DNSSEC...not a bang but a whimper?, (Tue, May 4th)
Tonight is the night that DNSSECis enabled between the DNSroot servers. I am not going to go into detail since the good people at the other ISChave already done a wonderful job of that in their posting.
Lots of the usual hype in the usual places including The Register, slashdot, etc. The fact is that this really only affects the way your ISPs talk DNS to the root servers. I suspect most users are using their ISPs DNS servers which will continue to talk to their customers the old way. It may cause problems for some users who are hosting their own DNSservers behind antiquated firewalls, but for the most part this will be a non-event.
What I find interesting is that using the resolver test at RIPE, my OpenDNS provided resolvers fail.
Hopefully that will be fixed before the big event.
Update: OpenDNSresponded to my query with a pointer to a forum article. It seems they are just fine.
-- Rick Wanner - rwanner at isc dot sans dot org
(c) SANS Internet Storm Center. http://isc.sans.org Creative Commons Attribution-Noncommercial 3.0 United States License.