<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
>

<channel>
	<title>Cyconet Blog &#187; ripe</title>
	<atom:link href="http://blog.waja.info/tag/ripe/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.waja.info</link>
	<description>Just a place to be!</description>
	<lastBuildDate>Wed, 28 Apr 2010 08:22:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
		<item>
		<title>Is DNSSEC ready for wild life?</title>
		<link>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/</link>
		<comments>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/#comments</comments>
		<pubDate>Fri, 20 Apr 2007 19:57:11 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[ripe]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/</guid>
		<description><![CDATA[Today the RIPE DNS for LIRs Training Course did take place. (some not up to date course material can be found here) Managing some thousands of zones inclusive nameserver infrastructure behind since several years, I thought it would be neat to provide a secure dns chain to our costumers. After going deeper into the material [...]]]></description>
			<content:encoded><![CDATA[<p>Today the <a target="new" href="http://www.ripe.net/training/dns/index.html">RIPE DNS for LIRs Training Course</a> did take place. (some not up to date course material can be found <a target="new" href="http://www.ripe.net/training/dns/material/">here</a>)<br />
Managing some thousands of zones inclusive nameserver infrastructure behind since several years, I thought it would be neat to provide a secure dns chain to our costumers.<br />
After going deeper into the material within the course, I recognized the following impacts:</p>
<ul>
<li>only <a target="new" href="http://www.isc.org/sw/bind/">bind9 (>= 9.3)</a> and <a target="new" href="http://en.wikipedia.org/wiki/NSD">NSD</a> privides support (yet)</li>
<li>bandwidth will be increased 2-3 times with max. key size</li>
<li>increased memory usage depending on your server software</li>
<li>operational costs will increasing dramaticaly due significant higher amount of regular work</li>
<li>more computing power (hardware) needed to generate dnssec ready zones and signing</li>
<li>unknown influence on resolving nameservers (load/memory/bandwidth)</li>
<li><strong>chain of trust</strong> ends at resolving nameserver and <strong>is not provided to enduser</strong></li>
</ul>
<p>Since the last issue isn&#8217;t solved (yet), it doesn&#8217;t make any sence for me to invest resources into setting up DNSSec infrastructur, cause the end user would not recognize if the communication with the resolving nameserver or the resolving nameserver itself is taken over.</p>
<p>Any complaints and/or hint? Did I missed something?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>Routing Registry Training Course and irrtoolset</title>
		<link>http://blog.waja.info/2005/11/29/routing-registry-training-course-and-irrtoolset-2/</link>
		<comments>http://blog.waja.info/2005/11/29/routing-registry-training-course-and-irrtoolset-2/#comments</comments>
		<pubDate>Tue, 29 Nov 2005 22:34:32 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[ripe]]></category>
		<category><![CDATA[routing]]></category>

		<guid isPermaLink="false">http://blog.waja.info/?p=48</guid>
		<description><![CDATA[Last week I passed the course, what famouse news. ;-) It is nice to know, what is needed to write ASN-, route-, aut-num objects and so on .. to autogenerate filterconfigs in theory. In the course, I got rtconfig segfaulting on the testground server. Yes .. thats good point to start. :( This week I [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I passed the course, what famouse news. ;-)</p>
<p>It is nice to know, what is needed to write ASN-, route-, aut-num objects and so on .. to autogenerate filterconfigs in theory. In the course, I got rtconfig segfaulting on the testground server. Yes .. thats good point to start. :(</p>
<p>This week I did modify our database objects and play around with rtconfig &#8230; as result &#8230; rtconfig didnt work as aspected. Many of the filterlists arent build, cause I got many &#8220;Warning: filter matches ANY/NOT ANY&#8221;. Maybe this an effect of our aut-num object, which reflects the outbound policy depending on downstream ASN with different prependings. But I&#8217;m unable to find any hints whats the real problem.<br />
Maybe its rtconfig itself, cause I got it only running on debian/sarge with a backported package which I found <a href="ftp://ftp.logos-bg.net/debian/">there</a>. The pkgsrc-package on NetBSD core dumped. Some investigation did unearth, that the irrtoolset depends on many old libs &#8230; how bad!</p>
<p>The question which comes to my mind &#8230; is anybody out there using irrtoolset in production??</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2005/11/29/routing-registry-training-course-and-irrtoolset-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>ipv6-first-alloc request</title>
		<link>http://blog.waja.info/2005/11/18/ipv6-first-alloc-request/</link>
		<comments>http://blog.waja.info/2005/11/18/ipv6-first-alloc-request/#comments</comments>
		<pubDate>Fri, 18 Nov 2005 21:14:02 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[ripe]]></category>

		<guid isPermaLink="false">http://blog.waja.info/?p=46</guid>
		<description><![CDATA[We decided, after we will reach the next billing categorie 2007 anyways (you remember, we got /18 allocated), that it will be neat to request a /32. I created a sweet address plan and got the allocation in less than 5 hours approved. :-)]]></description>
			<content:encoded><![CDATA[<p>We decided, after we will reach the next billing categorie 2007 anyways (you remember, we got /18 allocated), that it will be neat to request a /32.<br />
I created a sweet address plan and got the allocation in less than 5 hours approved. :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2005/11/18/ipv6-first-alloc-request/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>pa-ipv4 request</title>
		<link>http://blog.waja.info/2005/11/04/pa-ipv4-request/</link>
		<comments>http://blog.waja.info/2005/11/04/pa-ipv4-request/#comments</comments>
		<pubDate>Fri, 04 Nov 2005 20:42:32 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[ripe]]></category>

		<guid isPermaLink="false">http://blog.waja.info/?p=44</guid>
		<description><![CDATA[In the last days, I did clean up our RIPE database objects and our files. The reson is &#8230; I did request new pa-ipv4 on wednesday. :-) I did fix up the 2 files, which was requested by RIPE hostmaster and I got it passed. Also my IP plans was accepted, I did request /20 [...]]]></description>
			<content:encoded><![CDATA[<p>In the last days, I did clean up our RIPE database objects and our files. The reson is &#8230; I did request new pa-ipv4 on wednesday. :-)<br />
I did fix up the 2 files, which was requested by RIPE hostmaster and I got it passed. Also my IP plans was accepted, I did request /20 and /22 for broadband.</p>
<p>The great news &#8230; we got /18 allocated. STRIKE! :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2005/11/04/pa-ipv4-request/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>LIR Training Course</title>
		<link>http://blog.waja.info/2005/10/07/lir-training-course/</link>
		<comments>http://blog.waja.info/2005/10/07/lir-training-course/#comments</comments>
		<pubDate>Fri, 07 Oct 2005 20:04:30 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Party]]></category>
		<category><![CDATA[ripe]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2005/10/07/lir-training-course/</guid>
		<description><![CDATA[Yesterday I finished the RIPE LIR Cource second time. They told us, that database objects are filtered since some weeks and with the -B you can get it unfiltered. This fact I was searching 2 weeks ago for some hours. I didnt recognise the announcement on db-wg mailinglist. My opinion is, that this is a [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I finished the RIPE LIR Cource second time.</p>
<p>They told us, that database objects are filtered since some weeks and with the -B you can get it unfiltered. This fact I was searching 2 weeks ago for some hours. I didnt recognise the announcement on db-wg mailinglist.<br />
My opinion is, that this is a useless feature. It does confuse the NOC people and spammer do know to bypass this anyways.</p>
<p>Also you cant use webupdate if your maintainer only has a pgp-key. Thats realy bad &#8230; so you need X509, if you have to use webupdate and wonna use secure authentification.<br />
To remove pgp-objects, you have to contact hostmaster@ripe.net.<br />
Other news &#8230; its allowed to make subassignments on IPv4 and new thing &#8230; lir-partitioned.</p>
<p>The benefit of the course &#8230; I&#8217;m fit into other great stuff, which may come up in the future &#8230; :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2005/10/07/lir-training-course/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->