Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Food for thought?

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Chronological Thread  
  • From: N C <burningserenity AT novo-ordo.com>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] Food for thought?
  • Date: Tue, 14 Jul 2026 18:47:17 -0400

I like the sound of this.

  1. I've begun the process of documenting my server setup, to help with this effort. I will post a repository to GitHub within the coming days or weeks.
  2. a. Hopes and dreams. Perhaps those who have already setup some good orchestration scripts can provide some links.
  3. b. AlienVault does "pulses," where people share IoCs, hashes, attacks, and mitigations. These get shared to a mailing list, similar to this one. We could start with a simple mailing list. If we need something more discrete, there is already the IRC channel.
  4. c. More hopes and dreams, but I'm willing to bet somebody out here has made some kind of nice management interface with React...
  5. Yeah, even some friendly guidelines would be go a long way. You might not even have to kick people's servers out for failing to abide all of the standards, just give them a red dot or a frowny face.

Anyway, nice to meet you all. Hope you enjoyed my 2c.

On Tue 14 Jul 18:27, Rouben wrote:

The recent email thread quoted below about a server “disappearing” from the server list triggered a lightbulb moment in my mind… I sincerely don’t mean to criticize and hope to start a friendly and respectful discussion. I thought that it might be helpful to share the core infrastructure code with a centralized git repository that all members could review. I feel like this might be helpful towards addressing a few core issues that I’ve always felt persisted at OpenNIC:

  1. The infrastructure code to track servers, for example, seems to be an “opaque box” to most people. It’d be nice to know how the service(s) are set up and maintained and what makes them tick, for both educational but also peer-review purposes.
  2. There doesn’t seem to be any continuity / succession planning at all for some of the infrastructure: if the maintainer(s) go away for whatever reason, the infrastructure just disappears / goes dark and likely would have to be adopted by a vounteer and set up from scratch. Having the infrastructure documented can help with this, rather than having to reinvent the wheel from scratch.
  3. Almost all server operator(s) are on their own when it comes to: 3.a. Deployment playbooks / configurations and hardening, including updates to hardening (e.g. firewall rules). Sure there is some very bare bones and somewhat dated stuff on the Wiki, but that’s just sufficient… it could be a lot more comprehensive. 3.b. Threat information sharing … for example, information regarding attack specifics, mitigation techniques or their post-mortems. 3.c. Infrastructure monitoring beyond external pings recorded by the server list page.
  4. At a higher level, it’d be nice to have semi-formal change management practices that are a balance of democratic voting and technical reasoning. I think we have this largely, although variables like dependencies and impact are discussed ad hoc as part of the democratic voting/discussion process. Aside from mailing list history there seem to be no other records. For git we can use something self-hosted like gitlab (overkill IMO), gitea or its European fork, forgejo. The latter is used by Berlin-based Codeberg. For documentation, we could just stick to best practices with an expectation that all server operators abide by them at a minimum. I don’t think actual enforcement is necessary, although conducting more comprehensive scans of server deployments to verify that certain best practices are in place (like querying for the latest known zone record change and checking if the servers are compliant with their responses vs. just doing a basic check that the server is “up”). Threat sharing and incident response is the trickiest, since we would likely need a synchronous communication medium. Something like Signal or Matrix (if self-hosted is preferable) could work. Rouben On Tue, Jul 14, 2026 at 13:11 Jeff Taylor <[1]shdwdrgn AT sourpuss.net> wrote: I think the record was lost, I don't see this entry in the current list. Unfortunately this is a problem we've been seeing and haven't found the source of the trouble yet. could you add your server again and let me know when that's been done? I'm also on the IRC chat if you want to reach out directly. On 7/13/26 09:37, N C wrote:

I'd like to announce my new public Tier 2 DNS server: IPv4: 142.196.173.2 IPv6: 2603:9001:f01:ad99::1002 Software: Unbound 1.25.1 Features: UDP/TCP port 53 Logging: Queries not logged Location: United States The server uses OpenNIC root hints (ns2/ns4/ns6/ns8.opennic.glue) and has been tested to resolve both ICANN and OpenNIC TLDs. I've registered the server at [2]servers.opennic.org. Please let me know if any adjustments are needed. Thanks, Nicholas Carlton You are a member of the OpenNIC Discuss list. You may unsubscribe by emailing [3]discuss-unsubscribe AT lists.opennicproject.org You are a member of the OpenNIC Discuss list. You may unsubscribe by emailing [4]discuss-unsubscribe AT lists.opennicproject.org References

  1. mailto:shdwdrgn AT sourpuss.net
  2. http://servers.opennic.org/
  3. mailto:discuss-unsubscribe AT lists.opennicproject.org
  4. mailto:discuss-unsubscribe AT lists.opennicproject.org

You are a member of the OpenNIC Discuss list. You may unsubscribe by emailing discuss-unsubscribe AT lists.opennicproject.org




Archive powered by MHonArc 2.6.24.

Top of Page