NSA.gov is down
nsa.gov
nsa.gov
I have noticed lately that an awful lot of the government domains no longer have a webserver answering for the root domain and or do not have an a record at the root domain.
$ unbound-host -v navy.mil
navy.mil has no address (secure)
navy.mil has no IPv6 address (secure)
navy.mil mail is handled by 5 mx14.nmci.navy.mil. (secure)
navy.mil mail is handled by 5 mx15.nmci.navy.mil. (secure)
navy.mil mail is handled by 5 mx13.nmci.navy.mil. (secure)
$ unbound-host -v dod.mil
dod.mil has no address (secure)
dod.mil has no IPv6 address (secure)
dod.mil has no mail handler record (secure)
$ unbound-host -v nga.mil
nga.mil has no address (secure)
nga.mil has no IPv6 address (secure)
nga.mil mail is handled by 5 mailnde.nga.mil. (secure)
nga.mil mail is handled by 5 mailarn.nga.mil. (secure)
Updated:In addition to the "trend" I mentioned they might be doing maintenance. The dnssec records for nsa.gov are borked at the moment:
http://dnssec-debugger.verisignlabs.com/nsa.gov
dnsviz at sandia is super slow lately, which sucks. But you can compare verisign's answer to sandia's if you want:
Edit: www goes to an Akamai CDN vs bare domain goes to a straight IP address.
Clickable links:
There was a link to schneier's blog here recently and a few people mentioned that his cert was expired. I am willing to be that everyone who saw the cert warning were httpseverywhere users.
https://www.eff.org/https-everywhere
One could argue this should be a built-in option these days....
Really, I'd ask so what? How probable is it that they're just doing regular maintenance at 1am (EDT)? I think likely. But lets pollute what used to be a pretty great front page with baseless speculation over nothing. Even if it was an attack, how utterly meaningless. NSA website does not equal NSA internal network.