feldman</a> in <a href="" rel="category tag">News</a> on June 27, 2012 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p><a href=""><img decoding="async" class="alignleft size-full wp-image-2473" title="webwereldlogo" src="" alt="Webwereld" width="221" height="90" /></a></p> <p>Webwereld&#8217;s <a href="">story</a> about DNSSEC adoption in .NL describes how, with under five million domains, .NL has almost 12,000 using DNSSEC &#8212; more than the number of DNSSEC-enabled domains in .COM.</p> <p>Current counts of domain registrations and DNSSEC use for .NL are in the right-hand sidebar of <a title="SIDN web site" href="">SIDN&#8217;s web site</a> (and <a title="SIDN's English web site" href="">English translation</a>).</p> </div> <p class="tags"><a href="" rel="tag">SIDN</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-414" class="post-414 post type-post status-publish format-standard hentry category-adoption category-dnssec category-news tag-dnssec tag-root-zone"> <h3><a href="" rel="bookmark" title="Permanent Link: DNSSEC signed answers from L root server">DNSSEC signed answers from L root server</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Olafur Gudmundsson ">Olafur Gudmundsson</a> in <a href="" rel="category tag">Adoption</a>, <a href="" rel="category tag">DNSSEC</a>, <a href="" rel="category tag">News</a> on January 27, 2010 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p>The first root server (L) has started to serve up a signed version of the root zone. This is the first step in the live testing that will lead to a production signed root by the middle of the year.  For information on the status of the root signing process visit: <a href=""></a></p> <p>The root is intentionally publishing bogus signing keys, so the answers are not verifiable. Once the testing completes the actual keys will be published.</p> <p>Current DNSKEY set advertised: <font size="-5"><br /> <span><br /> . 86400 IN DNSKEY 256 3 8 AwEAAa1Lh++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOULD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MORE/INFORMATION+++<br /> +++++++++++++++++++++++++++++++++++++++++++++++8<br /> . 86400 IN DNSKEY 257 3 8 AwEAAawBe++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOULD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MORE/INFORMATION+++<br /> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++<br /> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++8=<br /> . 86400 IN RRSIG DNSKEY 8 0 86400 20100204235959 20100121000000 19324 . NO9bHgWYB3wQlVZXQKwDGUjTgIyfz1i8aWH8nBlT5isnYbr6PTfR4fWlSx8+avFfR0fVekauaQelKOyiUav4H9Y1AZ2OBguu7RjozQu1qErKboWd1NglIIOGar0Ol4Ur9+<br /> 4bo2LSxjp/X4ESypW0lX04z5uB6DZZei1zafzRGUnLIMdV9xdKEOJrm9UCKvYK5g8bjRq8KA8vT+<br /> pidexZMrBQ3ie8R9daf/s6VK7zUJK0jF1vqhPbZFSQmBpJUlxh4VnOv7nnhcq4Moj49wqmNxKRqfvSwHAJBG6dEgShnlu/rfVsdxfFUCjIGX8YnSC7lYqODwgUGh+i/arA AK+bzg==<br /> </span></font></p> </div> <p class="tags"><a href="" rel="tag">DNSSEC</a>, <a href="" rel="tag">Root zone</a></p> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-352" class="post-352 post type-post status-publish format-standard hentry category-adoption category-dnssec category-news"> <h3><a href="" rel="bookmark" title="Permanent Link: GCN: DNSSEC among top 10 technologies for 2010">GCN: DNSSEC among top 10 technologies for 2010</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Denise Graveline ">Denise Graveline</a> in <a href="" rel="category tag">Adoption</a>, <a href="" rel="category tag">DNSSEC</a>, <a href="" rel="category tag">News</a> on January 15, 2010 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p>Adding to our compilation of <a href="">observers who&#8217;ve put DNSSEC on their lists of 2010 trends to watch</a>, Government Computer News has put DNSSEC on its <a href="">list of 10 Technologies to Watch in 2010</a>. Noting that the DNS security extensions &#8220;add an important level of assurance,&#8221; the article noted:</p> <blockquote><p>Leading by example, the U.S. government has helped to spur adoption. Following disclosure last year of a <a href=""><strong>serious vulnerability</strong></a> in the DNS protocols, the Office of Management and Budget mandated that the dot-gov top-level domain be signed in 2009 and that agencies sign their secondary domains by the end of that year.</p></blockquote> </div> <p class="postcontrols"> <a class="no comments" href="">No Comments</a> </p> <div class="clear"></div> </div> <!-- /post --> <!-- post --> <div id="post-341" class="post-341 post type-post status-publish format-standard hentry category-dnssec category-news tag-verisign"> <h3><a href="" rel="bookmark" title="Permanent Link: Twitter attack prompts a DNSSEC reminder">Twitter attack prompts a DNSSEC reminder</a></h3> <!-- story header --> <div class="postheader"> <div class="postinfo"> <p> Posted by <a href="" title="Posts by Denise Graveline ">Denise Graveline</a> in <a href="" rel="category tag">DNSSEC</a>, <a href="" rel="category tag">News</a> on January 15, 2010 </p> </div> </div> <!-- /story header --> <div class="postbody entry clearfix"> <p><a href="">eWeek Europe&#8217;s look</a> at the December attack that took down Twitter suggests that businesses need a stronger focus on DNS security, and includes this reminder about DNSSEC from <strong>Rick Howard</strong>, director of security intelligence at VeriSign iDefense:</p> <blockquote><p>&#8220;Basic DNS monitoring is sorely lacking,&#8221; he continued. &#8220;While enterprises may monitor DNS availability, and are increasingly aware of DDoS [distributed denial of service] attacks targeting domain name servers, simple monitoring for DNS integrity is often overlooked. <strong>Enterprises should also pay attention to the rollout of DNSSEC</strong>, which mitigates some attacks, but is not yet widely available.&#8221;</p></blockquote> <p>The attack  used &#8220;legitimate credentials to log in and redirect to a site purporting to be under the control of the Iranian Cyber Army,&#8221; the article notes.</p> </div> <p <li class="infotext">
<p>You are currently browsing the archives for the News category.</p>
</li> class="textwidget"><ul> <li><a href="">Deploy360 DNSSEC</a> <li><a href="">DNSSEC Tools Project</a> <li><a href="">DANE Info</a> </ul></div> </div></li><li><div id="wgs_widget-2" class="widget widget_wgs_widget"><h2 class="title">Search</h2><div class="wgs_wrapper"><div class="gcse-searchbox-only" data-resultsUrl=""></div></div></div></li> <li><div id="recent-posts-2" class="widget widget_recent_entries"> <h2 class="title">Recent Posts</h2> <ul> <li> <a href="">Call for Participation &#8212; ICANN DNSSEC and Security Workshop at ICANN68 Virtual Policy Forum in June 2020</a> </li> <li> <a href="">Call for Participation &#8212; ICANN DNSSEC and Security Workshop at ICANN67 in March 2020 in Cancun, Mexico</a> </li> <li> <a href="">Slides and video available for ICANN 66 DNSSEC Workshop</a> </li> <li> <a href="">Call for Participation &#8211; ICANN DNSSEC and Security Workshop at ICANN66, Montreal, Canada</a> </li> <li> <a href="">Call for Participation &#8211; DNSSEC Workshop at ICANN65, Marrakech, Morocco</a> </li> </ul> </div></li><li><div id="archives-2" class="widget widget_archive"><h2 class="title">Archives</h2> <label class="screen-reader-text" for="archives-dropdown-2">Archives</label> <select id="archives-dropdown-2" name="archive-dropdown"> <option value="">Select Month</option> <option value=''> May 2020 &nbsp;(1)</option> <option value=''> January 2020 &nbsp;(1)</option> <option value=''> November 2019 &nbsp;(1)</option> <option value=''> September 2019 &nbsp;(1)</option> <option value=''> May 2019 &nbsp;(1)</option> <option value=''> January 2019 &nbsp;(1)</option> <option value=''> May 2017 &nbsp;(1)</option> <option value=''> March 2017 &nbsp;(1)</option> <option value=''> December 2016 &nbsp;(1)</option> <option value=''> August 2016 &nbsp;(1)</option> <option value=''> June 2016 &nbsp;(1)</option> <option value=''> April 2016 &nbsp;(1)</option> <option value=''> March 2016 &nbsp;(1)</option> <option value=''> January 2016 &nbsp;(1)</option> <option value=''> November 2015 &nbsp;(1)</option> <option value=''> October 2015 &nbsp;(2)</option> <option value=''> July 2015 &nbsp;(1)</option> <option value=''> June 2015 &nbsp;(1)</option> <option value=''> March 2015 &nbsp;(1)</option> <option value=''> February 2015 &nbsp;(1)</option> <option value=''> January 2015 &nbsp;(1)</option> <option value=''> December 2014 &nbsp;(1)</option> <option value=''> November 2014 &nbsp;(1)</option> <option value=''> October 2014 &nbsp;(1)</option> <option value=''> September 2014 &nbsp;(1)</option> <option value=''> August 2014 &nbsp;(1)</option> <option value=''> July 2014 &nbsp;(2)</option> <option value=''> September 2013 &nbsp;(1)</option> <option value=''> July 2013 &nbsp;(1)</option> <option value=''> June 2013 &nbsp;(1)</option> <option value=''> April 2013 &nbsp;(1)</option> <option value=''> March 2013 &nbsp;(3)</option> <option value=''> February 2013 &nbsp;(2)</option> <option value=''> December 2012 &nbsp;(1)</option> <option value=''> July 2012 &nbsp;(7)</option> <option value=''> June 2012 &nbsp;(9)</option> <option value=''> May 2012 &nbsp;(4)</option> <option value=''> April 2012 &nbsp;(5)</option> <option value=''> March 2012 &nbsp;(11)</option> <option value=''> February 2012 &nbsp;(5)</option> <option value=''> January 2012 &nbsp;(7)</option> <option value=''> December 2011 &nbsp;(4)</option> <option value=''> November 2011 &nbsp;(6)</option> <option value=''> October 2011 &nbsp;(6)</option> <option value=''> September 2011 &nbsp;(4)</option> <option value=''> August 2011 &nbsp;(2)</option> <option value=''> July 2011 &nbsp;(5)</option> <option value=''> June 2011 &nbsp;(3)</option> <option value=''> May 2011 &nbsp;(1)</option> <option value=''> April 2011 &nbsp;(1)</option> <option value=''> March 2011 &nbsp;(3)</option> <option value=''> February 2011 &nbsp;(5)</option> <option value=''> January 2011 &nbsp;(6)</option> <option value=''> December 2010 &nbsp;(6)</option> <option value=''> November 2010 &nbsp;(6)</option> <option value=''> October 2010 &nbsp;(13)</option> <option value=''> September 2010 &nbsp;(7)</option> <option value=''> August 2010 &nbsp;(13)</option> <option value=''> July 2010 &nbsp;(7)</option> <option value=''> June 2010 &nbsp;(22)</option> <option value=''> May 2010 &nbsp;(4)</option> <option value=''> April 2010 &nbsp;(7)</option> <option value=''> March 2010 &nbsp;(15)</option> <option value=''> February 2010 &nbsp;(9)</option> <option value=''> January 2010 &nbsp;(27)</option> <option value=''> December 2009 &nbsp;(8)</option> </select> <script type="text/javascript"> /* <![CDATA[ */ (function() { var dropdown = document.getElementById( "archives-dropdown-2" ); function onSelectChange() { if ( dropdown.options[ dropdown.selectedIndex ].value !== '' ) { document.location.href = this.options[ this.selectedIndex ].value; } } dropdown.onchange = onSelectChange; })(); /* ]]> */ </script> </div></li><li><div id="categories-2" class="widget widget_categories"><h2 class="title">Categories</h2> <ul> <li class="cat-item cat-item-169"><a href="">About The DNSSEC Deployment Initiative</a> </li> <li class="cat-item cat-item-85"><a href="">Adoption</a> </li> <li class="cat-item cat-item-86"><a href="">Case Studies</a> </li> <li class="cat-item cat-item-87"><a href="">DNSSEC</a> </li> <li class="cat-item cat-item-164"><a href="">DNSSEC Deployment Maps</a> </li> <li class="cat-item cat-item-166"><a href="">ICANN DNSSEC Workshops</a> </li> <li class="cat-item cat-item-88"><a href="">Meetings and Workshops</a> </li> <li class="cat-item cat-item-89 current-cat"><a aria-current="page" href="">News</a> </li> <li class="cat-item cat-item-90"><a href="">Policy</a> </li> <li class="cat-item cat-item-91"><a href="">Technical guides</a> </li> <li class="cat-item cat-item-176"><a href="">Tools</a> </li> <li class="cat-item cat-item-1"><a href="">Uncategorized</a> </li> </ul> </div></li><li><div id="tag_cloud-2" class="widget widget_tag_cloud"><h2 class="title">Tags</h2><div class="tagcloud"><a href="" class="tag-cloud-link tag-link-92 tag-link-position-1" style="font-size: 8pt;" aria-label=".BIZ (1 item)">.BIZ</a> <a href="" class="tag-cloud-link tag-link-93 tag-link-position-2" style="font-size: 10.191304347826pt;" aria-label=".org (2 items)">.org</a> <a href="" class="tag-cloud-link tag-link-95 tag-link-position-3" style="font-size: 10.191304347826pt;" aria-label=".us (2 items)">.us</a> <a href="" class="tag-cloud-link tag-link-201 tag-link-position-4" style="font-size: 17.860869565217pt;" aria-label="Adoption (12 items)">Adoption</a> <a href="" class="tag-cloud-link tag-link-99 tag-link-position-5" style="font-size: 10.191304347826pt;" aria-label="Applications (2 items)">Applications</a> <a href="" class="tag-cloud-link tag-link-102 tag-link-position-6" style="font-size: 15.913043478261pt;" aria-label="CCTLDs (8 items)">CCTLDs</a> <a href="" class="tag-cloud-link tag-link-105 tag-link-position-7" style="font-size: 13.84347826087pt;" aria-label="deployment progress (5 items)">deployment progress</a> <a href="" class="tag-cloud-link tag-link-202 tag-link-position-8" style="font-size: 19.321739130435pt;" aria-label="DNSSEC (16 items)">DNSSEC</a> <a href="" class="tag-cloud-link tag-link-195 tag-link-position-9" style="font-size: 8pt;" aria-label="DNSSEC-coord (1 item)">DNSSEC-coord</a> <a href="" class="tag-cloud-link tag-link-112 tag-link-position-10" style="font-size: 10.191304347826pt;" aria-label="DOC (2 items)">DOC</a> <a href="" class="tag-cloud-link tag-link-114 tag-link-position-11" style="font-size: 10.191304347826pt;" aria-label="Dot-EDU (2 items)">Dot-EDU</a> <a href="" class="tag-cloud-link tag-link-115 tag-link-position-12" style="font-size: 12.869565217391pt;" aria-label="dot-gov (4 items)">dot-gov</a> <a href="" class="tag-cloud-link tag-link-116 tag-link-position-13" style="font-size: 10.191304347826pt;" aria-label="Dot-NL (2 items)">Dot-NL</a> <a href="" class="tag-cloud-link tag-link-118 tag-link-position-14" style="font-size: 10.191304347826pt;" aria-label="dot-SE (2 items)">dot-SE</a> <a href="" class="tag-cloud-link tag-link-121 tag-link-position-15" style="font-size: 10.191304347826pt;" aria-label="Dot-US (2 items)">Dot-US</a> <a href="" class="tag-cloud-link tag-link-124 tag-link-position-16" style="font-size: 11.652173913043pt;" aria-label="EDUCAUSE (3 items)">EDUCAUSE</a> <a href="" class="tag-cloud-link tag-link-127 tag-link-position-17" style="font-size: 11.652173913043pt;" aria-label="FOSE (3 items)">FOSE</a> <a href="" class="tag-cloud-link tag-link-133 tag-link-position-18" style="font-size: 22pt;" aria-label="ICANN (27 items)">ICANN</a> <a href="" class="tag-cloud-link tag-link-168 tag-link-position-19" style="font-size: 8pt;" aria-label="ICANN46 (1 item)">ICANN46</a> <a href="" class="tag-cloud-link tag-link-167 tag-link-position-20" style="font-size: 8pt;" aria-label="ICANN47 (1 item)">ICANN47</a> <a href="" class="tag-cloud-link tag-link-179 tag-link-position-21" style="font-size: 8pt;" aria-label="ICANN51 (1 item)">ICANN51</a> <a href="" class="tag-cloud-link tag-link-196 tag-link-position-22" style="font-size: 12.869565217391pt;" aria-label="ICANN52 (4 items)">ICANN52</a> <a href="" class="tag-cloud-link tag-link-197 tag-link-position-23" style="font-size: 10.191304347826pt;" aria-label="ICANN53 (2 items)">ICANN53</a> <a href="" class="tag-cloud-link tag-link-199 tag-link-position-24" style="font-size: 11.652173913043pt;" aria-label="ICANN54 (3 items)">ICANN54</a> <a href="" class="tag-cloud-link tag-link-204 tag-link-position-25" style="font-size: 8pt;" aria-label="ICANN55 (1 item)">ICANN55</a> <a href="" class="tag-cloud-link tag-link-205 tag-link-position-26" style="font-size: 10.191304347826pt;" aria-label="ICANN56 (2 items)">ICANN56</a> <a href="" class="tag-cloud-link tag-link-206 tag-link-position-27" style="font-size: 8pt;" aria-label="ICANN57 (1 item)">ICANN57</a> <a href="" class="tag-cloud-link tag-link-207 tag-link-position-28" style="font-size: 10.191304347826pt;" aria-label="ICANN58 (2 items)">ICANN58</a> <a href="" class="tag-cloud-link tag-link-208 tag-link-position-29" style="font-size: 8pt;" aria-label="ICANN59 (1 item)">ICANN59</a> <a href="" class="tag-cloud-link tag-link-134 tag-link-position-30" style="font-size: 10.191304347826pt;" aria-label="IETF (2 items)">IETF</a> <a href="" class="tag-cloud-link tag-link-135 tag-link-position-31" style="font-size: 10.191304347826pt;" aria-label="Infoblox (2 items)">Infoblox</a> <a href="" class="tag-cloud-link tag-link-165 tag-link-position-32" style="font-size: 14.695652173913pt;" aria-label="maps (6 items)">maps</a> <a href="" class="tag-cloud-link tag-link-145 tag-link-position-33" style="font-size: 11.652173913043pt;" aria-label="Neustar (3 items)">Neustar</a> <a href="" class="tag-cloud-link tag-link-152 tag-link-position-34" style="font-size: 11.652173913043pt;" aria-label="PIR (3 items)">PIR</a> <a href="" class="tag-cloud-link tag-link-153 tag-link-position-35" style="font-size: 8pt;" aria-label="Ripe (1 item)">Ripe</a> <a href="" class="tag-cloud-link tag-link-170 tag-link-position-36" style="font-size: 8pt;" aria-label="Roadmap (1 item)">Roadmap</a> <a href="" class="tag-cloud-link tag-link-154 tag-link-position-37" style="font-size: 10.191304347826pt;" aria-label="Root (2 items)">Root</a> <a href="" class="tag-cloud-link tag-link-155 tag-link-position-38" style="font-size: 11.652173913043pt;" aria-label="Root zone (3 items)">Root zone</a> <a href="" class="tag-cloud-link tag-link-156 tag-link-position-39" style="font-size: 11.652173913043pt;" aria-label="SIDN (3 items)">SIDN</a> <a href="" class="tag-cloud-link tag-link-158 tag-link-position-40" style="font-size: 10.191304347826pt;" aria-label="State Government (2 items)">State Government</a> <a href="" class="tag-cloud-link tag-link-160 tag-link-position-41" style="font-size: 11.652173913043pt;" aria-label="TLD (3 items)">TLD</a> <a href="" class="tag-cloud-link tag-link-161 tag-link-position-42" style="font-size: 8pt;" aria-label="UDP Fragments (1 item)">UDP Fragments</a> <a href="" class="tag-cloud-link tag-link-162 tag-link-position-43" style="font-size: 10.191304347826pt;" aria-label="Verisign (2 items)">Verisign</a> <a href="" class="tag-cloud-link tag-link-163 tag-link-position-44" style="font-size: 8pt;" aria-label="workshop (1 item)">workshop</a> <a href="" class="tag-cloud-link tag-link-177 tag-link-position-45" style="font-size: 8pt;" aria-label="YADIFA (1 item)">YADIFA</a></div> </div></li><li><div id="recent-comments-2" class="widget widget_recent_comments"><h2 class="title">Recent Comments</h2><ul id="recentcomments"><li class="recentcomments"><span class="comment-author-link"><a href="" class="url" rel="ugc external nofollow">justina colmena</a></span> on <a href="">DNSSEC deployed in .US; .BIZ shortly to follow, Neustar says</a></li><li class="recentcomments"><span class="comment-author-link">Dan Web site sponsored by the <a href="">Internet Society Deploy360 Programme</a>.<br><br>
<a href="">Privacy Policy</a><br><br> 