Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
News
Sports
TV & Film
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts126/v4/16/a3/97/16a397cc-90eb-7347-3cf8-ed3287c5c8a1/mza_11790339641350512172.jpg/600x600bb.jpg
PING
APNIC
50 episodes
5 days ago
PING is a podcast for people who want to look behind the scenes into the workings of the Internet. Each fortnight we will chat with people who have built and are improving the health of the Internet. The views expressed by the featured speakers are their own and do not necessarily reflect the views of APNIC.
Show more...
Tech News
Technology,
History,
News
RSS
All content for PING is the property of APNIC and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
PING is a podcast for people who want to look behind the scenes into the workings of the Internet. Each fortnight we will chat with people who have built and are improving the health of the Internet. The views expressed by the featured speakers are their own and do not necessarily reflect the views of APNIC.
Show more...
Tech News
Technology,
History,
News
https://is1-ssl.mzstatic.com/image/thumb/Podcasts126/v4/16/a3/97/16a397cc-90eb-7347-3cf8-ed3287c5c8a1/mza_11790339641350512172.jpg/600x600bb.jpg
DELEG: Changing the DNS engine in flight again
PING
59 minutes 27 seconds
5 months ago
DELEG: Changing the DNS engine in flight again
In this episode of PING, APNIC’s Chief Scientist, Geoff Huston (https://blog.apnic.net/author/geoff-huston/), revisits changes underway in how the Domain Name System (DNS) delegates authority over a given zone and how resolvers discover the new authoritative sources. We last explored this in March 2024. (https://blog.apnic.net/2024/03/07/podcast-deleg-in-band-dns-delegation/)In DNS, the word ‘domain’ refers to a scope of authority. Within a domain, everything is governed by its delegated authority. While that authority may only directly manage its immediate subdomains (children), its control implicitly extends to all subordinate levels (grandchildren and beyond). If a parent domain withdraws delegation from a child, everything beneath that child disappears. Think of it like a Venn diagram of nested circles — being a subdomain means being entirely within the parent’s scope.The issue lies in how this delegation is handled. It’s by way of nameserver (NS) records. These are both part of the child zone (where they are defined) and the parent zone (which must reference them). This becomes especially tricky with DNSSEC. The parent can’t authoritatively sign the child’s NS records because they are technically owned by the child. But if the child signs them, it breaks the trust chain from the parent.Another complication is the emergence of third parties to the delegate, who actually operate the machinery of the DNS. We need mechanisms to give them permission to make changes to operational aspects of delegation, but not to hold all the keys a delegate has regarding their domain name.A new activity has been spun up in the IETF (https://datatracker.ietf.org/doc/charter-ietf-deleg/) to discuss how to alter this delegation problem by creating a new kind of DNS record, the DELEG record. This is proposed to follow the Service Binding model defined in RFC 9460. Exactly how this works and what it means for the DNS is still up in the air.DELEG could fundamentally change how authoritative answers are discovered, how DNS messages are transported, and how intermediaries interact with the DNS ecosystem. In the future, significant portions of DNS traffic might flow over new protocols, introducing novel behaviours in the relationships between resolvers and authoritative servers.Read more about DELEG on the APNIC Blog and the web:* DNS and the proposed DELEG record (https://blog.apnic.net/2024/02/08/dns-and-the-proposed-deleg-record/) (APNIC Blog, February 2024)* DELEG Working Group Charter (https://datatracker.ietf.org/doc/charter-ietf-deleg/) (IETF Website)* Service Binding and Parameter Specification via the DNS (https://datatracker.ietf.org/doc/rfc9460/) (IETF RFC 9460)*
PING
PING is a podcast for people who want to look behind the scenes into the workings of the Internet. Each fortnight we will chat with people who have built and are improving the health of the Internet. The views expressed by the featured speakers are their own and do not necessarily reflect the views of APNIC.