Jordans IDN zone fails
Jordan's IDN zone has a long running outage
Recent content in The posts on Kal Feher
Jordan's IDN zone has a long running outage
After a break of nearly 2 years I restart my TLD DNSSec availability project
A guide to running Bash scripts on AWS Lambda with example code. Instructions for uploading to AWS. Creating an IAM role and policy for your function. Defining your function via the CLI.
With Lets Encrypt no longer generating Expiration Notification Emails, here's a couple of ways you can replace the service with something you can build yourself. Use AWS Free tier resources to check your certificates. Learn how to automate certificate expiration checking.
A step by step guide to setting up a WireGuard VPN and Squid proxy for personal use. Deploy and maintain your VPN with Ansible and do it as securely and simply as possible. Understand how to configure WireGuard for your needs.
Certificates will no longer use Whois based information for Domain Control Validation
Analysing 500 million records a day on the AWS Free tier. Things I learned while building a project I didn't want to pay for.
Finding the owner of expiring certificates used for IAM Roles Anywhere.
The internet root zone will start the roll over of it's Key Signing Key in 2025. What can we expect?
The HTTPS DNS record delivers some long desired capabilities to domain owners. It has been formally adopted in RFC9460 for some time now. Can we use it? How well is it supported?
A collection of use cases to explain the behaviour of HTTPS DNS records.
IETF Brisvegas has arrived.
A review of the TLD DNS failures I've observed during 2023 and why the same failures keep happening
Deploying a root and intermediate CA using CFSSL and Ansible
Using a Self Signed CA with K8s and updating trusted CAs on Centos
Setting up an AWS lab with Ansible.
A simple explanation on how HTTPS records work
Allowing ISC BIND to use http ports for DoH with SE Linux
I swap out Google Analytics for Matomo on Kubernetes.
Deploy parsedmarc on K8s and ensure it works with Opensearch
Deploying the AWX Operator with Ansible
Resolving webhook timeouts with nginx ingress
Layered zones are gone from firewalld, so what now?
Once again I run my site against some basic Internet security tools
I move my old blog content over to a new domain and break stuff
Leaving Ghost and learning about some of Jekyll's quirks.
Deploying the Unifi controller software via Ansible.
Learning about DANE and how automation makes the pain go away
Understand how to read TLSA records and what the numbers in those records signify
An introduction to the concept of centralised certificate management.
Second post in a series explaining centralised management options for ACME based certificates
Third post in a series explaining centralised management options for ACME based certificates
A fast way to generate TLSA records using Ansible.
Using Ansible to deploy and configure ISC BIND
Configure session recording via configuration files only, allowing you to automate it.
Observations of the REGEXT meeting at IETF103
Travelling to Bangkok for IETF103
An explanation of how DNS can be used to exfiltrate data from your network and how to stop it.
Finding where all those Quagga files went.
Revisiting the DNS Root Key rollover