DNS

Sponsored
by

DNS / Most Viewed

The 2024-2026 Root Zone KSK Rollover: Initial Observations and Early Trends

On Jan. 11, 2025, Verisign supported the Internet Corporation for Assigned Names and Numbers (ICANN) in taking a major step to ensure the continued security, stability, and resiliency of the Domain Name System (DNS). While imperceptible to most users, this action - specifically, the introduction of a new Domain Name System Security Extensions (DNSSEC) Key Signing Key (KSK) in the root zone - is the next step of a multi-year-long process to change, or "roll," the cryptographic key that secures the root of the DNS. more

DNSSEC Takes Off in Wake of Root Zone Signing

The Domain Name System Security Extensions (DNSSEC) is a suite of IETF-developed specifications designed to validate information provided by the Domain Name System (DNS). ... When the root zone was signed in June 2010, this acted as a catalyst for TLD operators to deploy DNSSEC on their side. We have seen a gradual but significant increase in signed TLDs since then. The map in this post shows the level of DNSSEC deployment in Europe. more

CENTR Replies to ITU Study on ccTLD Governance

The Council of European National Top-Level Domain Registries (CENTR) announced today their response to Professor Michael Geist's draft survey report "Government and country-code top level Domains: A global survey", which was conducted on behalf of the International Telecommunication Union (ITU) in December 2003. "In the last decade the general trend has been to de-regulate markets in the Communications Industry, which continues to stimulate economic growth and innovation, and it seems perverse that this ITU supported report is seeking to go against the proven successful trend," said Paul Kane, chairman of CENTR. more

What ICANN Should Do Now to Help Future Applicants of New gTLDs

During ICANN71, the Brand Registry Group (BRG) openly asked potential future applicants what ICANN can do to help prepare them for the next gTLD round. The answer was very clear - commit to opening the next round and provide as much information as possible early on. However, in recent correspondence to the BRG from ICANN Chair, Maarten Botterman, he emphasized that "significant work lies ahead of us: the 2012 Applicant Guidebook must be updated with more than 100 outputs... more

Domain Registrars File Lawsuit Against ICANN

Members of the Domain Justice Coalition filed a lawsuit today requesting a temporary restraining order and other relief against ICANN to block the implementation of a domain name Wait Listing Service (WLS). The WLS was proposed by VeriSign, Inc. (pdf) and approved by ICANN in federal court in Los Angeles. The suit challenges ICANN's failure to comply with its internal decision-making process requirements when it approved implementation of the WLS in the face of opposition from domain name registrars, resellers and consumers. more

DNS Clients Do Request DNSSEC Today

After the DNS root zone was finally signed and a number of Top-Level Domains (TLDs) began signing their zones, we were curious to see how many clients actually request DNSSEC information. We looked at the RIPE NCC server that provides secondary service to several country code top-level domains (ccTLDs). more

DITL Data Isn’t Statistically Valid for This Purpose (Part 2 of 4)

For several years, DNS-OARC has been collecting DNS query data "from busy and interesting DNS name servers" as part of an annual "Day-in-the-Life" (DITL) effort (an effort originated by CAIDA in 2002) that I discussed in the first blog post in this series. DNS-OARC currently offers eight such data sets, covering the queries to many but not all of the 13 DNS root servers (and some non-root data) over a two-day period or longer each year from 2006 to present. more

Secure Unowned Hierarchical Anycast Root Name Service - And an Apologia

In Internet Draft draft-lee-dnsop-scalingroot-00.txt, I described with my coauthors a method of distributing the task of providing DNS Root Name Service both globally and universally. In this article I will explain the sense of the proposal in a voice meant to be understood by a policy-making audience who may in many cases be less technically adept than the IETF DNSOP Working Group for whom the scalingroot-00 draft was crafted. I will also apologize for a controversial observation concerning the addition of new root name servers... more

Open Ends: Civil Society and Internet Governance - Part II

This is the second part of a three-part series interview by Geert Lovink with Jeanette Hofmann, policy expert from Germany, where she talks about her experiences as a member of the ICANN's Nominating Committee and her current involvement as a civil society member of the German delegation for the World Summit of the Information Society (WSIS). "So much in the current debates over global governance seems to go back to the issue what place governments and individual nation states have within global governance. What has been your ICANN experience? Ideally, what would be the place of the state? Do you believe in a federal structure? Should, for instance, bigger countries, in terms of its population, have a great say?..." more

The Design of the Domain Name System, Part III - Name Structure and Delegation

In the previous installments, we looked at the overall design of the DNS and the way DNS name matching works. The DNS gains considerable administrative flexibility from its delegation structure. Each zone cut, the place in the DNS name tree where one set of DNS servers hands off to another, offers the option to delegate the administration of a part of the DNS at the delegation point. more

What’s My Name Got to Do With It?

For about 3 years I had been studying graphic design and finally after much searching decided to use bmw-design.com for my domain name. I chose bmw for my initials Bernadette Maria Walker. I searched for availability on Network Solutions and was happy to see that it had not been taken, so I registered my new domain name. This all seemed very innocent to me and I even designed my logo around this name. Then 5 days later I got this letter via FedEx from BMW Motor Company in Germany... more

DNS Privacy at IETF 104

From time to time the IETF seriously grapples with its role with respect to technology relating to users' privacy. Should the IETF publish standard specifications of technologies that facilitate third-party eavesdropping on communications or should it refrain from working on such technologies? Should the IETF take further steps and publish standard specifications of technologies that directly impede various forms of third party eavesdropping on communications? more

Mubarak, Ben Ali, Kaddafi, ICANN: What They Have in Common Is Scary. Will They Share the Same Fate?

Will current failed ICANN direction on the New generic Top-Level Domains (gTLDs) doom its Regime to follow the fate of Mubarak, Ben Ali, and soon Kaddafi's? The whirlwinds of change we all have witnessed that started blowing in Tunisia, moved to Egypt and is now engulfing Libya, Yemen, Jordan and soon many others, have signaled a revolutionary way of thinking not just at local or regional levels but I believe on global levels too. more

Regime Change on the Internet: Conference Notes

"Regime Change on the Internet? Internet Governance after WGIG" was the first public event held in the United States on July 28, 2005 to review the UN Working Group on Internet Governance (WGIG) report. Here are my notes from the event: "Markus Kummer, Executive Coordinator, UN Working Group on Internet Governance, reminded the audience that the mandate of the WGIG was specifically articulated by the first part of the WSIS - "To investigate and make proposals for action as appropriate". It was not for sweeping regime change as the conference title would suggest." more

New CIRA Whois Policy Strikes Balance Between Privacy and Access

My weekly technology law column focuses this week on the new CIRA whois policy that is scheduled to take effect on June 10, 2008. The whois issue has attracted little public attention, yet it has been the subject of heated debate within the domain name community for many years. It revolves around the whois database, a publicly accessible, searchable list of domain name registrant information (as in "who is" the registrant of a particular domain name). more