Pages
follow
/pages/index.html
Archives
follow
/archive/
@jpmens
follow
https://twitter.com/jpmens
About
follow
/pages/about/
Support
follow
https://liberapay.com/jpmens/donate
Vanity DNSSEC key tags
follow
/2021/10/11/vanity-dnssec-key-tags/
generating vanity DNSSEC key tags
follow
https://shaunc.com/blog/article/generating-vanity-dnssec-key-tags~NvTJKAhLogni
@Shaft
follow
https://mamot.fr/@Shaft
11 Oct 2021
follow
/2021/10/11/vanity-dnssec-key-tags/
e-mail
follow
mailto:?X-site=jpmens.net&subject=Vanity DNSSEC key tags&body=You%20might%20like%20this:%20https://jpmens.net/2021/10/11/vanity-dnssec-key-tags/
DNSSEC provisioning automation with CDS/CDNSKEY in the real world
follow
/2021/10/05/dnssec-cds-cdnskey-in-the-real-world/
RFC7344
follow
https://datatracker.ietf.org/doc/html/rfc7344
worked with CDS/CDNSKEY
follow
/2017/09/21/parents-children-cds-cdnskey-records-and-dnssec-cds/
SWITCH
follow
https://www.switch.ch
Michael
follow
https://twitter.com/mhausding
Daniel
follow
https://twitter.com/seckle_ch
Oli
follow
https://twitter.com/mailerda3mon
SWITCH
follow
https://www.switch.ch
guidelines for CDS processing at SWITCH
follow
https://www.nic.ch/export/shared/.content/files/SWITCH_CDS_Manual_en.pdf
idea a user suggested
follow
https://gitlab.isc.org/isc-projects/bind9/-/issues/1748
BIND
follow
https://www.isc.org/bind/
well-known precedent
follow
https://gist.github.com/jpmens/ca82a5c40347ceee7a7bc1eaae7d9002
BIND
follow
https://www.isc.org/bind/
status of CDS publication
follow
https://www.nic.ch/security/cds/
Oli
follow
https://twitter.com/mailerda3mon
CDS automation with Knot-DNS
follow
/2019/11/13/an-authoritative-knot/
have to wait
follow
https://gist.github.com/jpmens/ecca186e0704ce8d814feaad1493dc5e
DS to actually show up
follow
https://gist.github.com/jpmens/9141b6a1de88af4faf15865823ae446d
both our DS records in the parent
follow
https://gist.github.com/jpmens/88b87c3d3ca4f0ebb14dd2193ba72c15
SWITCH
follow
https://www.switch.ch
RFC8078
follow
https://datatracker.ietf.org/doc/html/rfc8078
SWITCH’ Guidelines
follow
https://www.nic.ch/export/shared/.content/files/SWITCH_CDS_Manual_en.pdf
signed Delete CDS in the zone
follow
https://gist.github.com/jpmens/2d0b8eaddbd3ce39bb736d22de846a12
I’ve had the time to reflect what went wrong
follow
https://gitlab.isc.org/isc-projects/bind9/-/issues/2931
Knot
follow
https://www.knot-dns.cz
BIND
follow
https://www.isc.org/bind/
SWITCH
follow
https://www.switch.ch
RFC8078
follow
https://datatracker.ietf.org/doc/html/rfc8078
RFC8078
follow
https://datatracker.ietf.org/doc/html/rfc8078
DNSSEC Bootstrapping
follow
https://datatracker.ietf.org/doc/draft-thomassen-dnsop-dnssec-bootstrapping/
SWITCH
follow
https://www.switch.ch
05 Oct 2021
follow
/2021/10/05/dnssec-cds-cdnskey-in-the-real-world/
e-mail
follow
mailto:?X-site=jpmens.net&subject=DNSSEC provisioning automation with CDS/CDNSKEY in the real world&body=You%20might%20like%20this:%20https://jpmens.net/2021/10/05/dnssec-cds-cdnskey-in-the-real-world/
Specifying duration in BIND"s named.conf
follow
/2021/09/09/specifying-duration-in-bind-s-named-conf/
Michael
follow
https://twitter.com/mwlauthor
OpenDNSSEC
follow
https://www.opendnssec.org
ISO 8601
follow
https://en.wikipedia.org/wiki/ISO_8601
Evan
follow
https://twitter.com/nuthaven
single tweet
follow
https://twitter.com/nuthaven/status/1435716890798616579
it isn’t
follow
https://mastodon.gougere.fr/@bortzmeyer/106902184471184481
09 Sep 2021
follow
/2021/09/09/specifying-duration-in-bind-s-named-conf/
e-mail
follow
mailto:?X-site=jpmens.net&subject=Specifying duration in BIND"s named.conf&body=You%20might%20like%20this:%20https://jpmens.net/2021/09/09/specifying-duration-in-bind-s-named-conf/
When and where did our vehicles stop for fuel?
follow
/2021/06/24/when-and-where-did-our-vehicles-stop-for-fuel/
OwnTracks
follow
https://owntracks.org
Christoph
follow
https://ckrey.de
OwnTracks.de
follow
https://owntracks.de
the 14000+ stations by Tankerkoenig
follow
https://creativecommons.tankerkoenig.de
OpenStreetMap
follow
https://www.openstreetmap.org/
donate
follow
https://donate.openstreetmap.org
GeoFabrik
follow
http://download.geofabrik.de
Hamburg
follow
http://download.geofabrik.de/europe/germany/hamburg.html
OpenStreetMap PBF
follow
https://wiki.openstreetmap.org/wiki/PBF_Format
how this all works
follow
https://wiki.openstreetmap.org/wiki/Elements
are many more features
follow
https://wiki.openstreetmap.org/wiki/Map_features
CDB
follow
http://www.corpit.ru/mjt/tinycdb.html
Autobahn A7 at Malsfeld, Germany
follow
https://www.openstreetmap.org/?mlat=51.087340&mlon=9.485283&zoom=18#map=18/51.08734/9.48528
osmium
follow
https://osmcode.org/osmium-tool/manual.html
OSM XML
follow
https://wiki.openstreetmap.org/wiki/OSM_XML
JSON
follow
http://json.org
OpenCageData
follow
https://opencagedata.com
CDB
follow
http://www.corpit.ru/mjt/tinycdb.html
geohash
follow
https://en.wikipedia.org/wiki/Geohash
very practical geohashes page
follow
https://www.movable-type.co.uk/scripts/geohash.html
ignition event received from Traccar
follow
/2018/09/14/position-and-event-forwarding-from-traccar/
CDB
follow
http://www.corpit.ru/mjt/tinycdb.html
follow
https://www.openstreetmap.org/?mlat=50.140319&mlon=8.449902&zoom=18#map=18/50.14032/8.44990
follow
https://www.openstreetmap.org/?mlat=50.017033&mlon=7.180631&zoom=18#map=18/50.01703/7.18063
Aire de Wasserbillig
follow
https://www.openstreetmap.org/search?query=49.728327%2C6.491032#map=16/49.7283/6.4910
enclosing way
follow
https://www.openstreetmap.org/way/522400820#map=17/49.72745/6.49058
follow
https://www.openstreetmap.org/search?query=49.728327%2C6.491032#map=16/49.7283/6.4910
MQTT
follow
http://jpmens.net/2013/02/25/lots-of-messages-mqtt-pub-sub-and-the-mosquitto-broker/
MQTT
follow
http://mqtt.org
Jeff Geerling
follow
https://www.jeffgeerling.com
Bell Slapper
follow
https://github.com/geerlingguy/pi-bell-slapper
OwnTracks.de
follow
https://owntracks.de
OpenStreetMap
follow
https://www.openstreetmap.org/
24 Jun 2021
follow
/2021/06/24/when-and-where-did-our-vehicles-stop-for-fuel/
e-mail
follow
mailto:?X-site=jpmens.net&subject=When and where did our vehicles stop for fuel?&body=You%20might%20like%20this:%20https://jpmens.net/2021/06/24/when-and-where-did-our-vehicles-stop-for-fuel/
SSH with a SmartCard-HSM and EC keys
follow
/2021/06/16/ssh-with-a-smartcard-hsm/
using a SmartCard-HSM for DNSSEC
follow
/2021/06/04/using-a-smartcard-hsm-for-dnssec-with-bind/
post by Remy van Elst
follow
https://raymii.org/s/articles/Get_Started_With_The_Nitrokey_HSM.html
CardContact SmartCard-HSM
follow
http://www.smartcard-hsm.com/
OpenSSH
follow
http://www.openssh.org/
portable OpenSSH version 8.6p1
follow
https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/
16 Jun 2021
follow
/2021/06/16/ssh-with-a-smartcard-hsm/
e-mail
follow
mailto:?X-site=jpmens.net&subject=SSH with a SmartCard-HSM and EC keys&body=You%20might%20like%20this:%20https://jpmens.net/2021/06/16/ssh-with-a-smartcard-hsm/
A diagram to depict the DNSSEC chain of trust
follow
/2021/06/09/visualizing-the-dnssec-chain-of-trust/
Using a SmartCard-HSM for DNSSEC with BIND, Knot DNS, and LDNS/NSD
follow
/2021/06/04/using-a-smartcard-hsm-for-dnssec-with-bind/
Transitioning the .CY ccTLD to DNSSEC
follow
/2021/05/27/transitioning-cy-to-dnssec/
DNS open zone data
follow
/2021/05/18/dns-open-zone-data/
An iOS app update that really annoys me
follow
/2021/05/16/an-ios-app-update-that-really-annoys-me/
Time to solve: 10800 seconds
follow
/2021/04/21/time-to-solve-10800/
Storing generic passwords in macOS" keychain
follow
/2021/04/18/storing-passwords-in-macos-keychain/
The Unix Magic poster
follow
/2021/04/09/the-unix-magic-poster/
On towels, DNS, and strncmp()
follow
/2021/03/31/towels-dns-and-strncmp/
Configure SSH ProxyCommand for Ansible AWX on Kubernetes
follow
/2021/03/25/configure-ssh-proxycommand-for-awx-on-kubernetes/
Paternoster: a CLI to invoke Ansible playbooks
follow
/2021/03/19/paternoster-a-cli-to-invoke-ansible-playbooks/
Alter Ansible"s output on debugging
follow
/2021/03/12/alter-ansible-s-output-on-debugging/
An advanced Ansible course
follow
/2021/03/08/an-advanced-ansible-course/
BIND named "grants" using external authenticator
follow
/2020/12/20/bind-named-grants-using-external-authenticator/
Look who"s rolling his keys ...
follow
/2020/12/14/look-who-s-rolling-his-keys/
Delock MQTT-enabled power socket switches
follow
/2020/11/22/delock-mqtt-enabled-power-socket-switches/
Fun with tweets and the Joplin API
follow
/2020/10/09/fun-with-tweets-and-the-joplin-api/
Airports of the world, and other data in DNS
follow
/2020/10/04/airports-of-the-world/
Using {{ ansible_managed }} in Ansible templates
follow
/2020/09/29/using-ansible-managed/
It used to be simpler to teach
follow
/2020/09/27/it-used-to-be-simpler/
Archives >
follow
/archive/