AFRINIC (r)DNSSEC Infrastructure
...and how we (silently) migrated a signer
Amreesh Phokeer amreesh@afrinic.net R&D
ICANN-59 (28 June 2017) 1
AFRINIC (r)DNSSEC Infrastructure ...and how we (silently) migrated - - PowerPoint PPT Presentation
AFRINIC (r)DNSSEC Infrastructure ...and how we (silently) migrated a signer Amreesh Phokeer amreesh@afrinic.net R&D ICANN-59 (28 June 2017) 1 African RIR RIR for the African and Indian Ocean region Community-driven through policy
...and how we (silently) migrated a signer
ICANN-59 (28 June 2017) 1
2
– 6 Root Servers (K and L)
– “c.in-addr.arpa” and “c.ip6.arpa”
– Free secondary/slave to African ccTLDs (~30)
3
4
>$ host 192.0.32.7 7.32.0.192.in-addr.arpa domain name pointer www.icann.org.
5
do domain: 2 : 2.9 .9.0 .0.0 .0.8 .8.f .f.3 .3.4 .4.1 .1.0 .0.0 .0.2 .2.i .ip6 p6.a .arpa pa
de descr: rDNS for
/48 - AF AFRINIC C CP CPT OPS
g: ORG ORG-AF AFNC1 C1-AF AFRINIC ad admin-c: c: IT7-AF AFRINIC te tech-c: c: IT7-AF AFRINIC zo zone-c: c: IT7-AF AFRINIC
ns nser erver er: ns : ns1.a 1.afrini nic.net .net ns nser erver er: ns : ns3.a 3.afrini nic.net .net ns nser erver er: ns : ns2.a 2.afrini nic.net .net ds ds-rd rdata ta: 2842 8 2 c2 c2e3b07f192cf cfdb0f0395e66f446ce ce02e9484e22fb787a17f7babe91547 d3 d3ed4 d4
re remark rks: A : AFRINI NIC C CPT O OPS mn mnt-by by: AFRI RINIC-IT IT-MN MNT mn mnt-lo lowe wer: AF AFRINIC-IT IT-MN MNT so source: AFRINIC # Filtered 6
7
– ZSK: Monthly – KSK: Yearly (double DS)
8
KS KSK 2048 2048 bits RS RSA ZSK ZSK 1024 1024 bits RS RSA Si Signa natur ure SH SHA-256 256 RS RSA
– DNSKEY: TTL on SOA – NSEC: mininum of SOA – RRSIG: lowest TTL – DS: TTL on NS
9
10
11
12
13
14 Cr Crit iteria ia Opt Option
Ex Expor port ex existing ng ke keys ys Opt Option
Ke Key rollover Opt Option
Ne New K Keys Opt Option
Ex Existing g keys fo followed b by ro rollover r In Invalidity window NO NO YES NO Ke Key manipulation YES NO NO YES Rol Rollov
me None Wait for old signatures to expire Wait for caches to pick up new keys
Number o r of f in interactio ions wit with parents 2 1
DNSKEY RRset size Same Double Same Same Ex Expos posure of
private ke keys ys YES NO: only public keys exposed NO YES
15
16
17
...and how we (silently) migrated a signer
ICANN-59 (28 June 2017) 18