<?xml version="1.0" encoding="UTF-8"?>
<feed xml:lang="en-US" xmlns="http://www.w3.org/2005/Atom">
  <title>bert hubert finally blogs: PowerDNS 2.9.22 released, RFC 5452 assigned!</title>
  <subtitle type="html">code, musings and more</subtitle>
  <id>tag:blog.netherlabs.nl,2005:Typo</id>
  <generator version="4.0" uri="http://www.typosphere.org">Typo</generator>
  <link href="http://blog.netherlabs.nl/xml/atom/article/142599/feed.xml" rel="self" type="application/atom+xml"/>
  <link href="http://blog.netherlabs.nl/articles/2009/01/27/powerdns-2-9-22-released-rfc-5452-assigned" rel="alternate" type="text/html"/>
  <updated>2009-01-27T23:13:15+01:00</updated>
  <entry>
    <author>
      <name>bert hubert</name>
      <email>bert.hubert@netherlabs.nl</email>
    </author>
    <id>urn:uuid:212b8f56-4bb7-4d8a-b0f9-dc488076e04e</id>
    <published>2009-01-27T22:56:00+01:00</published>
    <updated>2009-01-27T23:13:15+01:00</updated>
    <title type="html">PowerDNS 2.9.22 released, RFC 5452 assigned!</title>
    <link href="http://blog.netherlabs.nl/articles/2009/01/27/powerdns-2-9-22-released-rfc-5452-assigned" rel="alternate" type="text/html"/>
    <category term="powerdns" scheme="http://blog.netherlabs.nl/articles/category/powerdns" label="PowerDNS"/>
    <summary type="html">&lt;p&gt;Hi everybody!&lt;/p&gt;

&lt;p&gt;What a day! Remco van Mook and I received a message today that our &lt;a href="http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be"&gt;RFC Draft&lt;/a&gt; (full text &lt;a href="http://tools.ietf.org/html/draft-ietf-dnsext-forgery-resilience-10"&gt;here&lt;/a&gt;) has entered the &amp;#8216;AUTH48&amp;#8217; stage. This means that it has been assigned a number (RFC 5452!), and that barring meteor strikes or similar things, we are now finally done. Yay!&lt;/p&gt;

&lt;p&gt;We spent 2 years and 9 months on this. It felt like even more. I&amp;#8217;ve been told the draft has already made a difference in some places - from now on, DNS implementations that have certain bad spoofing behaviour &lt;code&gt;MUST&lt;/code&gt; clean up their act :-)&lt;/p&gt;

&lt;p&gt;In short, had this RFC been followed, the whole Kaminsky DNS scare could have been prevented. Do note that the draft is 2 years older than Kaminksy&amp;#8217;s discovery. The DNS community should have listened to Dan Bernstein *10* years ago.&lt;/p&gt;

&lt;p&gt;Some more thoughts on this subject can be found &lt;a href="http://blog.netherlabs.nl/articles/2008/07/09/some-thoughts-on-the-recent-dns-vulnerability"&gt;here&lt;/a&gt;. I&amp;#8217;m slightly bitter.&lt;/p&gt;

&lt;p&gt;As if the RFC weren&amp;#8217;t enough excitement for one day, I also released PowerDNS Authoritative Server 2.9.22, the first release of the authoritative server in almost 20 months. Because of this long delay, a lot of effort was spent field testing this release before it &amp;#8216;went gold&amp;#8217; (to use an expression I really despise).&lt;/p&gt;

&lt;p&gt;I sincerely hope we shook out most of the bugs. The PowerDNS community really delivered, and many of our enthusiastic users deployed pre-release code on their significant installations, to make sure everybody else would be able to upgrade with confidence.&lt;/p&gt;

&lt;p&gt;Read the whole store &lt;a href="http://doc.powerdns.com/changelog.html#CHANGELOG-AUTH-2-9-22"&gt;here&lt;/a&gt;.&lt;/p&gt;</summary>
    <content type="html">&lt;p&gt;Hi everybody!&lt;/p&gt;

&lt;p&gt;What a day! Remco van Mook and I received a message today that our &lt;a href="http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be"&gt;RFC Draft&lt;/a&gt; (full text &lt;a href="http://tools.ietf.org/html/draft-ietf-dnsext-forgery-resilience-10"&gt;here&lt;/a&gt;) has entered the &amp;#8216;AUTH48&amp;#8217; stage. This means that it has been assigned a number (RFC 5452!), and that barring meteor strikes or similar things, we are now finally done. Yay!&lt;/p&gt;

&lt;p&gt;We spent 2 years and 9 months on this. It felt like even more. I&amp;#8217;ve been told the draft has already made a difference in some places - from now on, DNS implementations that have certain bad spoofing behaviour &lt;code&gt;MUST&lt;/code&gt; clean up their act :-)&lt;/p&gt;

&lt;p&gt;In short, had this RFC been followed, the whole Kaminsky DNS scare could have been prevented. Do note that the draft is 2 years older than Kaminksy&amp;#8217;s discovery. The DNS community should have listened to Dan Bernstein *10* years ago.&lt;/p&gt;

&lt;p&gt;Some more thoughts on this subject can be found &lt;a href="http://blog.netherlabs.nl/articles/2008/07/09/some-thoughts-on-the-recent-dns-vulnerability"&gt;here&lt;/a&gt;. I&amp;#8217;m slightly bitter.&lt;/p&gt;

&lt;p&gt;As if the RFC weren&amp;#8217;t enough excitement for one day, I also released PowerDNS Authoritative Server 2.9.22, the first release of the authoritative server in almost 20 months. Because of this long delay, a lot of effort was spent field testing this release before it &amp;#8216;went gold&amp;#8217; (to use an expression I really despise).&lt;/p&gt;

&lt;p&gt;I sincerely hope we shook out most of the bugs. The PowerDNS community really delivered, and many of our enthusiastic users deployed pre-release code on their significant installations, to make sure everybody else would be able to upgrade with confidence.&lt;/p&gt;

&lt;p&gt;Read the whole store &lt;a href="http://doc.powerdns.com/changelog.html#CHANGELOG-AUTH-2-9-22"&gt;here&lt;/a&gt;.&lt;/p&gt;</content>
  </entry>
  <entry>
    <author>
      <name>Lennie</name>
    </author>
    <id>urn:uuid:1c0390e8-a538-42ee-89bf-9359ceb0d9c8</id>
    <published>2009-02-08T16:32:12+01:00</published>
    <updated>2009-02-08T16:32:12+01:00</updated>
    <title type="html">Comment on PowerDNS 2.9.22 released, RFC 5452 assigned! by Lennie</title>
    <link href="http://blog.netherlabs.nl/articles/2009/01/27/powerdns-2-9-22-released-rfc-5452-assigned#comment-142602" rel="alternate" type="text/html"/>
    <content type="html">sorry, that was a typo, it's: &lt;a href="http://www.EDNS-ping.org" rel="nofollow"&gt;www.EDNS-ping.org&lt;/a&gt;
</content>
  </entry>
  <entry>
    <author>
      <name>Lennie</name>
    </author>
    <id>urn:uuid:f1396313-9735-4ac3-ba24-6876a114c733</id>
    <published>2009-02-08T16:27:57+01:00</published>
    <updated>2009-02-08T16:27:57+01:00</updated>
    <title type="html">Comment on PowerDNS 2.9.22 released, RFC 5452 assigned! by Lennie</title>
    <link href="http://blog.netherlabs.nl/articles/2009/01/27/powerdns-2-9-22-released-rfc-5452-assigned#comment-142601" rel="alternate" type="text/html"/>
    <content type="html">And he keeps on going with &lt;a href="http://www.ENDS-ping.org" rel="nofollow"&gt;www.ENDS-ping.org&lt;/a&gt; as the next draft he's working on</content>
  </entry>
  <entry>
    <author>
      <name>Sean Leach</name>
    </author>
    <id>urn:uuid:67c64242-a42e-4355-ad9b-c846a96a272c</id>
    <published>2009-01-28T03:32:38+01:00</published>
    <updated>2009-01-28T03:32:38+01:00</updated>
    <title type="html">Comment on PowerDNS 2.9.22 released, RFC 5452 assigned! by Sean Leach</title>
    <link href="http://blog.netherlabs.nl/articles/2009/01/27/powerdns-2-9-22-released-rfc-5452-assigned#comment-142600" rel="alternate" type="text/html"/>
    <content type="html">Congrats Bert!</content>
  </entry>
</feed>

