DNSSEC @ Mozilla
Shyam Mani shyam@mozilla.com
DNSSEC @ Mozilla OSCON, 2011 Shyam Mani shyam@mozilla.com - - PowerPoint PPT Presentation
DNSSEC @ Mozilla OSCON, 2011 Shyam Mani shyam@mozilla.com about:mozilla Agenda The Basics Implementation What we I messed up The Future What and the Why DNS Security Extensions Based on public key crypto RFC
Shyam Mani shyam@mozilla.com
Zone Name
Zone Name
Zone Name TTL
Zone Name TTL
Zone Name TTL 257 = KSK
Zone Name TTL 257 = KSK 256 = ZSK
Zone Name TTL 257 = KSK 256 = ZSK
Zone Name TTL 257 = KSK Key Algorithm 256 = ZSK
Zone Name TTL 257 = KSK Key Algorithm 256 = ZSK 7 = RSASHA1-NSEC3-SHA1
Zone Name
Zone Name
Zone Name TTL
Zone Name TTL
Zone Name TTL Key Tag
Zone Name TTL Key Tag
Zone Name TTL Key Tag 7 = Algo
Zone Name TTL Key Tag 7 = Algo 1 = Checksum (SHA1)
Zone Name TTL Key Tag 7 = Algo 1 = Checksum (SHA1) 2 = Checksum (SHA256)
Zone Name TTL Key Tag 7 = Algo 1 = Checksum (SHA1) 2 = Checksum (SHA256)
Zone Name TTL Key Tag 7 = Algo Checksum 1 = Checksum (SHA1) 2 = Checksum (SHA256)
(Sub)Domain
(Sub)Domain
(Sub)Domain A = Record Type
(Sub)Domain A = Record Type 7 = Algo
(Sub)Domain A = Record Type 7 = Algo 3 = Labels
(Sub)Domain A = Record Type 7 = Algo 3 = Labels
(Sub)Domain A = Record Type Inception 7 = Algo 3 = Labels
(Sub)Domain A = Record Type Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels
(Sub)Domain A = Record Type Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels
(Sub)Domain A = Record Type Expiry Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels
(Sub)Domain A = Record Type Expiry Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels
(Sub)Domain A = Record Type Expiry Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels Key Tag
(Sub)Domain A = Record Type Expiry Inception
YYYYMMDDHHMMSS
7 = Algo 3 = Labels Key Tag
(Sub)Domain A = Record Type Expiry Inception Signer Name
YYYYMMDDHHMMSS
7 = Algo 3 = Labels Key Tag
Fetching ZSK 17852/NSEC3RSASHA1 from key repository. Fetching KSK 51618/NSEC3RSASHA1 from key repository. Verifying the zone using the following algorithms: NSEC3RSASHA1. Zone signing complete: Algorithm: NSEC3RSASHA1: KSKs: 1 active, 0 stand-by, 0 revoked ZSKs: 1 active, 1 stand-by, 0 revoked mozilla.org.signed Signatures generated: 5999 Signatures retained: 0 Signatures dropped: 0 Signatures successfully verified: 5999 Signatures unsuccessfully verified: 0 Runtime in seconds: 5.068 Signatures per second: 1183.636
http://dnsviz.net/d/mozilla.org/dnssec/ Sandia National Labs
policy-map global policy class inspection_default inspect dns maximum-length 4096
http://secspider.cs.ucla.edu/ SecSpider - the DNSSEC monitoring project
http://people.mozilla.org/~shyam/presentations/oscon-2011.pdf