DNSSEC
The extensions that let a resolver prove a DNS answer came from the zone owner: signed RRsets, DS delegations and a chain to the root. Interviewers probe it because DNS itself is unauthenticated.
on this pageshowhide
explore
- Signature and Key Records6 questions
- Chain of Trust5 questions
- Zone Signing & Key Roles5 questions
- Validation & Resolution5 questions
- Authenticated Denial6 questions
- Key Rollover & Deployment6 questions
questions
page 2 of 2What do DNSSEC CDS and CDNSKEY records contain, where must a child zone publish them, and what does their delete form look like?
basics
~20 sCDS (type 59) copies the DS format and CDNSKEY (type 60) the DNSKEY format; a child publishes them at its apex to state the DS RRset it wants. 'CDS 0 0 0 0' or 'CDNSKEY 0 3 0 0' asks for all DS removed.
Why should an application not rely on the DNSSEC AD bit from a remote resolver, and what makes that bit trustworthy?
basics
~20 sAD is a header bit no DNSSEC signature covers, so anyone on the path can set it. Trust it only from a trusted resolver over an authenticated channel (loopback, TSIG, SIG(0), IPsec), or validate on the host instead.
A registrar must DNSSEC-sign 10,000 customer zones it hosts; how would you choose between a KSK/ZSK split and a combined key, and where would the keys live?
basics
~20 sA registrar signing 10,000 DNSSEC zones is well served by one combined key per zone, held online in hardware, with automated DS updates. An offline key-signing key per zone cannot keep pace with DNSKEY signatures that expire on every zone.
showing 31–33 of 33