RSSAmplifier

Blog

The posts on Kal Feher

Recent content in The posts on Kal Feher

kalfeher.comRSS feed ↗40 posts

Latest posts

Jordans IDN zone fails

Jordan's IDN zone has a long running outage

TLD DNSSec Availability Project

After a break of nearly 2 years I restart my TLD DNSSec availability project

Running Bash Scripts on AWS Lambda

A guide to running Bash scripts on AWS Lambda with example code. Instructions for uploading to AWS. Creating an IAM role and policy for your function. Defining your function via the CLI.

Build Your Own Certificate Expiry Notifications

With Lets Encrypt no longer generating Expiration Notification Emails, here's a couple of ways you can replace the service with something you can build yourself. Use AWS Free tier resources to check your certificates. Learn how to automate certificate expiration checking.

A step by step guide to setting up WireGuard

A step by step guide to setting up a WireGuard VPN and Squid proxy for personal use. Deploy and maintain your VPN with Ansible and do it as securely and simply as possible. Understand how to configure WireGuard for your needs.

Validating Certificates with Whois is Going Away

Certificates will no longer use Whois based information for Domain Control Validation

Scaling on a budget

Analysing 500 million records a day on the AWS Free tier. Things I learned while building a project I didn't want to pay for.

Finding Expiring IAMRolesAnywhere Certificates

Finding the owner of expiring certificates used for IAM Roles Anywhere.

We're rolling again

The internet root zone will start the roll over of it's Key Signing Key in 2025. What can we expect?

HTTPS DNS Record Support

The HTTPS DNS record delivers some long desired capabilities to domain owners. It has been formally adopted in RFC9460 for some time now. Can we use it? How well is it supported?

Using HTTPS DNS records

A collection of use cases to explain the behaviour of HTTPS DNS records.

IETF 119 Brisbane

IETF Brisvegas has arrived.

TLD DNS Failure Modes

A review of the TLD DNS failures I've observed during 2023 and why the same failures keep happening

A simple CA using CFSSL

Deploying a root and intermediate CA using CFSSL and Ansible

Kubernetes Self Signing and Trusting your CA

Using a Self Signed CA with K8s and updating trusted CAs on Centos

Initialising AWS With Ansible

Setting up an AWS lab with Ansible.

Simple HTTPS Records

A simple explanation on how HTTPS records work

ISC BIND, DoH and SE Linux

Allowing ISC BIND to use http ports for DoH with SE Linux

Goodby Google, Hello Matomo

I swap out Google Analytics for Matomo on Kubernetes.

Parsedmarc on Kubernetes with Opensearch

Deploy parsedmarc on K8s and ensure it works with Opensearch

AWX deployment with Ansible

Deploying the AWX Operator with Ansible

Debugging K8s nginx ingress webhook timeouts

Resolving webhook timeouts with nginx ingress

Firewalld says no to drifting

Layered zones are gone from firewalld, so what now?

Securing my site

Once again I run my site against some basic Internet security tools

Starting over with the blog

I move my old blog content over to a new domain and break stuff

Moving to Jekyl

Leaving Ghost and learning about some of Jekyll's quirks.

Unifi Controller Software with Ansible

Deploying the Unifi controller software via Ansible.

Practical TLSA

Learning about DANE and how automation makes the pain go away

What Do TLSA Numbers Mean?

Understand how to read TLSA records and what the numbers in those records signify

Centralising Certificate Management - Part 1

An introduction to the concept of centralised certificate management.

Centralising Certificate Management - Part 2

Second post in a series explaining centralised management options for ACME based certificates

Centralising Certificate Management - Part 3

Third post in a series explaining centralised management options for ACME based certificates

TLSA with Ansible

A fast way to generate TLSA records using Ansible.

Ansible Role for BIND

Using Ansible to deploy and configure ISC BIND

Session Recording using tlog

Configure session recording via configuration files only, allowing you to automate it.

RegExt at IETF103

Observations of the REGEXT meeting at IETF103

IETF 103 Bangkok

Travelling to Bangkok for IETF103

Exfil with DNS

An explanation of how DNS can be used to exfiltrate data from your network and how to stop it.

Changes to Quagga Configuration layout

Finding where all those Quagga files went.

Root Key Rollover

Revisiting the DNS Root Key rollover