Conversation

Toke Høiland-Jørgensen

Got a notification from my registrar that I was using an outdated DNSSEC key algorithm for my domain, so decided to re-learn how DNSSEC signing actually works in Bind.

Discovered that there's now a mode where Bind will manage keys and signing automatically. Yay! Only problem is, the domain in question was not configured that way.

Decided to use the occasion to swap over the config to that mode. Which of course caused Bind to generate new (managed) keys without doing any of the smooth gradual rollover that it otherwise implements. Oops!

Ah well, everything is set up correctly now, and it'll only be a single TTL until the whole world agrees. Should be fine; right? 😅

#DNS #DNSSEC #OpsFail
1
0
3

@toke Ah, I am too late to point you to this very helpful write-up of how to migrate gently from one mode to another written up by the esteemed @fanf — hopefully useful to anyone else following in your footsteps!

https://dotat.at/@/2024-05-11-dnssec-policy.html

1
0
0
@dwm @fanf yes, this does indeed look like that I should have done. Ah well 🤷‍♂️
1
0
1

@toke In role-playing games as in life, "Experience is what you get right after you needed it."

1
0
0
@dwm haha, yes indeed. Now, to figure out how to remember this when I next have to pay attention to it in another decade or so...
1
0
0

@toke @dwm personal / private journal entry or public blog article?

1
0
0
@drscriptt @dwm that's not a bad idea, actually!
0
0
0