<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNSSEC does not work on Production Resolvers in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190179#M16891</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Enabling DNSSEC in the Router ensures the validation over the "last mile".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;“Enabling DNSEC in the router GUI ensures DNSSEC validation over the ‘last mile’, ie, between the DNS server &amp;amp; you.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;So, Cloudflare (or Google, or Quad9) does DNSSEC=yes: enabling locally means you are verifying locally what you get from Cloudflare (or Google, Quad9) as being still ok, not tampered with, when it gets to you. (&lt;A href="https://www.snbforums.com/threads/release-asuswrt-merlin-384-11-is-available.56501/page-3#post-488647" target="_blank" rel="nofollow noreferrer"&gt;found here&lt;/A&gt;)“&lt;BR /&gt;&lt;BR /&gt;“While DNSSEC ensures integrity of data between a resolver and an authoritative server, it does not protect the privacy of the “last mile” towards you. DNS resolver, 1.1.1.1, supports both emerging DNS privacy standards - DNS-over-TLS, and DNS-over-HTTPS, which both provide last mile encryption to keep your DNS queries private and free from tampering. (&lt;A href="https://blog.cloudflare.com/dns-resolver-1-1-1-1/" target="_blank" rel="nofollow noreferrer"&gt;found here&lt;/A&gt;)”&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 07 Mar 2020 13:41:50 GMT</pubDate>
    <dc:creator>pavlicekdevid</dc:creator>
    <dc:date>2020-03-07T13:41:50Z</dc:date>
    <item>
      <title>DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190173#M16885</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;OpenDNS announced that it will start supporting the DNSSEC protocol on 24.02.2020 for production resolvers (&lt;A href="https://community.cisco.com/hc/en-us/articles/360039659971" target="_blank" rel="nofollow noreferrer"&gt;DNSSEC General Availability&lt;/A&gt;). I am using the DNS resolvers 208.67.222.222 and 208.67.220.220.&lt;BR /&gt;&lt;BR /&gt;But when I enable the DNSSEC support in my router settings (Asus RT-AC88U) I can't reach any websites. So my question is is it already supported ? Does anyone else use DNSSEC with production resolvers ?&lt;/P&gt;
&lt;P&gt;These are the settings on my Router. When I enable "Validate unsigned DNSSEC replies" I can't reach any website anymore.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="support.opendns.com_hc_user_images_GJqSDTVTBTAS__GdzRc7Ug.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228034i1373F17FCA993BC1/image-size/large?v=v2&amp;amp;px=999" role="button" title="support.opendns.com_hc_user_images_GJqSDTVTBTAS__GdzRc7Ug.png" alt="support.opendns.com_hc_user_images_GJqSDTVTBTAS__GdzRc7Ug.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Feb 2020 19:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190173#M16885</guid>
      <dc:creator>pavlicekdevid</dc:creator>
      <dc:date>2020-02-28T19:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190174#M16886</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;It seems your router attempts to validate all replies, not just unsigned DNSSEC replies.&lt;/P&gt;

&lt;P&gt;You need to understand what DNSSEC is.
&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions" rel="nofollow noreferrer"&gt;https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You should not need to change any settings.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Feb 2020 20:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190174#M16886</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-02-28T20:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190175#M16887</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hi&amp;nbsp;&lt;X-ZENDESK-USER data-user-name="rotblitz"&gt;309368103&lt;/X-ZENDESK-USER&gt;, but why does "Sandbox" and "FamilyShield" work when enabling the setting "Validate unsigned DNSSEC replies" ?&lt;/P&gt;
&lt;P&gt;Also for DNSSEC to work I thought that both Server and Client site have to enable it. &lt;A href="https://ititch.com/dnssec-what-you-need-to-know/" target="_blank" rel="nofollow noreferrer"&gt;https://ititch.com/dnssec-what-you-need-to-know/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Feb 2020 21:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190175#M16887</guid>
      <dc:creator>pavlicekdevid</dc:creator>
      <dc:date>2020-02-28T21:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190176#M16888</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I don’t know why it sometimes works. I do not know your router.&lt;/P&gt;
&lt;P&gt;And yes, client is OpenDNS, and server is the authoritative nameserver of the DNSSEC enabled domain. As you can see, you are out of the game.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 29 Feb 2020 12:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190176#M16888</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-02-29T12:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190177#M16889</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;X-ZENDESK-USER data-user-name="rotblitz"&gt;309368103&lt;/X-ZENDESK-USER&gt; It seems more as a bug to me. With the option "Validate unsigned DNSSEC replies" enabled on my Router (Asus RT-AC88U) it is &lt;STRONG&gt;only not working&lt;/STRONG&gt; on the Production resolvers (208.67.222.222, 208.67.220.220).&lt;/P&gt;
&lt;P&gt;As i suspected it is a issue on the OpenDNS side, as &lt;A href="https://community.cisco.com/hc/en-us/articles/360039659971" target="_blank" rel="nofollow noreferrer"&gt;they changed now the date&lt;/A&gt; for the Production resolvers to March 10, 2020. Before it was February 24, 2020.&amp;nbsp; You can check this &lt;A href="https://www.snbforums.com/threads/enable-dnssec-with-opendns.62404/#post-558081" target="_blank" rel="nofollow noreferrer"&gt;forum post&lt;/A&gt; also.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 07 Mar 2020 10:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190177#M16889</guid>
      <dc:creator>pavlicekdevid</dc:creator>
      <dc:date>2020-03-07T10:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190178#M16890</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Ok, this may be the reason for not working. &amp;nbsp;I still do not understand what your router has to do with it though. &amp;nbsp;The routers I know do not have such settings.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 07 Mar 2020 13:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190178#M16890</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-03-07T13:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190179#M16891</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Enabling DNSSEC in the Router ensures the validation over the "last mile".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;“Enabling DNSEC in the router GUI ensures DNSSEC validation over the ‘last mile’, ie, between the DNS server &amp;amp; you.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;So, Cloudflare (or Google, or Quad9) does DNSSEC=yes: enabling locally means you are verifying locally what you get from Cloudflare (or Google, Quad9) as being still ok, not tampered with, when it gets to you. (&lt;A href="https://www.snbforums.com/threads/release-asuswrt-merlin-384-11-is-available.56501/page-3#post-488647" target="_blank" rel="nofollow noreferrer"&gt;found here&lt;/A&gt;)“&lt;BR /&gt;&lt;BR /&gt;“While DNSSEC ensures integrity of data between a resolver and an authoritative server, it does not protect the privacy of the “last mile” towards you. DNS resolver, 1.1.1.1, supports both emerging DNS privacy standards - DNS-over-TLS, and DNS-over-HTTPS, which both provide last mile encryption to keep your DNS queries private and free from tampering. (&lt;A href="https://blog.cloudflare.com/dns-resolver-1-1-1-1/" target="_blank" rel="nofollow noreferrer"&gt;found here&lt;/A&gt;)”&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 07 Mar 2020 13:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190179#M16891</guid>
      <dc:creator>pavlicekdevid</dc:creator>
      <dc:date>2020-03-07T13:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190180#M16892</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I see now. Thanks.  It looks like my router does this automatically.  Even better.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 07 Mar 2020 14:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190180#M16892</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-03-07T14:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNSSEC does not work on Production Resolvers</title>
      <link>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190181#M16893</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;For anyone who is reading this and is also interested to implement DNSSEC to the "last mile" I am reporting that this now works perfectly on the production resolvers too.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Mar 2020 10:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dnssec-does-not-work-on-production-resolvers/m-p/5190181#M16893</guid>
      <dc:creator>pavlicekdevid</dc:creator>
      <dc:date>2020-03-11T10:42:26Z</dc:date>
    </item>
  </channel>
</rss>

