My book
Selected DNS entries
- Adieu OpenDNSSEC, bienvenido Knot-DNS!
- The ZONEMD (message digest) resource record
- How Knot-DNS simplifies adding member zones to a catalog zone
- DNSViz at home (self hosted)
- DNSSEC “key tag” or “key ID”?
- Red means Kaputt: when DNSSEC turns into a treasure hunt
- DNSSEC with NLnetLabs’ LDNS and NSD
- DNSSEC signing with the se.SAM N200 HSM with PKCS#11
- DNSSEC signing with an offline KSK
- My requirement for DNSSEC: a napkin
- Fun with the DNS SOA expire field
- GeoIP with BIND >= 9.16
- Vanity DNSSEC key tags
- DNSSEC provisioning automation with CDS/CDNSKEY in the real world
- A diagram to depict the DNSSEC chain of trust
- Using a SmartCard HSM for DNSSEC with BIND
- Transitioning the .CY ccTLD to DNSSEC
- On towels, DNS, and strncmp() (it’s about dig(1)’s
%comment
)
- DNS open zone data
- Time to solve: 10800 seconds
- BIND named ‘grants’ using external authenticator
- An authoritative Knot
- Parents, children, CDS/CDNSKEY records, and dnssec-cds
- DNS query/response logging with dnstap
- A first look at CoreDNS
- Unbound with views for local data
- Catalog zones in BIND 9
- A first look at the Knot DNS Resolver
- The semicolon in zone master files; some history
- Alert, backup, whatever on DNS NOTIFY with nsnotifyd
- Managing master/slave zones on PowerDNS with Ansible
- PowerDNS with a SmartCard HSM for DNSSEC
- Being notified of new and changed KSK in a zone
- Enabling DANE
- DNSSEC-signing with the Knot authoritative DNS server
- RFC 5011 with OpenDNSSEC, BIND, and Unbound
- A look at the PowerDNS REST API
- Using stash53 with the MQTT emitter
- stash53: Server-agnostic logging of DNS queries/responses
- List of DNS server software
- Processing BIND’s XML statistics with XSL
- Automatic provisioning of slave DNS servers
- Controlling back-end data for PowerDNS
- An exciting new feature in NSD4
- Understanding PowerDNS’ SOA-EDIT
- SSH public keys on a DNS FUSE
- Dynamically, or not dynamically: that is the question. RFC 2136
- Lightweight file “signing” with DNS
- Is my Web site being used via a DNSSEC-validator? (a lean DNSSEC widget)
- VerifyHostKeyDNS=yessssss!
- Creating ad hoc responses to DNS queries
- RFC 2136 Dynamic DNS Updates using GSS-TSIG and Kerberos
- Hesiod: a lightweight directory service on DNS
- PowerDNS with support for RFC 2136 Dynamic DNS Update
- credns: a DNSSEC-verification proxy
- Entropy: random data for DNSSEC
- On collecting SSH host keys for SSHFP DNS records
- Using BIND’s statistics server to list zones and AXFR the list
- A Lua back-end for BIND
- Whether or not to use Dynamic DNS
- Extending the Unbound DNS server with Python
- Dynamic DNS updates from SQL with a UDF and inotify()
- Speeding up large amounts of dynamic DNS updates (DDNS)
- DNS-related blogs and resources: DNSSexy
- Looking for a DNS-related job?
- PacketQ: SQL queries on DNS pcap files
- How to configure your BIND resolvers to lie using Response Policy Zones (RPZ)
- The countries.nerd.dk DNS BL
- PowerDNS authoritative server massages incoming AXFR with Lua script
- Performing dynamic DNS updates on your DNS
- Securing dynamic DNS updates (DDNS) with SIG(0)
- A DNS Statistics Collector: DSC
- Serving DNS replies from a CouchDB database with the BIND name server
- Nameserver count in the TLDs
- Where is your DNS server LOCated?
- DNSMASQ tips
DNSSEC
Really cool (cough) DNS stuff