Cloudflare: Please activate DNSSEC for servo.org
Categories
(Infrastructure & Operations :: DNS and Domain Registration, task)
Tracking
(Not tracked)
People
(Reporter: jan, Assigned: rtucker)
References
Details
(Keywords: nightly-community, Whiteboard: [kanban:https://webops.kanbanize.com/ctrl_board/19/6954])
Reporter | ||
Comment 1•6 years ago
|
||
Comment 2•6 years ago
|
||
Done! Below is the information that cloudflare provided - I assume that you would store the DS record at MarkMonitor? Thanks!
To enable DNSSEC you will need to add this DS record to your registrar. Most registrars will ask for only a few of the fields below. We have instructions for common registrars here
DS Record
servo.org. 3600 IN DS 2371 13 2 9D2D3A68FD39965788A13ECCBAAC5FF1CDA1B1875D2E446ED8DBB15ADD6DC397
Digest
9D2D3A68FD39965788A13ECCBAAC5FF1CDA1B1875D2E446ED8DBB15ADD6DC397
Digest Type
SHA256
Algorithm
13
Public Key
mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
Key Tag
2371
Flags
257
Reporter | ||
Comment 3•6 years ago
|
||
Thanks! Confirmed, the zone is properly signed by Cloudflare: http://dnsviz.net/d/servo.org/dnssec/
Eric, could you store the DS record at MarkMonitor? Thanks! :)
Comment 4•6 years ago
|
||
Rob is probably the expert on this, can you help here Rob?
Assignee | ||
Comment 5•6 years ago
|
||
The markmonitor web interface isn't working for some reason. Reaching out to our contact at MM to configure this.
Assignee | ||
Comment 6•6 years ago
|
||
Actually I was able to do it. The digest type needs to be set to 2 not SHA256 in their web interface.
Assignee | ||
Comment 7•6 years ago
|
||
http://dnsviz.net/d/servo.org/dnssec/
Leads me to believe this has been handled correctly.
Reporter | ||
Comment 8•6 years ago
|
||
Confirmed, thank you!
http://dnsviz.net/d/servo.org/XDTXXQ/dnssec/
https://www.hardenize.com/report/servo.org/1546966900#domain_dnssec
Description
•