dnssec revision dde525678a94746d4ffefd156a98dc20c96c2b3a
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysCopyright (C) 2000, 2001 Internet Software Consortium.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysSee COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysDNSSEC Release Notes
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThis document summarizes the state of the DNSSEC implementation in
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthis release of BIND9.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysOpenSSL Library Required
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysTo support DNSSEC, BIND 9 must be linked with version 0.9.6e or newer of
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe OpenSSL library. As of BIND 9.2, the library is no longer
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysincluded in the distribution - it must be provided by the operating
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllyssystem or installed separately.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysTo build BIND 9 with OpenSSL, use "configure --with-openssl". If
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe OpenSSL library is installed in a nonstandard location, you can
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysspecify a path as in "configure --with-openssl=/var".
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysKey Generation and Signing
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThe tools for generating DNSSEC keys and signatures are now in the
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbin/dnssec directory. Documentation for these programs can be found
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysin doc/arm/Bv9ARM.4.html and the man pages.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThe random data used in generating DNSSEC keys and signatures comes
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysfrom either /dev/random (if the OS supports it) or keyboard input.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysAlternatively, a device or file containing entropy/random data can be
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysServing Secure Zones
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysWhen acting as an authoritative name server, BIND9 includes KEY, SIG
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysand NXT records in responses as specified in RFC2535 when the request
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllyshas the DO flag set in the query.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysSecure Resolution
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysBasic support for validation of DNSSEC signatures in responses has
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbeen implemented but should still be considered experimental.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysWhen acting as a caching name server, BIND9 is capable of performing
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbasic DNSSEC validation of positive as well as nonexistence responses.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThis functionality is enabled by including a "trusted-keys" clause
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysin the configuration file, containing the top-level zone key of the
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe DNSSEC tree.