dnssec revision dde525678a94746d4ffefd156a98dc20c96c2b3a
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysCopyright (C) 2000, 2001 Internet Software Consortium.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysSee COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysDNSSEC Release Notes
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThis document summarizes the state of the DNSSEC implementation in
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthis release of BIND9.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysOpenSSL Library Required
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysTo support DNSSEC, BIND 9 must be linked with version 0.9.6e or newer of
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe OpenSSL library. As of BIND 9.2, the library is no longer
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysincluded in the distribution - it must be provided by the operating
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllyssystem or installed separately.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysTo build BIND 9 with OpenSSL, use "configure --with-openssl". If
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe OpenSSL library is installed in a nonstandard location, you can
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysspecify a path as in "configure --with-openssl=/var".
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysKey Generation and Signing
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThe tools for generating DNSSEC keys and signatures are now in the
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbin/dnssec directory. Documentation for these programs can be found
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysin doc/arm/Bv9ARM.4.html and the man pages.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThe random data used in generating DNSSEC keys and signatures comes
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysfrom either /dev/random (if the OS supports it) or keyboard input.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysAlternatively, a device or file containing entropy/random data can be
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysspecified.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysServing Secure Zones
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysWhen acting as an authoritative name server, BIND9 includes KEY, SIG
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysand NXT records in responses as specified in RFC2535 when the request
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllyshas the DO flag set in the query.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysSecure Resolution
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysBasic support for validation of DNSSEC signatures in responses has
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbeen implemented but should still be considered experimental.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysWhen acting as a caching name server, BIND9 is capable of performing
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysbasic DNSSEC validation of positive as well as nonexistence responses.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysThis functionality is enabled by including a "trusted-keys" clause
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysin the configuration file, containing the top-level zone key of the
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllysthe DNSSEC tree.
0cd13cbfb4270b840b4bd22ec5f673b2b6a2c02bwyllys
Validation of wildcard responses is not currently supported. In
particular, a "name does not exist" response will validate
successfully even if it does not contain the NXT records to prove the
nonexistence of a matching wildcard.
Proof of insecure status for insecure zones delegated from secure
zones works when the zones are completely insecure. Privately
secured zones delegated from secure zones will not work in all cases,
such as when the privately secured zone is served by the same server
as an ancestor (but not parent) zone.
Handling of the CD bit in queries is now fully implemented. Validation
is not attempted for recursive queries if CD is set.
Secure Dynamic Update
Dynamic update of secure zones has been implemented, but may not be
complete. Affected NXT and SIG records are updated by the server when
an update occurs. Advanced access control is possible using the
"update-policy" statement in the zone definition.
Secure Zone Transfers
BIND 9 does not implement the zone transfer security mechanisms of
RFC2535 section 5.6, and we have no plans to implement them in the
future as we consider them inferior to the use of TSIG or SIG(0) to
ensure the integrity of zone transfers.
$Id: dnssec,v 1.18 2002/08/09 02:34:07 mayer Exp $