skip to content

DNSSEC

The extensions that let a resolver prove a DNS answer came from the zone owner: signed RRsets, DS delegations and a chain to the root. Interviewers probe it because DNS itself is unauthenticated.

on this pageshow

explore

questions

page 2 of 2

What do DNSSEC CDS and CDNSKEY records contain, where must a child zone publish them, and what does their delete form look like?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

CDS (type 59) copies the DS format and CDNSKEY (type 60) the DNSKEY format; a child publishes them at its apex to state the DS RRset it wants. 'CDS 0 0 0 0' or 'CDNSKEY 0 3 0 0' asks for all DS removed.

open as a page

Why should an application not rely on the DNSSEC AD bit from a remote resolver, and what makes that bit trustworthy?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

AD is a header bit no DNSSEC signature covers, so anyone on the path can set it. Trust it only from a trusted resolver over an authenticated channel (loopback, TSIG, SIG(0), IPsec), or validate on the host instead.

open as a page

A registrar must DNSSEC-sign 10,000 customer zones it hosts; how would you choose between a KSK/ZSK split and a combined key, and where would the keys live?

level: principalimportance: nice to knowfreq 6%

basics

~20 s

A registrar signing 10,000 DNSSEC zones is well served by one combined key per zone, held online in hardware, with automated DS updates. An offline key-signing key per zone cannot keep pace with DNSKEY signatures that expire on every zone.

open as a page

showing 31–33 of 33