DNSSEC at Mozilla
DNSSEC at Mozilla
NANOG 51
about:mozilla
Agenda
Whats new?
Whats new?
Relationships
Check if your TLD has been signed Check with your registrar about DNSSEC Make sure your software works
Setup - Before
Setup - After
Commands
Generate keys dnssec-keygen -K /mozilla.org/ -3 -n ZONE -f KSK mozilla.org dnssec-keygen -K /mozilla.org/ -3 -n ZONE mozilla.org Modify times (if needed) dnssec-settime -A +6mo <keyid> Sign your zones dnssec-signzone -S -K /mozilla.org/ -o mozilla.org -a -t -u -3 salt -H 1 mozilla.org Changes to bind - named.conf dnssec-enable yes; dnssec-validation yes; zone "mozilla.org" IN { type master; file "mozilla.org.signed"; }
Steps
Upgrade bind across the board Kick off signer DNS servers pick up changes and restart Prot!!oneone!!
Verify!
http://dnsviz.net/d/mozilla.org/dnssec/
Things to be aware of
Keys are everything, protect them Make sure you have a backup plan Eventually, you run the risk of your entire Sign (zones), publish (zones) then push (DS) Network equipment might need changes
policy-map global policy class inspection_default inspect dns maximum-length 4096
boo-boo(s)
boo-boo(s)
boo-boo(s)
Moving forward...
Thanks!
http://people.mozilla.org/~shyam/presentations/nanog-51-2011-nal.pdf