A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
A failed DNSSEC key rollover caused the .AL TLD to go down, but resolution was restored using a Negative Trust Anchor and clients were informed through EDE 33, a new DNS error code indicating DNSSEC validation bypass.
MAIN POINTS
- The .AL TLD experienced downtime due to a failed DNSSEC key rollover.
- A Negative Trust Anchor was used to restore DNS resolution.
- Clients were informed via EDE 33, a new DNS error code.
- EDE 33 signals that DNSSEC validation was bypassed in the response.
TAKEAWAYS
- DNSSEC key rollovers can cause significant disruptions if they fail.
- Negative Trust Anchors are effective in restoring DNS resolution.
- EDE 33 enhances transparency by informing clients of DNSSEC bypass.
- Improved error codes like EDE 33 aid in better DNS troubleshooting.