Experts to Feds: Sign the DNS root ASAP
- 26 November, 2008 07:35
- Comments
Internet security gurus and leading vendors are urging the US federal government to rapidly deploy security and authentication mechanisms at the top level of the DNS hierarchy, which is known as the root zone.
In recent weeks, the National Telecommunications and Information Administration (NTIA) has received 30-plus comments in favor of securing DNS root zone data.
These comments are from the Internet Architecture Board (IAB) and the Internet Society as well as ISPs and domain name operators such as PayPal, Akamai Technologies, NeuStar, Comcast and Afilias.
The "rapid adoption of DNSSEC and signing of the root zone is an urgent requirement," wrote Michael Barrett, CISO with PayPal. "We applaud NTIA for initiating this inquiry, and urge it to move with all possible speed to implement DNSSEC [DNS Security Extensions]. Inaction or further delay would be detrimental to the interest of consumers and other Internet users and to the healthy growth of electronic commerce."
"Comcast is strongly in favor of the global adoption of DNSSEC, starting with the signing of the root," said a letter from Kathryn Zachem, vice president of regulatory and state legislative affairs, and Jason Livingood, executive director of Internet systems engineering with Comcast. "Until the root is signed, signatures for a top-level domain such as .net or .com, and signatures in domains like Comcast.net are of limited utility."
While the majority of the comments received by NTIA recommend deploying DNSSEC across the root zone, many of them prefer that this is done by the nonprofit Internet Corporation for Assigned Names and Numbers (ICANN) rather than a for-profit corporation such as VeriSign, which operates root servers A and J.
The Asia-Pacific Network Information Centre, a regional Internet registry, said it supports "ICANN's proposals to sign the root zone using the DNSSEC framework in a timely manner."
IAB Chair Olaf Kolkman similarly proposed that details about DNSSEC implementation on the root zone "should be decided upon within the context of the multi-stakeholder process, as currently embodied in ICANN. This would ensure involvement of all stakeholders through well established mechanisms."
The NTIA also received letters discouraging DNSSEC deployment from two lesser-known organizations -- PublicRoot Consortium and AV8 Internet -- as well as a few crackpot comments that are typical of any open Internet-based process.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- National Telecommunications and Information Administration
- Internet Architecture Board
- Internet Society (ISOC)
- ICANN - Internet Corporation for Assigned Names and Numbers
- IANA -- Internet Assigned Numbers Authority
- Internet standard
- IETF: Should we ignore the Kaminsky bug?
- Government Web Security
- request for public comments
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Microsoft at a loss over Event Viewer scam
-
Windows 7 for Dummies® Dvd+book Bundle
-
Teach Yourself Visually Windows 7
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition












Comments
Post new comment