dnssec revision cb2a4cad76fbda226e7cd9dd3ca017b52521e3d1
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteCopyright (C) 2000, 2001 Internet Software Consortium.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteSee COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteDNSSEC Release Notes
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteThis document summarizes the state of the DNSSEC implementation in
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortethis release of BIND9.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteOpenSSL Library Required
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteTo support DNSSEC, BIND 9 must be lined with version 0.9.5a or newer of
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortethe OpenSSL library. As of BIND 9.2, the library is no longer
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteincluded in the distribution - it must be provided by the operating
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortesystem or installed separately.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteTo build BIND 9 with OpenSSL, use "configure --with-openssl". If
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortethe OpenSSL library is installed in a nonstandard location, you can
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortespecify a path as in "configure --with-openssl=/var".
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteKey Generation and Signing
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteThe tools for generating DNSSEC keys and signatures are now in the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortebin/dnssec directory. Documentation for these programs can be found
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortein doc/arm/Bv9ARM.4.html and the man pages.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteThe random data used in generating DNSSEC keys and signatures comes
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortefrom either /dev/random (if the OS supports it) or keyboard input.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteAlternatively, a device or file containing entropy/random data can be
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortespecified.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteServing Secure Zones
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteWhen acting as an authoritative name server, BIND9 includes KEY, SIG
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteand NXT records in responses as specified in RFC2535 when the request
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortehas the DO flag set in the query.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteResponse generation for wildcard records in secure zones is not fully
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortesupported. Responses indicating the nonexistence of a name include a
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteNXT record proving the nonexistence of the name itself, but do not
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteinclude any NXT records to prove the nonexistence of a matching
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortewildcard record. Positive responses resulting from wildcard expansion
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortedo not include the NXT records to prove the nonexistence of a
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortenon-wildcard match or a more specific wildcard match.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteSecure Resolution
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteBasic support for validation of DNSSEC signatures in responses has
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortebeen implemented but should still be considered experimental.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteWhen acting as a caching name server, BIND9 is capable of performing
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortebasic DNSSEC validation of positive as well as nonexistence responses.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteThis functionality is enabled by including a "trusted-keys" clause
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortein the configuration file, containing the top-level zone key of the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortethe DNSSEC tree.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteValidation of wildcard responses is not currently supported. In
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteparticular, a "name does not exist" response will validate
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortesuccessfully even if it does not contain the NXT records to prove the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortenonexistence of a matching wildcard.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteProof of insecure status for insecure zones delegated from secure
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortezones works when the zones are completely insecure. Privately
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortesecured zones delegated from secure zones will not work in all cases,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortesuch as when the privately secured zone is served by the same server
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteas an ancestor (but not parent) zone.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteHandling of the CD bit in queries is now fully implemented. Validation
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forteis not attempted for recursive queries if CD is set.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteSecure Dynamic Update
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn ForteDynamic update of secure zones has been implemented, but may not be
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortecomplete. Affected NXT and SIG records are updated by the server when
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Fortean update occurs. Advanced access control is possible using the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte"update-policy" statement in the zone definition.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte$Id: dnssec,v 1.13 2001/07/13 00:48:46 gson Exp $
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte