<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Dnssec on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/dnssec/</link>
    <description>Recent content in Dnssec on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 27 Sep 2026 18:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/dnssec/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DNSSEC: Protecting Your Traffic From Forgery</title>
      <link>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</link>
      <pubDate>Sun, 27 Sep 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</guid>
      <description>Counted from the live root zone: 1,351 of 1,438 TLDs are signed, every single gTLD among them. Then it stops. 39 of 2,390 live gov.uk domains, 1 of 9 certificate authorities, and windowsupdate.com has no DS at all. What DNSSEC stops, what is really blocking it, and whether the problem is that we still do not understand DNS.</description>
    </item>
    <item>
      <title>Resolved: The Resolver You Are Already Running</title>
      <link>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</link>
      <pubDate>Sun, 27 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</guid>
      <description>systemd-resolved is on most Linux desktops, caching every lookup and validating none of them. What the stub on 127.0.0.53 does, measured cache figures, turning DNSSEC on, why DNS over TLS works but DNS over HTTPS does not exist, what Fedora, Ubuntu, Debian and RHEL each ship, and why you almost certainly do not need a custom build.</description>
    </item>
    <item>
      <title>Who Actually Controls DNS</title>
      <link>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</link>
      <pubDate>Tue, 25 Aug 2026 14:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</guid>
      <description>The root of the internet is a 1.5 MB text file. Who edits it, who signs it, and what ICANN has done with the power to decide what goes in it.</description>
    </item>
    <item>
      <title>Samba4 and Securing AD Records Using DNSSEC</title>
      <link>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</link>
      <pubDate>Mon, 24 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</guid>
      <description>Every domain-joined machine finds its DC by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you have. Signing them from a Samba4 DC: BIND with dlz_bind9, inline signing, a hidden primary, dynamic updates kept out of the locator zone, then forcing Windows and Linux clients to validate the signatures.</description>
    </item>
  </channel>
</rss>
