Skip to content
A chain of trust running from the signed root through a signed TLD and stopping at an unsigned second-level domain, with the counted figures beside each step

DNSSEC: Protecting Your Traffic From Forgery

The hard part of DNSSEC was finished years ago. Counted from the live root zone on 27 September 2026, 1,351 of 1,438 top level domains carry a DS record and every one of the 1,038 gTLDs is signed. Then it stops dead. A census of every gov.uk domain in the official register finds 39 signed out of 2,390 that still resolve, nine of them parish councils, while HMRC, the NHS, GCHQ and the National Cyber Security Centre are not among them. One certificate authority in nine has signed. So has one Linux distribution in three. windowsupdate.com has no DS at all. This is what a forged answer actually costs, what signing does about it, why the usual excuses do not survive contact with the numbers, and whether forty-two years after Mockapetris the real problem is that almost nobody understands what DNS actually promises.

27th September 2026 Â· 48 min Â· 10979 words Â· Damien Dye

Webex Is Looking For Your Certificates On A Cisco Build Server

Webex 46.8.0.35631 on Fedora 44 sits behind a yellow banner reading “Offline - No internet connection” while every other program on the machine reaches the internet without complaint. It stopped the VoIP line dead. The network was never the problem: Cisco bundle their own fork of OpenSSL and built it with OPENSSLDIR set to /workspace/.conan2/p/b/cisco8ee8b59cf93de/p/ssl, a directory that exists on a build container and nowhere else, so it loads no trust anchors and every handshake fails. The post runs in order: what the broken state actually is, asking the shipped library where it thinks its certificates live, reproducing the exact error code outside Webex, why nothing warns you, the two fixes that do not work and why, and the one that does. Then the build process: they used $ORIGIN for the code and left three data paths absolute, the RPM header names a container ID so the container was already in the pipeline and never used to run the result, the package requires a glibc from 2018 because they will not link statically, 2.2 GB is shipped twice, and it carries no documentation and no file marked as configuration. Then how it should have been built, the six fixes and the one-line check that catches it. And finally the cross-check: Cisco hold 98 entries in CISA’s known-exploited catalogue, second only to Microsoft, and a trust path nobody checked and a bypass nobody checked are the same failure at different stakes.

15th September 2026 Â· 42 min Â· 9141 words Â· Damien Dye