Post #2146644
2026-05-05 22:37 UTC
Replies (4)
-
@jpmens@mastodon.social 2026-05-06 07:43
Quad9 removed their NTA during the night https://quad9.net/api/ntas.txt Quad1 (I call them that) still have it in place: queries to signed zones do not have an +AD on their responses.
-
@shaft@piaille.fr 2026-05-05 22:48
@jpmens@mastodon.social The end timestamp :D
-
@paul_ipv6@infosec.exchange 2026-05-05 23:21
@jpmens@mastodon.social this was why we did an RFC for it... i trust quad9 to follow the full RFC and review regularly to see if it can be taken down. interesting in q8. i thought they auto-NTA'ed on some level of failure. should make a good dnsoarc talk for someone doing a post-mortem on this.
-
@adamshostack@infosec.exchange 2026-05-05 23:31
@jpmens@mastodon.social It's been a while since I dug into #dnssec but ... I thought the goal of a cryptographic trust infrastructure included that a company (Let's call them "quad9") can't interfere with someone else's #DNS records. (Let's call them ".de") But apparently, quad9 can just say "eh, ignore .de's policy? Someone help me understand? Added in edit: I understand the policy to be ".de has records authenticated with this key"?