Security Track: DNSSEC-related Outages @TeamNANOG
Security Track: DNSSEC-related Outages  @TeamNANOG
Uploaded February 2025 | Updated September 2026, 1 week ago
DNSSEC deployment has been underway for years, but has faced technical hurdles and operational resistance. Some suggest the technology is more trouble than it is worth, and increases DNS fragility. We have been examining active probe-driven data to evaluate and quantify DNSSEC-related outages in-the-wild. We aim to put these results in perspective. We first define what constitutes a DNSSEC-related outage. We present the current state of our findings with an overview of the evidence data we collect and analyze, along with our current, best interpretation of the results. We seek to quantify the impact of DNSSEC-related outages and compare them to outages in DNS generally as well as other cryptography-secured based systems such as the web (X.509) and routing (RPKI). This talk will give operators an evidence-based view of DNSSEC-related outages over the span of many years, helping to inform those who are reluctant or interested in furthering DNSSEC deployment.

Speaker John Kristoff - Dataplane.org / UIC
Security Track: DNSSEC-related OutagesA Decade of Intent Management in Network Automation: What We Got Right, What We MissedNANOG TriviaVersioned Services for Network AutomationNANOG Community MeetingBuilding Resilience: Taking OOB Networks to the Next LevelNANOG 95 Conference ClosingNANOG 93 Conference OpeningLightning Talk: Seeing Through the RDMA Fog: Monitoring RoCEv2 with sFlowTriggering QUICLightning Talk: GraphQL for Network and Security EngineersEnterprise Cellular: Improving in-building Mobile Cellular using CBRS Neutral Host Networks
NANOG |

Security Track: DNSSEC-related Outages

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER