A massive failure occurred in the operation of the "DE" domain zone used in Germany. The issues arose due to a misconfiguration of DNSSEC for the root zone "DE" made by DENIC, the organization responsible for the top-level domain "DE". From May 5, 22:30 to May 6, 1:30 (MSK), attempts to resolve domains in the "DE" zone through DNS servers that utilize DNSSEC for data verification resulted in errors. On DNS servers employing DNSSEC, failures were also observed when resolving domains, which do not directly use DNSSEC.
The problem affected many DNS resolvers of providers and public DNS services such as 1.1.1.1 and 8.8.8.8. As a temporary measure, Cloudflare disabled DNSSEC authentication for domains in the "DE" zone in its DNS service 1.1.1.1. Users of DNS resolvers with DNSSEC disabled were not affected.
The official reasons for the incident have not yet been announced. It is believed that the issue arose due to an error in updating the digital signature for the "DE" zone, performed on May 5 at 20:49 (MSK). The key used for verifying the top-level domain is the root of trust for other keys used in second-level domains, and in turn, uses the key of the domain "." as a higher-level confirmation of its trustworthiness.
As a result of the operation conducted in the "DE" domain zone, the cryptographic signature (RRSIG — Resource Record Signature) for the NSEC3 DNS record turned out to be incorrect. The NSEC3 record is used to confirm the authenticity of DNS responses regarding the absence of a domain, in order to prevent NXDOMAIN response spoofing attacks for existing domains. In case of issues with the digital signature for the NSEC3 record, the DNS server cannot verify the authenticity of hashes with data about existing domains and, accordingly, cannot perform the verification, considers the response to be fake, and returns an error for any domain queries.
Source: opennet.ru
