Internet Assigned Numbers Authority
Internet Assigned Numbers Authority
  • 23
  • 81 263
Root KSK Ceremony 54
www.iana.org/dnssec/ceremonies/54
มุมมอง: 376

วีดีโอ

Root KSK Ceremony 53: Day 2Root KSK Ceremony 53: Day 2
Root KSK Ceremony 53: Day 2
มุมมอง 1.2K3 หลายเดือนก่อน
www.iana.org/dnssec/ceremonies/53-2
Root KSK Ceremony 53: Day 1Root KSK Ceremony 53: Day 1
Root KSK Ceremony 53: Day 1
มุมมอง 8713 หลายเดือนก่อน
www.iana.org/dnssec/ceremonies/53-1
Root KSK Ceremony 52Root KSK Ceremony 52
Root KSK Ceremony 52
มุมมอง 1.5K5 หลายเดือนก่อน
www.iana.org/dnssec/ceremonies/52
Root KSK Ceremony 51Root KSK Ceremony 51
Root KSK Ceremony 51
มุมมอง 3.8K8 หลายเดือนก่อน
www.iana.org/dnssec/ceremonies/51
Root KSK Ceremony 50Root KSK Ceremony 50
Root KSK Ceremony 50
มุมมอง 2.3Kปีที่แล้ว
www.iana.org/dnssec/ceremonies/50
Root KSK Ceremony 49Root KSK Ceremony 49
Root KSK Ceremony 49
มุมมอง 3.3Kปีที่แล้ว
www.iana.org/dnssec/ceremonies/49
Root KSK Ceremony 48Root KSK Ceremony 48
Root KSK Ceremony 48
มุมมอง 1.6Kปีที่แล้ว
www.iana.org/dnssec/ceremonies/48
Root KSK Ceremony 47Root KSK Ceremony 47
Root KSK Ceremony 47
มุมมอง 15Kปีที่แล้ว
www.iana.org/dnssec/ceremonies/47
Root KSK Ceremony 46Root KSK Ceremony 46
Root KSK Ceremony 46
มุมมอง 1.7Kปีที่แล้ว
www.iana.org/dnssec/ceremonies/46
Root KSK Ceremony 45Root KSK Ceremony 45
Root KSK Ceremony 45
มุมมอง 4.8K2 ปีที่แล้ว
www.iana.org/dnssec/ceremonies/45
Root KSK Ceremony 44Root KSK Ceremony 44
Root KSK Ceremony 44
มุมมอง 1.3K2 ปีที่แล้ว
www.iana.org/dnssec/ceremonies/44
Root KSK Ceremony 43Root KSK Ceremony 43
Root KSK Ceremony 43
มุมมอง 2.9K2 ปีที่แล้ว
www.iana.org/dnssec/ceremonies/43
Root KSK Ceremony 42Root KSK Ceremony 42
Root KSK Ceremony 42
มุมมอง 3.9K3 ปีที่แล้ว
www.iana.org/dnssec/ceremonies/42

ความคิดเห็น

  • @bvd0
    @bvd0 17 วันที่ผ่านมา

    The fact that these are live-streamed is so cool! The amount of transparency is impressive.

  • @eqfira
    @eqfira 2 หลายเดือนก่อน

    The people who are involved in this live very great i think by looking how they are doing it

  • @RamiSIK-zq4cx
    @RamiSIK-zq4cx 3 หลายเดือนก่อน

    Step 1.4, if alarms sounds, just leave. Isn't it a vulnerability by itslef in this process?

    • @andrespavez2861
      @andrespavez2861 3 หลายเดือนก่อน

      That is in case of an emergency. If the room needs to be evacuated in case of an emergency, you can open the door from inside without using a badge and pin. In that case, the sound alarm will be activated.

    • @iana-org
      @iana-org 2 หลายเดือนก่อน

      It's also basic code for buildings. One has to be able to exit any building in an emergency situation.

    • @RamiSIK-zq4cx
      @RamiSIK-zq4cx 2 หลายเดือนก่อน

      I understand the reasoning but was wondering if this has been part of the threat model to see if there is enough mitigating controls for protecting the sensitive material already accessible as part of this process when people leaves upon hearing the alarm. For example, in case of a fake alarm, you may have both safe boxes open and only protection may be the room door which is protected only by badge, which would completely invalidate the reason why you have safe boxes in there. Even, I would ask if the badge protected door is also fail-safe from outside in case of such a building alarm.

    • @iana-org
      @iana-org 2 หลายเดือนก่อน

      ​@@RamiSIK-zq4cx Firstly, there's only ever one safe open at a time. If an alarm sounded while either of these safes were open, it would be a simple matter to close and lock the safe before exiting the safe room. One would have to get past two other doors with progressively tighter requirements to gain entry to this third door to the safe room. Secondly, the access control system authorizing the badges of these doors operates independently of the safe, unless the safe door is open, in which all badge swipes are disabled until the safe door is closed again. If you check the ceremony scripts, it asks the CA to verify the "wait" light is off once the door is closed. That is the reason. They would not be able to badge out of the room unless sensor of the safe door is closed. Finally, independent of all that, there are two separate surveillance systems monitoring the room 24/7/365. Many overlapping controls would need to be defeated in order to access the room without authorization, and to access the room without triggering any alerts is extremely unlikely.

  • @MovingThePicture
    @MovingThePicture 3 หลายเดือนก่อน

    When is the next actual KSK change to happen? (Not the ZSK)

    • @andrespavez2861
      @andrespavez2861 3 หลายเดือนก่อน

      The KSK rollover is tentatively scheduled for October 11, 2026.

  • @Eluyaa
    @Eluyaa 5 หลายเดือนก่อน

    DNSSEC has a single point of failure in the US Government, as all ceremonies happen on US Soil. Please fix.

    • @thelittleerik4806
      @thelittleerik4806 4 หลายเดือนก่อน

      This has been an issue that's becoming more and more relevant as over time the geopolitical climate is taking a new shape. I suggest the United Nations building in Geneva, Switzerland to be the new designated headquarters.

  • @DaffyDaffyDaffy33322
    @DaffyDaffyDaffy33322 5 หลายเดือนก่อน

    I noticed the camera angle is different from the last ceremony. Is there footage of someone entering tier 5 to adjust the camera, or did that happen off camera?

    • @iana-org
      @iana-org 5 หลายเดือนก่อน

      Routine maintenance occurs in the key management facilities between ceremonies. The audit cameras themselves were replaced with new units a week prior, which would explain the slightly different camera angle. These cameras also use dual recording to local SD cards which are sealed and retained for audit purposes, and physically removing and installing SD cards can also inadvertently adjust the camera. We do not post footage every time we enter these facilities, however any activity that require opening either safe is scripted, recorded, and at minimum posted on the IANA ceremonies webpage and may be live streamed as well.

    • @DaffyDaffyDaffy33322
      @DaffyDaffyDaffy33322 5 หลายเดือนก่อน

      @@iana-org Makes sense, thanks for the reply!

  • @kirill.borisov
    @kirill.borisov 6 หลายเดือนก่อน

    "В очередной церемонии подписания ключей Root KSK Ceremony приняли участие Фантомас, Доктор Кто и Мистик".

  • @danielap5672
    @danielap5672 6 หลายเดือนก่อน

    Out of curiosity, could you share who your videographer/AV person is? I'd love to hire them for a key ceremony we're planning in CA in the next few months

    • @iana-org
      @iana-org 6 หลายเดือนก่อน

      Hello. We have our cameras and streaming equipment permanently installed in the key management facility. Maintenance and operations are documented and performed by the RKOS staff. We are happy to share information if you are interested in our setup.

  • @alexalper2022
    @alexalper2022 7 หลายเดือนก่อน

    4:11:46 exactly the kind of reference i'd expect :)

  • @MrMcCoolCloud
    @MrMcCoolCloud 8 หลายเดือนก่อน

    this is the nerdiest thing I've ever seen. Respect for maximum transparency

  • @SarahC2
    @SarahC2 8 หลายเดือนก่อน

    I concur!

  • @susanbrockway5636
    @susanbrockway5636 8 หลายเดือนก่อน

    Deberían de recibir un mejor reconocimiento ustedes sostienen internet 😺

  • @susanbrockway5636
    @susanbrockway5636 8 หลายเดือนก่อน

    Nice work guys 😊

  • @movax20h
    @movax20h 10 หลายเดือนก่อน

    At 1:13:10 during OP2 or OP3 audit. Serial communication is corrupted, few characters are missing. Fortunately not critical (the internal clock is not correct anyway). Please use better and shorter cable tho. This caused issues at 2:03:00, in few places. Including Serial Number readout. The staff incorrectly say this is a bug in a firmware, where in fact it is a fault of a cable.

    • @iana-org
      @iana-org 8 หลายเดือนก่อน

      After the ceremony, thorough testing took place where we were able to reproduce the issue with a different HSM of the same exact variety, and our initial assumption that it had to do with the HSM firmware ended up being completely wrong, but it's also not a cable issue. Further testing with our testing laptop and HSM allowed us to isolate the issue to the updated version of STTY’s translation of the RS232 controller. We consistently receive a random 1-2% error rate in the captured HSM output. Testing suggests the previous version of STTY included with the former version of COEN (our ceremony operating system) was performing error correction more optimally with our former hardware combination. Multiple USB to serial port adapters utilizing the STDI chipset were tested to circumvent the laptop’s onboard RS232 controller and serial port. We ran several diff comparisons of the captured output with consistent results, showing only anticipated character changes such as the HSM reset count and timestamps. We plan to return to using USB to serial port adapters in future KSK ceremonies. USB to serial port adapters were used with the previous generations of ceremony laptops in KSK ceremonies from 2010-2018 without issue. Hope this clears things up.

    • @movax20h
      @movax20h 8 หลายเดือนก่อน

      @@iana-org Hi IANA. Thanks for the response. That makes sense, serial could be finicky. It is weird that the built in serial was not cooperating. Maybe some flow control lines were not handled correctly, or driver has issues, all possible. Thanks for testing, and finding a hopefully secure workaround.

    • @iana-org
      @iana-org 8 หลายเดือนก่อน

      @@movax20h It really appears to just be the way the RS232 controller built into the laptop for that built-in serial port was doing the translation with the new version of STTY. It was a pretty deep dive down the rabbit hole to make that determination. At KSK Ceremony 50 we successfully used the USB to serial adapter combined with the same version of STTY without any issues, so we don't anticipate any issues of this variety to arise again.

  • @movax20h
    @movax20h 10 หลายเดือนก่อน

    How does doing "head -c ...." check on SD card at 49:05, verify that the bootloader and root is correct? That does not feel right to me. EDIT: My bad. This is correct, and actually necassary, due to SD card (sda) being bigger in total than the content on relevant partitions or the CD. "head -c ...." does verify the bootloader, partition tables and their content. All good.

  • @shubham_srt
    @shubham_srt 10 หลายเดือนก่อน

    this is sooo cool . Thank you ICANN for what you do, and thank you MKBHD team

  • @shubham_srt
    @shubham_srt 10 หลายเดือนก่อน

    This is so facinating. Thank You <3

  • @danboy12342
    @danboy12342 ปีที่แล้ว

    Still the most transparent organisation on earth

  • @martinligabue
    @martinligabue ปีที่แล้ว

    thanks for what you do

  • @rescdsk
    @rescdsk ปีที่แล้ว

    Peep the live chat replay

  • @nick_yt23
    @nick_yt23 ปีที่แล้ว

    What the final key encryption is used for, what exactly does it encrypt?

  • @abraad9041
    @abraad9041 ปีที่แล้ว

    banger

  • @fazeedkotta2580
    @fazeedkotta2580 ปีที่แล้ว

    Big up

  • @RaptieFeathers
    @RaptieFeathers ปีที่แล้ว

    This is amazing as ASMR

  • @Gloomy_Sunday_RIP
    @Gloomy_Sunday_RIP ปีที่แล้ว

    感觉很严谨的样子!

    • @TheFunnyDictator
      @TheFunnyDictator ปีที่แล้ว

      Hey, what language is that?!

    • @amytf1
      @amytf1 ปีที่แล้ว

      @@TheFunnyDictator unicode

  • @l0wr4n
    @l0wr4n ปีที่แล้ว

    What an honor and privilege to handle such a task.

  • @Andrei5656
    @Andrei5656 ปีที่แล้ว

    Fantastic, thanks for letting the MKBHD guys be your guests. The podcast they put together was great and I learned a lot about what you do and how all this works. Thank you.

  • @ReflinWulf
    @ReflinWulf ปีที่แล้ว

    what happens someone die ?

  • @thedislikebutton163
    @thedislikebutton163 ปีที่แล้ว

    We own . pizza FTW

  • @salmiakki5638
    @salmiakki5638 ปีที่แล้ว

    Is that an Built for purpose application specific OS?

  • @salmiakki5638
    @salmiakki5638 ปีที่แล้ว

    Can someone explain to me how they can update the Digital certificates of the DNS zone servers if the machine they do it on is air gapped? At which step the new certificates are actually deployed?

    • @kijeda
      @kijeda ปีที่แล้ว

      The cryptographic signatures generated during the ceremony are exported on a USB flash drive (the "HSMFD" in the script) and taken out of the facility at the end of the ceremony. Then during the daily production of the root zone they are inserted as part of the zone signing process.

    • @salmiakki5638
      @salmiakki5638 ปีที่แล้ว

      @@kijeda thank you so much!

  • @max_ishere
    @max_ishere ปีที่แล้ว

    This must be the most boring job ever

  • @max_ishere
    @max_ishere ปีที่แล้ว

    59:18 of course it's Ohio, what else could it be

  • @max_ishere
    @max_ishere ปีที่แล้ว

    It's Debian, fuuuck

  • @PieFlavouredPii
    @PieFlavouredPii ปีที่แล้ว

    Thanks for all the work you do IANA!!

  • @kaguraschimizu4609
    @kaguraschimizu4609 ปีที่แล้ว

    mkbHD baby❤

  • @zptaco
    @zptaco ปีที่แล้ว

    Waveform Podcast brought me here! Shoutout to David and the team

  • @wilyamiyoo
    @wilyamiyoo ปีที่แล้ว

    Gentleman at 8:08: Smash that like button. We have indeed, kind sir. ICANN, thank you for all that you do.

  • @mrmacneil
    @mrmacneil ปีที่แล้ว

    WAVEFORM/MKBHD sent me here. Super cool.

  • @tramcrazy
    @tramcrazy ปีที่แล้ว

    I want this job. It looks so fun!

  • @kirkydaturkey
    @kirkydaturkey ปีที่แล้ว

    7:53 “last but not least DAVID” 🙌😤🌋

  • @aryankathawale9269
    @aryankathawale9269 ปีที่แล้ว

    okay this makes me happy , a safe internet

  • @sameerasw
    @sameerasw ปีที่แล้ว

    I'm glad I learned about this! Thanks WVFRM team <3

    • @ravifleming
      @ravifleming ปีที่แล้ว

      You are Sri Lankan right?

    • @sameerasw
      @sameerasw ปีที่แล้ว

      @@ravifleming Yes! Was also happy to see a Sri Lankan in the session by random :)

  • @Clavinohou
    @Clavinohou ปีที่แล้ว

    this is everything i could want from an ICANN key signing ceremony

  • @octogintillion
    @octogintillion ปีที่แล้ว

    8:07 Subscribe to MKBHD! :)

  • @darkwise8628
    @darkwise8628 ปีที่แล้ว

    for anyone intrested, the MKBHD crew introduces itself at 7:21!

    • @Leanzazzy
      @Leanzazzy ปีที่แล้ว

      Interactive music by Vayne Sil starts playing

    • @Dheal
      @Dheal ปีที่แล้ว

      @@Leanzazzy 20 Syl ( It's a french artist)

  • @meettheguest
    @meettheguest ปีที่แล้ว

    MKBHD ❤️

  • @TRUEbASNER
    @TRUEbASNER ปีที่แล้ว

    For channel regulars wondering why this particular video is blowing up, look no further than the MKBHD guys😅

    • @aslt5711
      @aslt5711 10 หลายเดือนก่อน

      You got the link to the video ? I want to see it :)

    • @josephtaiwo7797
      @josephtaiwo7797 8 หลายเดือนก่อน

      On the Dec 1st 2023 episode, Their Spotify wrapped said this was their most viewed episode. Went to play ICANN and the 7 keys of the internet, and they talked about this. So I came down to TH-cam lol

    • @DKoldies_CEO_Drew_Scumbag
      @DKoldies_CEO_Drew_Scumbag 2 หลายเดือนก่อน

      Fuck whoever those people are because I found this with a search

  • @abhiagrawal9
    @abhiagrawal9 ปีที่แล้ว

    Shoutout to waveform podcast 🤣

  • @billybutcher69420
    @billybutcher69420 ปีที่แล้ว

    David is insanely cool