Re: The problem I see with DNSSEC as a potential end user and administrator.

" Ondřej Surý " <ondrej.sury@nic.cz> Fri, 08 August 2008 09:36 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2C2653A6CB5; Fri, 8 Aug 2008 02:36:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 4.127
X-Spam-Level: ****
X-Spam-Status: No, score=4.127 tagged_above=-999 required=5 tests=[AWL=0.500, BAYES_50=0.001, FH_RELAY_NODNS=1.451, FM_FORGED_GMAIL=0.622, HELO_MISMATCH_COM=0.553, J_CHICKENPOX_23=0.6, MIME_8BIT_HEADER=0.3, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L-HGrSAP1gqZ; Fri, 8 Aug 2008 02:36:28 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 4580B3A6CF9; Fri, 8 Aug 2008 02:36:28 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KROKn-000CAN-0U for namedroppers-data@psg.com; Fri, 08 Aug 2008 09:32:33 +0000
Received: from [64.233.182.184] (helo=nf-out-0910.google.com) by psg.com with esmtp (Exim 4.69 (FreeBSD)) (envelope-from <ondrej.sury@nic.cz>) id 1KROKj-000C9s-Bw for namedroppers@ops.ietf.org; Fri, 08 Aug 2008 09:32:31 +0000
Received: by nf-out-0910.google.com with SMTP id g13so804170nfb.11 for <namedroppers@ops.ietf.org>; Fri, 08 Aug 2008 02:32:28 -0700 (PDT)
Received: by 10.210.11.13 with SMTP id 13mr5191929ebk.142.1218187947943; Fri, 08 Aug 2008 02:32:27 -0700 (PDT)
Received: by 10.210.121.1 with HTTP; Fri, 8 Aug 2008 02:32:27 -0700 (PDT)
Message-ID: <e90946380808080232w756e1123u2237fa1ac846173f@mail.gmail.com>
Date: Fri, 08 Aug 2008 11:32:27 +0200
From: Ondřej Surý <ondrej.sury@nic.cz>
To: Duane at e164 dot org <duane@e164.org>
Subject: Re: The problem I see with DNSSEC as a potential end user and administrator.
Cc: Namedroppers <namedroppers@ops.ietf.org>, Mark Andrews <Mark_Andrews@isc.org>, Paul Vixie <paul@vix.com>, bert hubert <bert.hubert@netherlabs.nl>
In-Reply-To: <489C112A.8000306@e164.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: base64
Content-Disposition: inline
References: <489BE047.1010100@e164.org> <e90946380808080203g65c99a72meca9db15c1194df1@mail.gmail.com> <489C0E08.3040406@e164.org> <e90946380808080218n7acddd46gd99d39fa71edcb26@mail.gmail.com> <489C112A.8000306@e164.org>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

2008/8/8 Duane at e164 dot org <duane@e164.org>:
> Ondřej Surý wrote:
>> 2008/8/8 Duane at e164 dot org <duane@e164.org>:
>>> Ondřej Surý wrote:
>>>
>>>> I know that it does add more burder of shoulder of any sysadmin, but
>>>> is it really so much - add a cron job and some monitoring script and
>>>> you are done?
>>> at some point you load the beasts of burden up with so much work that
>>> one extra piece of straw is all that is needed or takes to break the
>>> poor animals back.
>>
>> But now is starts to be only rhethorical discussion.  Have you calculated
>> how much additional work it would be for you?  Using right tools for it
>> (like dnssec-tools[1] or ZKT[2])?
>
> If I have to go out of my way to learn about this stuff you again have
> shown it is neither straight forward nor simple to do.
>
> Until I can type a single command (or no commands) that sets everything
> up I really can't be bothered, since there is no perceived benefit in
> doing so for me.

So when you installed your DNS server infrastructure, was it just
some "magic" command which caused all your domain names to be server
by that servers?  Or did you have to make changes to config files,
generate TSIG keys, configure primary, configure slaves, add zones
to config file...

I see kind of analogy here.  Available tools are bit rough at this time,
but it's magnituted better that it was half a year ago.

Ondrej.
-- 
 Ondřej Surý
 technický ředitel/Chief Technical Officer
 -----------------------------------------
 CZ.NIC, z.s.p.o. -- .cz domain registry
 Americká 23,120 00 Praha 2,Czech Republic
 mailto:ondrej.sury@nic.cz http://nic.cz/
 sip:ondrej.sury@nic.cz tel:+420.222745110
 mob:+420.739013699 fax:+420.222745112
 -----------------------------------------
¶‹§²æìr¸›zǧu©ž²Æ zÚ'jg®Šiz»+z«ž²Ú)²'­~ŠàÂ+a¶°¢·nžË›±Êâmè§jȧ‚W¥Šwš²Ø^™ë,j­{[¡Üš­Èb½èm¶Ÿÿ¢›"z×è®åŠËlþv¦yÚ覗«³