ELSEIF
Your brief EB
183 stories from 71 feeds 32 clusters Refreshed 10 minutes ago next pull 13:20

INFRA Signal 202

A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed

WHY IT MATTERS

Operators of DNSSEC-signed zones now have visibility into when a resolver has suspended validation, rather than receiving a seemingly legitimate response with no indication that spoofing protections are inactive. This makes the security tradeoff of NTAs explicit to clients and aids debugging during DNSSEC incidents.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The .al TLD became unreachable on validating resolvers after the operator published a new DNSKEY but the root zone DS record still pointed to the old key, breaking the chain of trust.

02

Cloudflare deployed a Negative Trust Anchor for .al roughly three hours after the break, restoring resolution at the cost of DNS spoofing protection for the entire TLD.

03

Cloudflare's 1.1.1.1 now returns EDE 33 alongside responses served under an NTA, giving clients direct notification in the DNS response that validation was bypassed.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Cloudflare A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed Open ↗