FIRST 2010 John Kristoff – Team Cymru 1
13 Things to Consider Before DNSSEC
John Kristoff jtk@cymru.com
13 Things to Consider Before DNSSEC John Kristoff jtk@cymru.com - - PowerPoint PPT Presentation
13 Things to Consider Before DNSSEC John Kristoff jtk@cymru.com FIRST 2010 John Kristoff Team Cymru 1 Where is the DNSSEC? We make no endorsement of DNSSEC here We offer no repudiation of DNSSEC here The considerations herein
FIRST 2010 John Kristoff – Team Cymru 1
13 Things to Consider Before DNSSEC
John Kristoff jtk@cymru.com
FIRST 2010 John Kristoff – Team Cymru 2
Where is the DNSSEC?
FIRST 2010 John Kristoff – Team Cymru 3
Guidance, not proclamation
FIRST 2010 John Kristoff – Team Cymru 4
One of two critical systems
Routing (BGP) and naming (DNS) are by far the two most critical subsystems of the Internet infrastructure. And in the case of DNS, practically all Internet hosts participate directly in the DNS as a client, server or
unencumbered protocols in use throughout the
depending on your perspective.
FIRST 2010 John Kristoff – Team Cymru 5
How many NS RRs for your zone?
FIRST 2010 John Kristoff – Team Cymru 6
Authoritative name server RRset
FIRST 2010 John Kristoff – Team Cymru 7
Where are your name servers?
FIRST 2010 John Kristoff – Team Cymru 8
DNS Server Diversity
FIRST 2010 John Kristoff – Team Cymru 9
Are parent and children consistent?
FIRST 2010 John Kristoff – Team Cymru 10
Delegation Consistency
FIRST 2010 John Kristoff – Team Cymru 11
Does your server answer anything from anyone?
FIRST 2010 John Kristoff – Team Cymru 12
Open Resolvers
http://www.team-cymru.org/Services/Resolvers/
FIRST 2010 John Kristoff – Team Cymru 13
How easily can returning answers be spoofed?
What is the rdata/ttl for ... ? HERE IT IS!! Mmwuahaha...
FIRST 2010 John Kristoff – Team Cymru 14
Answer Spoofing Protection
FIRST 2010 John Kristoff – Team Cymru 15
Is your name registration secure?
Please transfer domain.example.org to... Mmwuahaha...
FIRST 2010 John Kristoff – Team Cymru 16
Domain Name Registration
FIRST 2010 John Kristoff – Team Cymru 17
What is on your name server?
httpd snmpd ftpd proxyd dhcpd
FIRST 2010 John Kristoff – Team Cymru 18
Co-mingling Services
FIRST 2010 John Kristoff – Team Cymru 19
How are servers administered?
pictures from techrepublic, Bill Detwiler
OR
FIRST 2010 John Kristoff – Team Cymru 20
Administrative Processes
http://www.team-cymru.org/ReadingRoom/Templates/
FIRST 2010 John Kristoff – Team Cymru 21
How much RAM, CPU, disk and network capacity is available?
FIRST 2010 John Kristoff – Team Cymru 22
Physical Resources
FIRST 2010 John Kristoff – Team Cymru 23
Are you filtering DNS over TCP? OR
FIRST 2010 John Kristoff – Team Cymru 24
TCP
FIRST 2010 John Kristoff – Team Cymru 25
What queries do you see/make?
FIRST 2010 John Kristoff – Team Cymru 26
Monitoring and Auditing
http://www.team-cymru.org/Monitoring/DNS/ http://www.team-cymru.org/Monitoring/BGP/
FIRST 2010 John Kristoff – Team Cymru 27
Are name server clocks accurate?
FIRST 2010 John Kristoff – Team Cymru 28
Time Synchronization
FIRST 2010 John Kristoff – Team Cymru 29
Have you read IETF RFC 2870?
Network Working Group R. Bush Request for Comments: 2870 Verio Obsoletes: 2010 D. Karrenberg BCP: 40 RIPE NCC Category: Best Current Practice M. Kosters Network Solutions
SAIC June 2000 Root Name Server Operational Requirements
FIRST 2010 John Kristoff – Team Cymru 30
IETF RFC 2870
FIRST 2010 John Kristoff – Team Cymru 31
How can Team Cymru help?