dnssec workshop - icann gnso...4. dnssec lessons learned: roland van rijswijk, surfnet 5. dnssec...

33
1 DNSSEC Workshop Cartagena, Colombia 08 December 2010

Upload: others

Post on 31-Aug-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

1

DNSSECWorkshop

Cartagena,Colombia

08December2010

Page 2: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Program Committee

•  MarkusTravaille,SIDN•  SimonMcCalla,Nominet

•  RussMundy,Cobham

•  SteveCrocker,Shinkuro,Inc.•  JulieHedlund,ICANN

Page 3: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Sponsors

•  PublicInterestRegistry

•  OpenDNSSEC•  .SE•  Afilias

•  GoDaddy•  Dyn,Inc.•  Comcast•  SIDN•  Nominet

Page 4: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Agenda

4

1.  CapsuleViewofDeployment:SteveCrocker,Co‐Chair,DNSSECDeploymentIniOaOve

2.  PanelDiscussion:DNSSECAdopOon‐‐BestPracOcesontheSOmulaOonoftheDeploymentofDNSSECinccTLDandgTLD’sModerator:MarkusTravaille,SIDN;Panelists:JamesBladel,GoDaddy;MaUMansell,MeshDigital/DomainMonster;PavelTuma,CZ.NIC;LanceWolak,PublicInterestRegistry;andChrisWright,AusRegistry

Page 5: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Agenda, Cont.

5

3.  IncidentsandResponses:RoyArends,NominetUK

4.  DNSSECLessonsLearned:RolandvanRijswijk,SURFnet

5.  DNSSECToolDevelopment:•  OpenSourceTools,RussMundy,

Co‐Chair,DNSSECDeploymentIniOaOve

•  DNSSECforHumans,JoãoDamas,InternetSystemsCorporaOon(ISC)

Page 6: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Agenda, Cont.

6

6.  PanelDiscussion:DNSSECImplementaOonApproaches‐‐ExperiencesandBestPracOcesontheVarietyofDNSSECDeploymentsAroundtheWorldModerator:SimonMcCalla,NominetUK;Panelists:OndrejFilip,CZNIC;MaULarson,VeriSign;RichardLamb,ICANN;RamMohan,Afilias;RickardBellgrim,InternetInfrastructureFoundaOon(.SE);JoãoDamas,InternetSystemsCorporaOon(ISC)

Page 7: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Agenda, Cont.

7

8.  ISPValidaOonandCapability:PreparingforandRollingOutDNSSEC:JasonLivingood,Comcast

9.  AcOviOesfromtheRegion:ErickIriarteAhon,LACTLD;RamMohan,Afilias;FredericoNeves,NIC.br

Page 8: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

CapsuleViewofDeployment

ccTLDDNSSECDeploymentMar2010throughDec2011

SteveCrockerCo‐Chair,DNSSECDeployment

IniOaOve

8

Page 9: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 10: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 11: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 12: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 13: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 14: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

ccTLD DNSSEC Adoption

0

10

20

30

40

50

60

Mar'10 Jun'10 Sep'10 Dec'10 Dec'11

Experimental

Announced

ParOal

Full

Page 15: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

MeasurementofDNSSECUptake

SteveCrockerCo‐Chair,DNSSECDeployment

IniOaOve

Page 16: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Tracking DNSSEC Uptake •  TLDsaregeingsigned•  RegistrarsandRegistrants–sOllveryearly•  Resolversokware–reasonablygood•  Resolversinthefield–earlydays•  TeliainSweden,ComcastintheU.S.areleaders

•  ActualValidaOon–veryearlydays

Page 17: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Actual Validation •  AnumberresolversareautomaOcallyrequesOngsignedresponses.

•  Onlysomeoftheanswersareactuallyvalidated.

•  FromtheauthoritaOvenameserver’sperspecOve,isthereawaytotellwhichrequestsforsignedanswersarelikelytobeactuallyvalidated?

•  Yes.Lookattherequestsforthekeys.

Page 18: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Measuring Requests for Keys •  NeedregularmeasurementinplaceinmulOpleplaces.ThisisinprogressinmulOpleTLDs.

•  ShinkuroworkingwithPIR&Afiliasre.ORG.•  ThefollowingslidesshowfracOonoftotalqueriesandanswersthatareforkeys.•  MulOplelocaOons,acoupleofsamplesfromeach.•  Eachsampleis30to40minutes,tensofmillionsofqueries.

Page 19: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

“Results”

•  DNSkeyqueriesareintherangeof1/100of1%orless.

•  SomevariaOonwithgeography.

•  MeasurablechangesoverOme.

•  Actualusageisobviouslyquitesmall,BUT

•  Thereisactualusageandit’smeasurable.

Page 20: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 21: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 22: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment
Page 23: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

PanelDiscussionDNSSECAdopOon‐‐Best

PracOcesontheSOmulaOonoftheDeploymentofDNSSECin

ccTLDandgTLD’s

MarkusTravaille,SIDN,Moderator

23

Page 24: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Topics for Discussion

24

1.  DemandforDNSSECdomainsfromdomainowners•  Benefitsfordomainowners?•  Howtomarketthesebenefitsandcreateabusinesscase?

2.  VisibilityofDNSSECforinternetusers•  Howtoimprovethis?

•  Roleofsokwarevendors?

3.  BusinesscaseforDNSSECvalidaOon•  Toolstoreducecomplexity?

•  Howtoavoidunnecessarysupportcalls?

•  ValidaOonattheclientasasoluOon?

Page 25: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

IncidentsandResponsesRoyArends,NominetUK

25

Page 26: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

DNSSECLessonsLearnedRolandvanRijswijk,SURFnet

26

Page 27: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

DNSSECToolDevelopment:

OpenSourceToolsRussMundy,Co‐Chair

DNSSECDeploymentIniOaOve

27

Page 28: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

DNSSECToolDevelopment:

DNSSECforHumansJoãoDamas,ISC

28

Page 29: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

29

PanelDiscussionDNSSECImplementaOon

Approaches‐‐ExperiencesandBestPracOcesontheVarietyof

DNSSECDeploymentsAroundtheWorld

SimonMcCalla,NominetUKModerator

Page 30: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

Topics for Discussion

30

ThepanelistswilldebateanddiscussfourkeyquesOons,thevariousmeritsofeachapproach,andhowthesemightapplytodifferentsizedorganizaOonsandtheirposiOonintheDNSSEC‘chainoftrust’:1.  Whatisthehigh‐leveldesignofyourDNSSECimplementaOon

(tools&technologies)?

2.  HowdidyouimplementandintroduceDNSSECintoyourliveenvironment?

3.  WhatwerethechallengesyoufacedduringimplementaOon?

4.  Whatwerethelessonsyoulearnedfromtheexperience?

Page 31: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

ISPValidaOonandCapability:

PreparingforandRollingOutDNSSEC

JasonLivingoodComcast

31

Page 32: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

AcOviOesfromtheRegion

ErickIriarteAhon,LACTLDRamMohan,Afilias

FredericoNeves,NIC.br

32

Page 33: DNSSEC Workshop - ICANN GNSO...4. DNSSEC Lessons Learned: Roland van Rijswijk, SURFnet 5. DNSSEC Tool Development: • Open Source Tools, Russ Mundy, Co‐Chair, DNSSEC Deployment

ThankyouandquesOons

33