<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Trend-Watcher</title>
	<atom:link href="http://www.trend-watcher.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.trend-watcher.org</link>
	<description>Watch them Trends</description>
	<lastBuildDate>Sun, 15 Jan 2012 20:52:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>The Internet Hourglass</title>
		<link>http://www.trend-watcher.org/archives/the-internet-hourglass/</link>
		<comments>http://www.trend-watcher.org/archives/the-internet-hourglass/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 20:52:24 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=598</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00063300000000002 seconds-->
<!---Displayed in 0.119817 seconds.-->
This cartoon appeared in the July 2011 issue of the IETF Journal &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00057600000000002 seconds-->
<!---Displayed in 0.102888 seconds.-->
<p>This cartoon appeared in the <a href="http://http://www.internetsociety.org/publications/ietf-journal-october-2011">July 2011 issue of the IETF Journal</a></p>
<p><a href="http://www.trend-watcher.org/wp-content/uploads/2012/01/hourglass-3.png"><img class="wp-image-599 alignnone" title="hourglass-3" src="http://www.trend-watcher.org/wp-content/uploads/2012/01/hourglass-3-823x1024.png" alt="" width="461" height="573" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fthe-internet-hourglass%2F&amp;title=The%20Internet%20Hourglass" id="wpa2a_2">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/the-internet-hourglass/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Family CA</title>
		<link>http://www.trend-watcher.org/archives/the-family-ca/</link>
		<comments>http://www.trend-watcher.org/archives/the-family-ca/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 20:48:39 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=587</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00059999999999999 seconds-->
<!---Displayed in 0.105882 seconds.-->
This cartoon appeared in the october 2011 issue of the IETF Journal and was inspired the broken Diginotar CA. &#160; &#160;]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00057299999999993 seconds-->
<!---Displayed in 0.121866 seconds.-->
<p>This cartoon appeared in the october <a href="http://www.internetsociety.org/publications/ietf-journal-october-2011">2011 issue of the IETF Journal</a> and was inspired the broken Diginotar CA.</p>
<p>&nbsp;</p>
<p><a href="http://www.trend-watcher.org/wp-content/uploads/2012/01/Family-CA-e1326660135853.png"><img class="alignleft  wp-image-588" title="Family-CA" src="http://www.trend-watcher.org/wp-content/uploads/2012/01/Family-CA-1024x762.png" alt="" width="502" height="373" /></a></p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fthe-family-ca%2F&amp;title=The%20Family%20CA" id="wpa2a_4">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/the-family-ca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>draft-poster-session</title>
		<link>http://www.trend-watcher.org/archives/draft-poster-session/</link>
		<comments>http://www.trend-watcher.org/archives/draft-poster-session/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 19:49:00 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[IETF]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=574</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00061699999999998 seconds-->
<!---Displayed in 0.103139 seconds.-->
If you really, really, really want to draw attention to your just published Internet Draft you may consider walking around with this T-Shirt. (And if there are 5 people commenting that they would buy such shirt I&#8217;ll put the design in the IETF store at Cafepress.)]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00057599999999991 seconds-->
<!---Displayed in 0.102987 seconds.-->
<p>If you really, really, really want to draw attention to your just published Internet Draft you may consider walking around with this T-Shirt.</p>
<p>(And if there are 5 people commenting that they would buy such shirt I&#8217;ll put the design in the <a href="http://www.cafepress.com/ietf" target="_blank">IETF store at Cafepress.</a>)</p>
<p><img class="alignnone" src="http://www.secret-wg.org/Poster-Session.png" alt="Poster-Session T-Shirt" width="400" /></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fdraft-poster-session%2F&amp;title=draft-poster-session" id="wpa2a_6">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/draft-poster-session/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Harry&#8217;s Wand</title>
		<link>http://www.trend-watcher.org/archives/harrys-wand/</link>
		<comments>http://www.trend-watcher.org/archives/harrys-wand/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 19:40:19 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[IETF]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=568</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00062699999999993 seconds-->
<!---Displayed in -0.888812 seconds.-->
To appear in the IETF Journal.]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.000571 seconds-->
<!---Displayed in 0.117208 seconds.-->
<p>To appear in the <a href="http://www.isoc.org/ietfjournal/">IETF Journal</a>.</p>
<p><img class="alignnone" src="http://www.secret-wg.org/IETF-Journal/Harry-ID-small.png" alt="Harry's Loc/Split Wand" width="500" /></p>
<hr />
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fharrys-wand%2F&amp;title=Harry%26%238217%3Bs%20Wand" id="wpa2a_8">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/harrys-wand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Diffserv Tap</title>
		<link>http://www.trend-watcher.org/archives/the-diffserv-tap/</link>
		<comments>http://www.trend-watcher.org/archives/the-diffserv-tap/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 11:12:51 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[IETF]]></category>
		<category><![CDATA[IP]]></category>
		<category><![CDATA[QOS]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=559</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00060399999999999 seconds-->
<!---Displayed in 0.102852 seconds.-->
To appear in the IETF Journal.]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00057299999999999 seconds-->
<!---Displayed in 0.11926 seconds.-->
<p>To appear in the <a href="http://www.isoc.org/ietfjournal/">IETF Journal</a>.</p>
<p><img class="alignnone" src="http://www.secret-wg.org/IETF-Journal/DiffservTap-small.png" alt="Pile of NAT Boxes" width="400" height="488" /></p>
<hr />
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fthe-diffserv-tap%2F&amp;title=The%20Diffserv%20Tap" id="wpa2a_10">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/the-diffserv-tap/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DNSSEC Root Key declaration</title>
		<link>http://www.trend-watcher.org/archives/dnssec-root-key-declaration/</link>
		<comments>http://www.trend-watcher.org/archives/dnssec-root-key-declaration/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 08:29:42 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=522</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.000606 seconds-->
<!---Displayed in 0.10218 seconds.-->
On 16 June 2010 around 21:20 UTC I witnessed a key generation procedure by which a DNSSEC Key Signing Key for signing the DNS root has been created. The representation of this key in the DS RR format is as follows: . IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5 The hash of this DS RR represented [...]]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00058600000000003 seconds-->
<!---Displayed in 0.137872 seconds.-->
<p>On 16 June 2010 around 21:20 UTC I witnessed a key generation procedure by which a DNSSEC Key Signing Key for signing the DNS root has been created.</p>
<p>The representation of this key in the DS RR format is as follows:</p>
<blockquote class="code"><p>
. IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5</p></blockquote>
<p>The hash of this DS RR represented as a biometric wordlist reads:</p>
<blockquote class="code"><p>
deckhand pedigree snapline breakaway kickoff hemisphere flytrap detergent guidance coherence eating outfielder facial hurricane hamlet fortitude keyboard Bradbury cranky leprosy Dupont adroitness willow Chicago tempest sandalwood tactics component uproot distortion payday positive</p></blockquote>
<p>For more information about the publication of the trust anchor see:</p>
<p>http://www.root-dnssec.org/wp-content/uploads/2010/01/draft-icann-dnssec-trust-anchor-00.txt</p>
<p>For more information on the signing of the root see:</p>
<p>http://www.root-dnssec.org/</p>
<p>Olaf Kolkman<br />
July 13, 2010</p>
<p>A PGP signed version of this declaration can be found <a href="http://www.nlnetlabs.nl/downloads/DS-20100616.txt">here</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fdnssec-root-key-declaration%2F&amp;title=DNSSEC%20Root%20Key%20declaration" id="wpa2a_12">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/dnssec-root-key-declaration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Korg Poly 800</title>
		<link>http://www.trend-watcher.org/archives/the-korg-poly-800/</link>
		<comments>http://www.trend-watcher.org/archives/the-korg-poly-800/#comments</comments>
		<pubDate>Thu, 13 May 2010 16:36:31 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Music]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[Korg]]></category>
		<category><![CDATA[Synthesizer]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Waste of Time Department]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=491</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00060199999999999 seconds-->
<!---Displayed in 0.102851 seconds.-->
I recently plugged in the old KORG Poly800. One of the early mass produced polyphonic Synths. Unfortunately the batteries had drained, and the sound settings were completely gone. Now it is possible to restore the sound settings from the 20 year old cassette tape, if you a) would be able to find the original tape, [...]]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00062800000000007 seconds-->
<!---Displayed in 0.1022 seconds.-->
<p><a href="http://www.trend-watcher.org/wp-content/uploads/2010/05/IMG_4843.jpg"><img class="size-medium wp-image-518 alignleft" title="KORG POLY 800" src="http://www.trend-watcher.org/wp-content/uploads/2010/05/IMG_4843-225x300.jpg" alt="" width="225" height="300" /></a></p>
<p>I recently plugged in the old KORG Poly800. One of the early mass produced polyphonic Synths.</p>
<p>Unfortunately the batteries had drained, and the sound settings were completely gone. Now it is possible to restore the sound settings from the 20 year old cassette tape, if you a) would be able to find the original tape, and b) would have a cassette player. Unfortunately I have neither.</p>
<p>There are two ways you can go about this. Either you can restore all original sound settings manually from the documentation (<a href="http://www.secret-wg.org/KORG/poly800-soundsettings.PDF">pdf here</a>) or you can download a <a href="http://www.secret-wg.org/KORG/Poly800-factory.wav">&#8220;wav&#8221; file  with the original program</a> from the POLY800 cassette. Connecting the Poly800 to your computer and fiddling a bit with the output level took me about 5 minutes.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fthe-korg-poly-800%2F&amp;title=The%20Korg%20Poly%20800" id="wpa2a_14">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/the-korg-poly-800/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.secret-wg.org/KORG/Poly800-factory.wav" length="245848" type="audio/x-wav" />
		</item>
		<item>
		<title>Pile Of NAT Boxes</title>
		<link>http://www.trend-watcher.org/archives/pile-of-nat-boxes/</link>
		<comments>http://www.trend-watcher.org/archives/pile-of-nat-boxes/#comments</comments>
		<pubDate>Wed, 12 May 2010 23:07:59 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Cartoons]]></category>
		<category><![CDATA[Cartoon]]></category>
		<category><![CDATA[IPv4 Exhaustion]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[NAT]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=348</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00061 seconds-->
<!---Displayed in 0.107954 seconds.-->
To appear in the IETF Journal.]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00057300000000005 seconds-->
<!---Displayed in -0.897289 seconds.-->
<p>To appear in the <a href="http://www.isoc.org/ietfjournal/">IETF Journal</a>.</p>
<p><img class="alignnone" src="http://www.secret-wg.org/IETF-Journal/NATpile-small.png" alt="Pile of NAT Boxes" width="400" height="488" /></p>
<hr />
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fpile-of-nat-boxes%2F&amp;title=Pile%20Of%20NAT%20Boxes" id="wpa2a_16">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/pile-of-nat-boxes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress&#8230;.</title>
		<link>http://www.trend-watcher.org/archives/wordpress/</link>
		<comments>http://www.trend-watcher.org/archives/wordpress/#comments</comments>
		<pubDate>Wed, 12 May 2010 21:28:44 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Waste of Time Department]]></category>

		<guid isPermaLink="false">http://www.trend-watcher.org/?p=341</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.000601 seconds-->
<!---Displayed in 0.102348 seconds.-->
I gave in.. after mucking around with LifeType for a few years I decided to migrate my blogs to wordpress.  Dan Rooke&#8217;s plog import plugin helped me to port all the posts. While I managed to get both the net-dns blog as well as this one running from the FreeBSD port install using the  Virtual Multiblog [...]]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.000587 seconds-->
<!---Displayed in 0.102314 seconds.-->
<p>I gave in.. after mucking around with <a href="http://lifetype.net">LifeType </a>for a few years I decided to migrate my blogs to wordpress.  Dan Rooke&#8217;s <a href="http://forums.lifetype.net/viewtopic.php?f=23&amp;t=4337">plog import plugin</a> helped me to port all the posts. While I managed to get both the net-dns blog as well as this one running from the FreeBSD port install using the  <a href="http://striderweb.com/nerdaphernalia/features/virtual-multiblog/" target="_blank">Virtual Multiblog</a> plugin.</p>
<p>After the usual tweaking of themes I&#8217;m done and I hope I can stay away from the actual install and configuration for a while.</p>
<p>You might ask: why not drupal.</p>
<p>Answer: I couldn&#8217;t find an easy migration tool for the LifeType blog.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fwordpress%2F&amp;title=WordPress%26%238230%3B." id="wpa2a_18">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On Death and Rollovers</title>
		<link>http://www.trend-watcher.org/archives/on-death-and-rollovers/</link>
		<comments>http://www.trend-watcher.org/archives/on-death-and-rollovers/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 14:29:48 +0000</pubDate>
		<dc:creator>olaf</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[Operations]]></category>
		<category><![CDATA[Unbound]]></category>

		<guid isPermaLink="false">http://www.evangineer.net/?p=125</guid>
		<description><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00060700000000002 seconds-->
<!---Displayed in 0.102325 seconds.-->
I just posted this to the unbound-users list In Geoff Huston&#8217;s recent ISP Column &#8220;Roll Over and Die?&#8221;, Roy Arends made a thorough analysis of the behavior of Unbound in the face of increased traffic towards authoritative servers after a failed key-rollover. Key of Roy&#8217;s analysis is the observation that Unbound holds back after finding a [...]]]></description>
			<content:encoded><![CDATA[<!--Searching /usr/local/www/wordpress/wp-content/uploads/random-image: found 71 images in 0.00059199999999998 seconds-->
<!---Displayed in 0.123914 seconds.-->
<div><em><span style="font-size: x-small;">I just posted this to the unbound-users list</span></em></div>
<p>In Geoff Huston&#8217;s recent <a title="Roll over and die" href="http://www.potaroo.net/ispcol/2010-02/rollover.pdf" target="_blank">ISP Column &#8220;Roll Over and Die?&#8221;</a>, Roy Arends made a thorough analysis of the behavior of Unbound in the face of increased traffic towards authoritative servers after a failed key-rollover.</p>
<p>Key of Roy&#8217;s analysis is the observation that Unbound holds back after finding a bogus DNSKEY but does that on a per query instead of a per zone basis.</p>
<blockquote class="code"><p>The default value of 60 seconds causes UNBOUND to restrain itself. However, since its a per-message cache, it only restrains itself for that qname/qclass/qtype tuple. Hence, if a different query is asked, UNBOUND needs to validate the response, sees a bogus DNSKEY in the cache and starts to re-fetch the dnskey keyset. In other words, a lame root key will cause DNSKEY queries for every unique query seen per 60 second window.</p></blockquote>
<p>We will address this using a caching mechanism that will treat DNSSEC validation failures on a zone wide basis instead of treating them as intermittent RR-set failures. That should reduce the traffic to authoritative servers significantly.</p>
<p>The reason why this particular problem is interesting is that, as developers, we are constantly trying to make the tradeoff between the ability to recover from failure and the costs that those recovery mechanism impose on third parties. Failure to validate a signature can have many reasons, varying from misconfiguration or synchronization failure at the authoritative side, to on-path failure or attack, to misconfiguration a the receiving side. In this case we have not been conservative enough when making the trade-offs.</p>
<p>The fact that these sort of issues are identified are a healthy sign of what is still early deployment and we are eager to learn from these experiences. We use two resources for gathering experience that can help us making implementation choices: the IETF DNSOP working group and <a title="DNS OARC" href="https://www.dns-oarc.net/" target="_blank">OARC</a>. OARC is an organization where data is collected and shared so that impact of certain implementation behavior is quantified. We would like to ask people to contribute measurement data and share experiences.</p>
<p>Back to the particular issue of stale keys. The column points out that there are mechanisms to prevent stale keys being retained after a key rollover: the mechanism described in RFC5011. As of version 1.4.0 Unbound has native support for maintaining the trust-anchor for key-rollovers based on RFC5011. We have also made &#8220;autotrust&#8221; &lt;link&gt; available for cases where trust-anchors need to be maintained  and Unbound is not used.</p>
<p>In the particular case described in the columnm, RFC5011 methodology might not have worked; an old OS distribution carrying a stale key that is several generations old cannot be tracked using RFC5011 techniques. Wijngaards and Kolkman have been working on a proposal to fix that particular issue: &#8220;<a title="Trust Anchor History" href="http://tools.ietf.org/html/draft-wijngaards-dnsop-trust-history">DNSSEC Trust Anchor History Service</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.trend-watcher.org%2Farchives%2Fon-death-and-rollovers%2F&amp;title=On%20Death%20and%20Rollovers" id="wpa2a_20">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.trend-watcher.org/archives/on-death-and-rollovers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

