One of the 13 root DNS servers (c.root-servers.net), which ensure the operation of the root DNS zone (the initial link in the chain of domain name resolution, delivering information about the DNS servers serving top-level domains and the keys for their verification using DNSSEC), was out of sync with the other root DNS servers for four days. The root DNS server "C" (192.33.4.12) is maintained by 12 servers located in various countries. All of these servers, from May 18 to May 22, did not reflect changes in the root zone, returned outdated data, and were not synchronized with the rest of the DNS infrastructure.
During the specified period, no changes were made to the root zone, but an update of the DNSEC digital signature for the top-level domain ".gov" was planned, conducted as part of the transition to cryptographic keys based on the ECDSA algorithm. For certifying the ".gov" zone in DNSSEC, algorithms 8 (RSA/SHA-256) and 13 (ECDSA P-256/SHA-256) have recently been used, although algorithm 8 remains active. Over the weekend, it was planned to add a DS record for algorithm 13 to the root zone, after which the process of removing the DS record for algorithm 8 would begin. A similar replacement was planned for the ".int" domain. As a result, the DS records related to supporting algorithm 13 for the root servers were handed over to IANA but were never published, as the process of key replacement was halted after issues were identified until the situation with root server "C" is clarified.
The operation of root DNS server "C" is provided under agreements with the ICANN corporation by Tier 1 backbone provider Cogent Communications, present in 53 countries. A few days before the incident, problems were noted with access from the Cogent Communications network to 1575 autonomous systems due to the termination of peering with Indian Tier 1 provider Tata Communications.
The reason for the cessation of updates to the root DNS zone is attributed to a failure in the monitoring system responsible for tracking changes. The failure occurred after a routing modification that was unrelated to the operation of DNS servers (detailed information about the reasons is not provided yet). Apart from desynchronization, no violations in processing requests to the root DNS server "C" have been recorded. Synchronization was fully restored on May 22 at 7 PM (MSK). Among the potential problems that could have arisen during the prolonged desynchronization, there is a possibility of providing outdated data about the keys used in DNSSEC and the addresses of DNS servers servicing domains the first level.
Source: opennet.ru
