The DNS Server That Lagged Behind
• 3 min read
Around the end of October and beginning of November 2024, twenty six African TLDs had a technical problem - one of their authoritative name servers served stale data. This is a tale of monitoring, anycast, and debugging.
Great survey, thanks for this work. Indeed, the variations in EDE are funny. For bogus.bortzmeyer.fr, Unbound (and 1.1.1.1) say "9 (DNSKEY Missing)", 9.9.9.9 say "10 (RRSIGs Missing)" and Knot-Resolver say "12 (NSEC Missing)"
"The IP to CO2 Intensity API allows you to query an IP address" The second link actually goes to a service that takes a host name, not an IP address.
A good thing about the IETF is that it is open and discussions are public so here is the link to the discussion inside the IETF about this article: https://mailarchive.ietf.org/arch/msg/ietf/M2vDMHuj063n5jvcUydcr0oRWy0/
I was at the same side meeting and had a different impression. My article in French: https://www.bortzmeyer.org/filtrage-vie-privee.html
Interesting and timely since, in the last two weeks, at least five domains of important public services in France have been down. At least four of them had poor DNS hosting (only two unicast authoritative name servers, sometimes in the same physical location). My report (in French): https://www.bortzmeyer.org/service-public-impots-dns.html
You do not mention the use of RIPE Atlas probes. Is the user tag "iwantbcp38compliancetesting" still useful/used?
You do not say if all the talks at the meeting were in croatian? (I ask because Vesna's one has a title in english.) I'm wondering if people are used to talk about things like QUIC in croatian.
"Agreement that organisations such as the RIPE NCC or ICANN have the authority to administer Internet number or name resources" Organisations like the RIPE-NCC are a mean, not a goal in itself. If RIPE-NCC or ICANN were to be replaced by something else, it does not mean that the Internet would become fragmented. This mention of organisations appears a little bit too self-serving. "Agreement that these organisations will be governed according to multistakeholder processes" Again, this has nothing to do with fragmentation. If all the Internet were directed by Elon Musk according to a onestakeholder process, it does not mean it would be fragmented. Not every bad outcome is "fragmentation".
"you generally identify DoT service endpoints by their IP name" Did you mean IP address?
Unless I'm wrong, the bias for RIPE Atlas probes is measured by the number of probes in the AS. Isn't there also a bias when asking N probes for a measurement, without specifying area/country/AS? Are we guaranteed that the set of probes we obtain respects the general population of probes? Or is there an extra bias here?
Showing 57 comment(s)