Elektrine lite

← Feed

@jpmens@mastodon.social

Post #2146644

2026-05-05 22:37 UTC

Quad1 and Quad9 appear to have added an NTA (negative trust anchor) for .DE which means validators will no longer validate domains below *.DE; the situation will thus resolve (pun not really intended) itself soon’ish if temporarily until the root cause is fixed and the NTAs are removed. Quad8 is still validating .DE #dnssec Here is Quad9’s NTA: https://quad9.net/api/ntas.txt

Replies (4)

  • @jpmens@mastodon.social 2026-05-06 07:43

    Quad9 removed their NTA during the night https://quad9.net/api/ntas.txt Quad1 (I call them that) still have it in place: queries to signed zones do not have an +AD on their responses.

    Open ##2194324

  • @shaft@piaille.fr 2026-05-05 22:48

    @jpmens@mastodon.social The end timestamp :D

    Open ##2194325

  • @paul_ipv6@infosec.exchange 2026-05-05 23:21

    @jpmens@mastodon.social this was why we did an RFC for it... i trust quad9 to follow the full RFC and review regularly to see if it can be taken down. interesting in q8. i thought they auto-NTA'ed on some level of failure. should make a good dnsoarc talk for someone doing a post-mortem on this.

    Open ##2194327

  • @jpmens@mastodon.social It's been a while since I dug into #dnssec but ... I thought the goal of a cryptographic trust infrastructure included that a company (Let's call them "quad9") can't interfere with someone else's #DNS records. (Let's call them ".de") But apparently, quad9 can just say "eh, ignore .de's policy? Someone help me understand? Added in edit: I understand the policy to be ".de has records authenticated with this key"?

    Open ##2194331