dnssec implementation approaches - icann gnso · dnssec implementation approaches . the dlv...

4
1 DNSSEC Implementation Approaches 1

Upload: others

Post on 17-Aug-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DNSSEC Implementation Approaches - ICANN GNSO · DNSSEC Implementation Approaches . The DLV infrastructure zone • DLV is a DNS-based deployment aid for early DNSSEC deployment –allows

1

DNSSEC Implementation Approaches

1

Page 2: DNSSEC Implementation Approaches - ICANN GNSO · DNSSEC Implementation Approaches . The DLV infrastructure zone • DLV is a DNS-based deployment aid for early DNSSEC deployment –allows

The DLV infrastructure zone

• DLV is a DNS-based deployment aid for early DNSSEC deployment – allows early adopters to use DNSSEC now – fosters interest from the Domain holders – allows other parties to gauge interest

• Uses an open specification to provide the service

• Most commonly based upon the dlv.isc.org zone

Page 3: DNSSEC Implementation Approaches - ICANN GNSO · DNSSEC Implementation Approaches . The DLV infrastructure zone • DLV is a DNS-based deployment aid for early DNSSEC deployment –allows

Securing the DLV infrastrucure • Biggest challenge was to secure the registry – content input validation

• Publish Policy and practice statement – how we deal with data, keys and signatures – how we secure data

Page 4: DNSSEC Implementation Approaches - ICANN GNSO · DNSSEC Implementation Approaches . The DLV infrastructure zone • DLV is a DNS-based deployment aid for early DNSSEC deployment –allows

Securing the DLV infrastructure • Obviously, the zone is signed

– contributed to tool development that is now available in BIND (and Unbound) • 90%+ resolver population

• Keys stored offline in encrypted media – not an HSM, but has tight access and usage control, physical access control

• Anycast service on the DNS servers used