<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://www.gandibar.net/feed/rss2/xslt" ?><rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Gandi Bar - DNSSEC at Gandi (UPDATED)  - Comments</title>
  <link>http://www.gandibar.net/</link>
  <atom:link href="http://www.gandibar.net/feed/rss2/comments/1877" rel="self" type="application/rss+xml"/>
  <description>Gandi blog, to share our opinions</description>
  <language>en</language>
  <pubDate>Fri, 17 May 2013 22:25:02 -0400</pubDate>
  <copyright></copyright>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Dotclear</generator>
  
    
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Thomas (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187900</link>
    <guid isPermaLink="false">urn:md5:6a8e63c4528eae922716fc23df4b3bd6</guid>
    <pubDate>Tue, 15 May 2012 18:27:00 -0400</pubDate>
    <dc:creator>Thomas (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Some of you have been asking about securing .info domains with DNSSEC at gandi.net. The .info extension is compatible with DNSSEC (it can be signed), but we have not implemented the interface to support it yet.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Nicolas (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187788</link>
    <guid isPermaLink="false">urn:md5:ea0dbe6063e9581ab43a7c7fb3dc85b0</guid>
    <pubDate>Mon, 30 Apr 2012 04:07:53 -0400</pubDate>
    <dc:creator>Nicolas (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Gian: it's already available on .com&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Gian</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187783</link>
    <guid isPermaLink="false">urn:md5:8cf925a66335600f15b145e2ded9874e</guid>
    <pubDate>Sun, 29 Apr 2012 11:28:58 -0400</pubDate>
    <dc:creator>Gian</dc:creator>
    
    <description>&lt;p&gt;What about .com domains? When DNSSEC will be available for those domains?&lt;/p&gt;


&lt;p&gt;Thanks&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Thomas (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187724</link>
    <guid isPermaLink="false">urn:md5:1512d3eef61bd8e20b48ae305172239a</guid>
    <pubDate>Mon, 23 Apr 2012 10:22:28 -0400</pubDate>
    <dc:creator>Thomas (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Hi Walter,&lt;br /&gt;
It's all about maintaining a trust chain from the authoritative servers. You don't need to get a cert from a CA, just get the public key(s) of the zones you want to use as trust anchors. You can then generate and sign your keys using bind.&lt;br /&gt;
Here's a tutorial you can check out:&lt;br /&gt;
&lt;a href=&quot;http://www.nlnetlabs.nl/publications/dnssec_howto/#x1-90002.3&quot; title=&quot;http://www.nlnetlabs.nl/publications/dnssec_howto/#x1-90002.3&quot; rel=&quot;nofollow&quot;&gt;http://www.nlnetlabs.nl/publication...&lt;/a&gt;&lt;br /&gt;
Enjoy!&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Jonas B.</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187717</link>
    <guid isPermaLink="false">urn:md5:67099cdf4a38cd0b478754992bc64b2a</guid>
    <pubDate>Fri, 20 Apr 2012 14:59:44 -0400</pubDate>
    <dc:creator>Jonas B.</dc:creator>
    
    <description>&lt;p&gt;Worked like a charm! Thanks!&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Walter</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187713</link>
    <guid isPermaLink="false">urn:md5:036c592b30c35f314995d36602371c22</guid>
    <pubDate>Fri, 20 Apr 2012 01:41:32 -0400</pubDate>
    <dc:creator>Walter</dc:creator>
    
    <description>&lt;p&gt;Does this require Verisign/Thawte or is self-signed OK? And if OK, would it cause any problems?&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Alex Dupuy</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187698</link>
    <guid isPermaLink="false">urn:md5:93d67a33fd36fd09e5e29dc3ac0baba1</guid>
    <pubDate>Mon, 16 Apr 2012 13:04:55 -0400</pubDate>
    <dc:creator>Alex Dupuy</dc:creator>
    
    <description>&lt;p&gt;This is great - between this and IPv6 support, I will be transferring my .us registration to you.  My current registrar (dyn.com) provides IPv6 but not DNSSEC support for .us (at a very slightly higher price) and I was looking at some of the cheaper services (namecheap.com, name.com) but I have only one domain, I'd rather get better support for what I am already paying than save a few $$$.  BTW, found your service through comments on the xkcd blag - better than advertising, but you should buy a t-shirt from Randall for the business you'll be getting that way.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Romuald</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187555</link>
    <guid isPermaLink="false">urn:md5:ecde6985783a7f444ec3847672a63a0f</guid>
    <pubDate>Tue, 20 Mar 2012 05:42:18 -0400</pubDate>
    <dc:creator>Romuald</dc:creator>
    
    <description>&lt;p&gt;@Kyhwana&lt;br /&gt;
You'll be able to push the DNSKEY record using the control panel (as we compute the DS record on our side).&lt;br /&gt;
The API isn't live yet, but it should be quite soon (since our website use it :p)&lt;/p&gt;


&lt;p&gt;Concerning the transfer, we don't import DS records automatically yet. Send a mail to support asking to import records (after the transfer is finalized), then you should be able to delete it from your control panel.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Kyhwana</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187546</link>
    <guid isPermaLink="false">urn:md5:a7ba2983a8579bb1fd2fff4219766b68</guid>
    <pubDate>Mon, 19 Mar 2012 18:03:07 -0400</pubDate>
    <dc:creator>Kyhwana</dc:creator>
    
    <description>&lt;p&gt;Hmm, is .org available yet? Am I able to push new DS keys for .org using your API/control panel?&lt;/p&gt;


&lt;p&gt;I shifted to name.com because you guys kept dragging your feet on DNSSEC, only to discover that name.com can't delete DS keys. -.-&lt;/p&gt;


&lt;p&gt;If I shift my .org domain back, will you be able to delete that DS and let me reupload a new one?&lt;/p&gt;


&lt;p&gt;Also, the .nz root domain is signed, just not any of the 2nd level domains under it, will you support .nz when those get signed?&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - jordan shoes</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187539</link>
    <guid isPermaLink="false">urn:md5:63df16c1620a6de1294d53b55b206906</guid>
    <pubDate>Sun, 18 Mar 2012 07:12:11 -0400</pubDate>
    <dc:creator>jordan shoes</dc:creator>
    
    <description>&lt;p&gt;dragging feet I started to move domains away. But after the first one went away you enabled DNSKEY options.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - DickVisser</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187535</link>
    <guid isPermaLink="false">urn:md5:c8ee737d448419c08c32645c877095b5</guid>
    <pubDate>Sat, 17 Mar 2012 14:33:13 -0400</pubDate>
    <dc:creator>DickVisser</dc:creator>
    
    <description>&lt;p&gt;After 2 years of dragging feet I started to move domains away. But after the first one went away you enabled DNSKEY options.&lt;br /&gt;
So you guys just saved yourselves a customer!&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Nicolas (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187476</link>
    <guid isPermaLink="false">urn:md5:191dd30b50c61c4ef41167bc569ba803</guid>
    <pubDate>Sat, 10 Mar 2012 17:42:00 -0400</pubDate>
    <dc:creator>Nicolas (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Dubya:we will have a look at it...it's just a question of test and adaptation of our system. If the DNSSEC implementation at the registry is quite standard, it's easy to add.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Dubya</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187474</link>
    <guid isPermaLink="false">urn:md5:b74fc8125cc295a7cee76d461012764a</guid>
    <pubDate>Sat, 10 Mar 2012 10:35:26 -0400</pubDate>
    <dc:creator>Dubya</dc:creator>
    
    <description>&lt;p&gt;.li and .in also supports DNSSEC (according to &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_Internet_top-level_domains&quot; title=&quot;https://en.wikipedia.org/wiki/List_of_Internet_top-level_domains&quot; rel=&quot;nofollow&quot;&gt;https://en.wikipedia.org/wiki/List_...&lt;/a&gt;). Why don't you offer DNSSEC on these?&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - rudivd</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187472</link>
    <guid isPermaLink="false">urn:md5:a3c30b8983fa01a1987c883f0ba8ab87</guid>
    <pubDate>Fri, 09 Mar 2012 13:59:56 -0400</pubDate>
    <dc:creator>rudivd</dc:creator>
    
    <description>&lt;p&gt;Wow, this is the best thing since the invention of the wheel I would imagine !&lt;br /&gt;
Thanks all of you at Gandi, you guys Rock !&lt;br /&gt;
Go set it up asap !&lt;/p&gt;


&lt;p&gt;Rudi&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Somebody</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187470</link>
    <guid isPermaLink="false">urn:md5:f96edf8ba6ac69494e609f5f3428d65a</guid>
    <pubDate>Fri, 09 Mar 2012 10:36:52 -0400</pubDate>
    <dc:creator>Somebody</dc:creator>
    
    <description>&lt;p&gt;Thanks for implementing this.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Nicolas (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187423</link>
    <guid isPermaLink="false">urn:md5:7f28c071291af699ac2d5cc6e123f18c</guid>
    <pubDate>Thu, 08 Mar 2012 05:27:55 -0400</pubDate>
    <dc:creator>Nicolas (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Rebeca: no news about .PE and DNSSEC, I will contact the registry about it&lt;br /&gt;
Evaryont: it won't be included in our next reelease for sure, we target it for the following (end of march/beg of April)&lt;br /&gt;
Treyka: Thxs, I made a request to ICANN about it &lt;img src=&quot;/themes/default/smilies/smile.png&quot; alt=&quot;:)&quot; class=&quot;smiley&quot; /&gt;&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - treyka</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187416</link>
    <guid isPermaLink="false">urn:md5:c21c708972a1a2cf5dffe44933e3e6e6</guid>
    <pubDate>Thu, 08 Mar 2012 01:31:38 -0400</pubDate>
    <dc:creator>treyka</dc:creator>
    
    <description>&lt;p&gt;Yes! Thanks for implementing this! Took a while but good job, y'all! &lt;img src=&quot;/themes/default/smilies/laugh.png&quot; alt=&quot;:-D&quot; class=&quot;smiley&quot; /&gt;&lt;/p&gt;


&lt;p&gt;Now you guys should see about getting the ICANN list updated: &lt;a href=&quot;http://www.icann.org/en/news/in-focus/dnssec/deployment&quot; title=&quot;http://www.icann.org/en/news/in-focus/dnssec/deployment&quot; rel=&quot;nofollow&quot;&gt;http://www.icann.org/en/news/in-foc...&lt;/a&gt;&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Evaryont</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187415</link>
    <guid isPermaLink="false">urn:md5:fd1d08c0d25b4cc0359acb4d07d06073</guid>
    <pubDate>Thu, 08 Mar 2012 00:24:29 -0400</pubDate>
    <dc:creator>Evaryont</dc:creator>
    
    <description>&lt;p&gt;Is there a time table available when the .at and .me domains will have DNSSEC available?&lt;/p&gt;


&lt;p&gt;Thanks for this!&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Rebeca</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187408</link>
    <guid isPermaLink="false">urn:md5:2365ed79f68493f58ddddd1b1652ee7c</guid>
    <pubDate>Wed, 07 Mar 2012 15:08:15 -0400</pubDate>
    <dc:creator>Rebeca</dc:creator>
    
    <description>&lt;p&gt;Do you know when the .pe domain will be compatible with DNSSEC?&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Lennie</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187396</link>
    <guid isPermaLink="false">urn:md5:eb07c62cfc5e443a9d874fd3880a5c44</guid>
    <pubDate>Wed, 07 Mar 2012 04:54:13 -0400</pubDate>
    <dc:creator>Lennie</dc:creator>
    
    <description>&lt;p&gt;Cool thanks&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Thomas</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187388</link>
    <guid isPermaLink="false">urn:md5:4fcf9f103cfd7f95538ec07a5635cd7e</guid>
    <pubDate>Tue, 06 Mar 2012 21:09:42 -0400</pubDate>
    <dc:creator>Thomas</dc:creator>
    
    <description>&lt;p&gt;Lennie,&lt;br /&gt;
Yes, we will be putting the DNSSEC functions we now have in the GUI under the API. That's a fairly easy thing to do, so we hope to roll it out soon.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Lennie</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187386</link>
    <guid isPermaLink="false">urn:md5:adab9e0ceeaf1315cd900c6243d6fc48</guid>
    <pubDate>Tue, 06 Mar 2012 20:58:55 -0400</pubDate>
    <dc:creator>Lennie</dc:creator>
    
    <description>&lt;p&gt;@Michael Moore Would you answer my question too ?:&lt;/p&gt;


&lt;p&gt;Will you be adding the ability to update the trust-anchors through the Gandi XML-RPC API also so it can be automated ?&lt;/p&gt;


&lt;p&gt;That should be a lot less work to add I would think.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Michael Moore (Gandi)</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187385</link>
    <guid isPermaLink="false">urn:md5:a7f8861003c5460a00ff9a12d3c684a9</guid>
    <pubDate>Tue, 06 Mar 2012 20:48:09 -0400</pubDate>
    <dc:creator>Michael Moore (Gandi)</dc:creator>
    
    <description>&lt;p&gt;Yes, it is only allowed for external nameservers and not yet for Gandi's nameservers yet. We are working on making it available on Gandi's nameservers, but that is a significant undertaking, considering the amount of domains registered with us and the large majority of them using our nameservers.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Lennie</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187359</link>
    <guid isPermaLink="false">urn:md5:6a98c02d1434d3036b816b5676b0d8d6</guid>
    <pubDate>Mon, 05 Mar 2012 20:27:24 -0400</pubDate>
    <dc:creator>Lennie</dc:creator>
    
    <description>&lt;p&gt;@plc I don't know if you understand English, but I think that means that your domains are using Gandi nameservers. You can currently only use DNSSEC with your &amp;quot;own&amp;quot; nameservers. It was also mentioned in the article.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - plc</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187346</link>
    <guid isPermaLink="false">urn:md5:25ca081c06d3df0f980ff44bb48a8b04</guid>
    <pubDate>Mon, 05 Mar 2012 04:23:53 -0400</pubDate>
    <dc:creator>plc</dc:creator>
    
    <description>&lt;p&gt;Sur mon tableau de bord, sur mon .com DNSSEC est grisé et il y a marqué en popup &amp;quot;L''utilisation de DNSSEC est actuellement impossible sur les DNS de Gandi&amp;quot;&lt;/p&gt;


&lt;p&gt;Idem sur mes .fr, .biz, .net...&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Lennie</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187327</link>
    <guid isPermaLink="false">urn:md5:edacb8200d9cc146317eb16bfa58555a</guid>
    <pubDate>Sun, 04 Mar 2012 15:47:12 -0400</pubDate>
    <dc:creator>Lennie</dc:creator>
    
    <description>&lt;p&gt;Thank you for that, very cool.&lt;/p&gt;


&lt;p&gt;Will you be adding the ability to update the trust-anchors through the Gandi XML-RPC API also so it can be automated ?&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Romuald</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187317</link>
    <guid isPermaLink="false">urn:md5:69a968cc89d5bfe563385e8e3fc89021</guid>
    <pubDate>Sun, 04 Mar 2012 05:48:06 -0400</pubDate>
    <dc:creator>Romuald</dc:creator>
    
    <description>&lt;p&gt;@Stéphane&lt;br /&gt;
We've passed the .org registry certification last friday, so it should be available this week on your control panel.&lt;/p&gt;</description>
  </item>
      
    
    <item>
    <title>DNSSEC at Gandi (UPDATED) - Stéphane Graber</title>
    <link>http://www.gandibar.net/post/2012/03/02/DNSSEC-at-Gandi#c187316</link>
    <guid isPermaLink="false">urn:md5:1bd3741d23b664a3592b2a7078cfbd7a</guid>
    <pubDate>Sat, 03 Mar 2012 21:45:21 -0400</pubDate>
    <dc:creator>Stéphane Graber</dc:creator>
    
    <description>&lt;p&gt;Thanks for finally implementing this!&lt;/p&gt;


&lt;p&gt;Now I guess I just need to wait for .org to appear on the list (mine is currently signed and published in the DLV as a workaround ...).&lt;/p&gt;</description>
  </item>
      
</channel>
</rss>