DNSSEC Signer Switchover experience Alain Patrick AINA Former: - - PowerPoint PPT Presentation

dnssec signer switchover experience
SMART_READER_LITE
LIVE PREVIEW

DNSSEC Signer Switchover experience Alain Patrick AINA Former: - - PowerPoint PPT Presentation

DNSSEC Signer Switchover experience Alain Patrick AINA Former: AFRINIC NOW: WACREN Alain.Aina@wacren.net Disclaimer This switchover was done at AFRINIC https://www.afrinic.net/en/initiatives/dnssec


slide-1
SLIDE 1

DNSSEC Signer Switchover experience

Alain Patrick AINA

Former: AFRINIC

NOW: WACREN Alain.Aina@wacren.net

slide-2
SLIDE 2

This switchover was done at AFRINIC

https://www.afrinic.net/en/initiatives/dnssec https://afrinic.net/blog/67-migrating-an-opendnssec-signer

Disclaimer

slide-3
SLIDE 3

Context

ü Old signer on Opendnssec

ü Keys in SoftHSM ü KSK/ZSK, NSEC ü RSASHA256 ü Sqlite database

ü Zone signing issues noted

ü Workarounds until migration

slide-4
SLIDE 4

Motivations

ü Migrate to a newer version which is more stable, secure and scalable with :

ü MySql database ü New version of SoftHSM ü Keys in SoftHSM ü Same key algorithms and size ü Same policies ü Etc.

¡ ¡

slide-5
SLIDE 5

Strategy

¡ ü No private key export ü No fresh start ü Keep validation state of all signed zones all the time

ü Migrate with keys rollover

¡

slide-6
SLIDE 6

Architecture

slide-7
SLIDE 7

Pre ¡publish ¡DNSKEY ¡& ¡double ¡DS ¡

slide-8
SLIDE 8

Before switchover ¡

KSK New signer: 20119 ZSK New signer : 58890

slide-9
SLIDE 9

After switchover

slide-10
SLIDE 10

Final before old DS removal

slide-11
SLIDE 11

And so..

¡ ü It requires careful consideration of the planning and various timings

ü Signatures lifetime ü TTLs ü Keys management ü Switchover ü Etc..

ü It works out very well

ü No crash ü No alert

¡ ¡

slide-12
SLIDE 12

Conclusions

ü Good experience ü Would have been a different story with keys in HSM ü Will do same thing next time

ü Excerpt Pre-publishing KSKs

¡