From francisco at arias.com.mx Tue Jun 2 15:16:10 2009 From: francisco at arias.com.mx (Francisco Arias) Date: Tue, 2 Jun 2009 13:16:10 -0500 Subject: [lacnog] Fwd: .ORG is signed In-Reply-To: References: Message-ID: ---------- Forwarded message ---------- From: Ram Mohan Date: 2009/6/2 Subject: [dnssec-deployment] .ORG is signed To: DNSSEC deployment Cc: SSAC , Ram Mohan , Alexa Raad Folks, We?re glad to report that .ORG is DNSSEC signed, the largest TLD to be signed to date.? Thank you for staying involved, interested and in assisting us at Team ORG on getting to this significant milestone. Next up, big tasks include getting as many of the 7.7 million registrations to be signed, working closely with registrars, network operators, registrants and other key parts of the domain name eco-system. -Ram & Alexa Raad -------------------------------------------------------------------------- Alexa Raad CEO, PIR (http://www.pir.org) araad at pir.org Ram Mohan EVP & CTO, Afilias (http://www.afilias.info) rmohan at afilias.info -------------------------------------------------------------------------- ; <<>> DiG 9.4.2-P1 <<>> @validator soa org +dnssec ; (1 server found) ;; global options:? printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4489 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 4096 ;; QUESTION SECTION: ;org.?????????????????? IN??? SOA ;; ANSWER SECTION: org.??????? ????? 0???? IN??? SOA?? a0.org.afilias-nst.info. noc.afilias-nst.info. 2008678353 1800 900 604800 86400 org.????????????? 0???? IN??? RRSIG SOA 7 1 0 20090616152549 20090602142549 37493 org. IIfN8RIyFvsfM8bxFwtt+FJkqQk5dHtMPlrW4cWBYNMvOo8+FEMcqFni eAThKdQXU +0aMAr+HOKNB4HK67aq5IxoYmCB8RyBt/Fsh5i4MGgejMgX 42nonWPPqkBYAZkJh4d/ GWwEJANcr8XRyr4YpTaNfEZiFQAqj8lhDmFV 69M= ;; Query time: 52 msec ;; SERVER: 199.19.49.119#53(199.19.49.119) ;; WHEN: Tue Jun? 2 15:26:29 2009 ;; MSG SIZE? rcvd: 258 From francisco at arias.com.mx Thu Jun 4 11:49:42 2009 From: francisco at arias.com.mx (Francisco Arias) Date: Thu, 4 Jun 2009 09:49:42 -0500 Subject: [lacnog] Fwd: Root Signing announcement In-Reply-To: References: Message-ID: ---------- Forwarded message ---------- From: Steve Crocker Date: 2009/6/3 Subject: [dnssec-deployment] Root Signing announcement To: DNSSEC deployment Cc: Steve Crocker Both ICANN and NIST are displaying a press release that the U.S. Dept of Commerce, ICANN and VeriSign have agreed to work together to get the root signed by the end of the year. Here are the URLs for the ICANN and NIST press releases. http://www.icann.org/en/announcements/announcement-2-03jun09-en.htm http://www.nist.gov/public_affairs/releases/dnssec_060309.html The text of the NIST press release is copied below. Steve Commerce Department to Work with ICANN and VeriSign to Enhance the Security and Stability of the Internet?s Domain Name and Addressing System FOR IMMEDIATE RELEASE: June 3, 2009 WASHINGTON ?The U.S. Department of Commerce's National Telecommunications and Information Administration (NTIA) and National Institute of Standards and Technology (NIST) announced today that the two agencies are working with the Internet Corporation for Assigned Names and Numbers (ICANN) and VeriSign on an initiative to enhance the security and stability of the Internet. The parties are working on an interim approach to deployment, by year?s end, of a security technology?Domain Name System Security Extensions (DNSSEC)?at the authoritative root zone (i.e., the address book) of the Internet. There will be further consultations with the Internet technical community as the testing and implementation plans are developed. The Domain Name and Addressing System (DNS) is a critical component of the Internet infrastructure. The DNS associates user-friendly domain names (e.g., www.commerce.gov) with the numeric network addresses (e.g., 170.110.225.163) required to deliver information on the Internet, making the Internet easier for the public to navigate. The accuracy, integrity, and availability of the data supplied by the DNS are essential to the operation of any system or service that uses the Internet. Over the years, vulnerabilities have been identified in the DNS protocol that threaten the authenticity and integrity of the DNS data. ?Many of these vulnerabilities are mitigated by DNSSEC, which is a suite of Internet Engineering Task Force (IETF) specifications for securing information provided by the DNS. ?The Internet is an ever-increasing means of communications and commerce, and this success is due in part to the Internet domain name and addressing system,? said Acting NTIA Administrator Anna M. Gomez. ?The Administration is committed to preserving the stability and security of the DNS, and today?s announcement supports this commitment.? "NIST has been an active participant within the international community in developing the DNSSEC protocols and has collaborated with various U.S. agencies in deploying DNSSEC within the .gov domain," said Cita M. Furlani, director of NIST's Information Technology Laboratory. "Signing the root will significantly speed up the global deployment of DNSSEC and enhance the security of the Internet.? The NTIA in the U.S. Department of Commerce serves as the executive branch agency principally responsible for advising the President on communications and information policies. For more information about the NTIA, visit www.ntia.doc.gov. As a non-regulatory agency, NIST promotes U.S. innovation and industrial competitiveness by advancing measurement science, standards and technology in ways that enhance economic security and improve our quality of life. For more information visit, www.nist.gov. From bellagamba at isoc.org Thu Jun 4 15:12:36 2009 From: bellagamba at isoc.org (Sebastian Bellagamba) Date: Thu, 4 Jun 2009 15:12:36 -0300 Subject: [lacnog] Programa de Embajadores de ISOC al FGI / ISOC Embassadors program to the IGF Message-ID: (English below) Estimados, Continuando el exitoso programa de Embajadores de ISOC a la Cumbre Mundial de la Sociedad de la Informaci?n (CMSI) en 2005, al Foro de Gobernanza de Internet (FGI) en R?o en 2007 y en Hyderabad en 2008, nos complace anunciar un llamado a expresiones de inter?s para participar en el programa de Embajadores de ISOC al Foro de Gobernanza de Internet en Sharm El Sheikh, Egipto, en noviembre 2009. Como parte del programa de L?deres de Internet de ISOC, el programa de Embajadores est? dise?ado para involucrar miembros en las actividades de acci?n global de ISOC al mismo tiempo proveyendo de valiosos conocimientos y experiencias al evento del FGI en Sharm El Sheikh. Este a?o, ISOC est? apoyando no s?lo la participaci?n por primera vez de Embajadores, sino tambi?n la de Embajadores retornantes al Foro de Gobernanza de Internet. El FGI 2009 tendr? lugar del domingo 15 al mi?rcoles 18 de noviembre de 2009. Personas interesadas deben estar disponible para arribar no m?s tarde del s?bado14 de noviembre. M?s detalles sobre el programa de Embajadores de ISOC al FGI 2009 pueden encontrarse aqu? (en ingl?s): http://www.isoc.org/pubpolpillar/igfambassadors/ M?s informaci?n sobre: Programa de L?deres de Internet de ISOC: http://www.isoc.org/leaders/ Foro de Gobernanza de Internet: http://www.intgovforum.org/cms/ Saludos ============== Dear all, Following the successful ISOC Ambassador program to the World Summit on the Information Society (WSIS) in 2005, to the Internet Governance Forum (IGF) in Rio in 2007 and in Hyderabad in 2008, we are pleased to announce a call for expressions of interest to participate in the ISOC Ambassador program to the Internet Governance Forum meeting in Sharm El Sheikh, Egypt, in November 2009. As part of the ISOC Internet Leaders program, the Ambassador program is designed to involve members in ISOC's global engagement activities while providing valuable expertise and know-how to the IGF meeting in Sharm El Sheikh. This year, ISOC is supporting not only the participation of first time Ambassadors, but also of returning Ambassadors to the Internet Governance Forum. The IGF 2009 meeting will take place Sunday 15 through Wednesday 18 November 2009. Interested individuals should be available to arrive no later than Saturday 14 November. Further details on ISOC's IGF 2009 Ambassador program can be found here: http://www.isoc.org/pubpolpillar/igfambassadors/ Read also about: ISOC Internet Leaders program: http://www.isoc.org/leaders/ Internet Governance Forum: http://www.intgovforum.org/cms/ Best regards Sebastian Bellagamba bellagamba at isoc.org ------------------------------- Manager - Oficina Regional para America Latina y el Caribe Regional Bureau Manager for Latin America and the Caribbean ================== Internet Society www.isoc.org -------------- next part -------------- An HTML attachment was scrubbed... URL: From patara at lacnic.net Fri Jun 12 00:42:17 2009 From: patara at lacnic.net (Ricardo Patara) Date: Fri, 12 Jun 2009 07:42:17 +0400 Subject: [lacnog] Llamado a Analista de Recurso Internet / Call for Internet Resource Analyst / Chamada para Analista de Recursos Internet Message-ID: ** version in english bellow ** ** vers?o em portugu?s a continua??o ** LACNIC realiza llamado para analista de Recursos Internet (hostmaster). Mayores detalles en: http://lacnic.net/sp/anuncios/2009_llamadoHostmaster.html [ English Version ] LACNIC makes a call for Internet Resource Analyst (hostmaster) More details at: http://lacnic.net/en/anuncios/2009_llamadoHostmaster.html [ Vers?o em Portugu?s ] LACNIC realiza chamado para Analista de Recursos Internet (hostmaster) Maiores detalhes em: http://lacnic.net/pt/anuncios/2009_llamadoHostmaster.html From roberto.gonzalez at ucv.ve Thu Jun 25 17:57:40 2009 From: roberto.gonzalez at ucv.ve (=?ISO-8859-1?Q?Roberto_Gonz=E1lez?=) Date: Thu, 25 Jun 2009 16:27:40 -0430 Subject: [lacnog] hardware para squid Message-ID: <4A43E4C4.5050202@ucv.ve> Actualmente tenemos un squid en prueba para web caching con dos discos. Un disco tiene una cache coss (20Gb de espacio), otro con aufs (70 Gb de espacio). El tama?o de los caches depende de los 4Gb de RAM que tiene el servidor. El servidor se comunica por wccp con el dispositivo de enrrutamiento. Queriamos conocer una configuraci?n hardware en producci?n (cantidad de menoria, discos y sistema de archivos de las caches) para un trafico mediano/alto. El tr?fico web que debe soportar el squid cuando pase a produccion es de 60Mb. Gracias. -- Lic. Roberto Gonzalez B. Direccion de Tecnologia de Informacion y Comunicaciones Division de Investigacion y Tecnologia Universidad Central de Venezuela tlf. 605-48-81 / 49-14 From fobispo at gmail.com Thu Jun 25 18:14:54 2009 From: fobispo at gmail.com (Francisco Obispo) Date: Fri, 26 Jun 2009 16:44:54 +1930 Subject: [lacnog] hardware para squid In-Reply-To: <4A43E4C4.5050202@ucv.ve> References: <4A43E4C4.5050202@ucv.ve> Message-ID: Estimado Roberto, Te voy a dar unos tips de configuraci?n, que a nosotros nos han servido bastante: - No utilices RAID para el squid, es mucho mejor que dejes que los caches est?n en discos independientes. - Si vas a tener mucho tr?fico y vas a "cachear" o guardar contenidos grandes, utiliza varios disco duros como cache. -Usa manejo asyncrono de los directorios de cache - He conseguido bastante mejora en performance, cuando se utiliza el sistema de archivos reiserfs para los caches, ya que fue dise?ado para manejar los archivos de MP3.com, es decir.. muchos pero muchos archivos (algo similar a un cache) - Asegurate de entonar el kernel de linux a trav?s de /proc para que deshabilites syn_cookies, y le des m?s recursos al stack TCP/IP (memoria sobretodo) -Instala una peque?a red para que puedas agregar _varios_ servidores a medida que vas creciendo en demanda. Obtuvimos muchos ?xitos usando Multicast para solicitar contenidos entre los servidores de cache.. -Consigue TODA la memoria RAM que puedas, y ELIMINA por completo el uso de SWAP -Habilita SNMP en el SQUID y supervisalo con un CACTI, o alguna otra herramienta de monitoreo, en especial observa el valor de "archivos abiertos".. seguro vas a tener que cambiarlo con ulimit, y recompilar para aumentar el FD_MAX permitido. Si vas a usar un equipo Cisco relativamente nuevo, quiz?s vas a tener que usar WCCPv2, y un tunel GRE contra el router. Recientemente instalamos uno, y funcion? sin mayores inconvenientes. Si necesitas mas detalles avisame para enviarte mas informaci?n. saludos 2009/6/26 Roberto Gonz?lez > Actualmente tenemos un squid en prueba para web caching con dos discos. Un > disco tiene una cache coss (20Gb de espacio), otro con aufs (70 Gb de > espacio). El tama?o de los caches depende de los 4Gb de RAM que tiene el > servidor. El servidor se comunica por wccp con el dispositivo de > enrrutamiento. > Queriamos conocer una configuraci?n hardware en producci?n (cantidad de > menoria, discos y sistema de archivos de las caches) para un trafico > mediano/alto. El tr?fico web que debe soportar el squid cuando pase a > produccion es de 60Mb. > Gracias. > > -- > Lic. Roberto Gonzalez B. > Direccion de Tecnologia de Informacion y Comunicaciones Division de > Investigacion y Tecnologia > Universidad Central de Venezuela > tlf. 605-48-81 / 49-14 > > _______________________________________________ > LACNOG mailing list > LACNOG at lacnic.net > https://mail.lacnic.net/mailman/listinfo/lacnog > ------------ pr?xima parte ------------ Se ha borrado un adjunto en formato HTML... URL: