DNSSEC 롤오버 실패로 .AL 전체가 마비…Cloudflare 1.1.1.1이 검증 우회를 알리는 새 방법
Another Entry in the "Stuff Im Glad Im Not Responsible for" Ledger

2026년 7월 3일, 알바니아의 국가 최상위 도메인 .AL 운영 기관(AKEP)이 DNSSEC 키 롤오버를 시도하다 실패해, 검증 리졸버를 사용하는 모든 .AL 도메인 접속이 두절됐다. Cloudflare의 공개 DNS 리졸버 1.1.1.1은 .DE 사고 때와 마찬가지로 Negative Trust Anchor(NTA)를 적용해 도메인 접속을 복구했지만, NTA가 적용된 응답은 검증이 우회되었음을 클라이언트가 알 수 없다는 문제가 있었다. 이번 .AL 사고에서 1.1.1.1은 처음으로 응답에 새 Extended DNS Error(EDE) 코드(EDE 33)를 포함시켜 NTA 적용을 투명하게 알렸다. 이는 Quad9의 Babak Farrokhi가 제안한 인터넷 초안으로, IETF DNSOP 워킹그룹에서 논의될 예정이다.
A response served under a Negative Trust Anchor now says so directly, giving operators, monitoring tools, and users the information they need to understand what the resolver did and why.