Gentoo Archives: gentoo-server

From: Benjamin Smee <strerror@g.o>
To: gentoo-server@l.g.o
Cc: Thilo Bangert <thilo.bangert@×××.net>
Subject: Re: [gentoo-server] DNS, Firewall and Mail Server.
Date: Wed, 01 Jun 2005 00:05:30
Message-Id: 200506010204.59401.strerror@gentoo.org
In Reply to: Re: [gentoo-server] DNS, Firewall and Mail Server. by Thilo Bangert
1 lo,
2
3 On Monday 30 May 2005 19:33, Thilo Bangert wrote:
4 > okay, but how does DNSSEC help you establish that? and what is it that
5 > you are securing...
6
7 By cryptographically signing zones you can be assured of the integrity of the
8 domains. You are basically securing yourself against dns spoofing. Google
9 around for more information on the benefits of dnssec.
10
11 >
12 > i don't know much about DNSSEC, but
13 > from my understanding can DNSSEC establish cryptographic authority about
14 > a DNS record, iff you can trust the master of the zone. since non of
15 > the root servers supports DNSSEC, your zone can still be subject to
16 > forgery...
17 >
18 > or are you running your own root zone? i guess using split-horizon
19 > resolvers could be another setup in which this would work... ?
20
21 Running our own root zone.
22
23 On a side note courses such as
24 (http://secure.interop.com/catalog/sessionDetail.do?SESSION_ID=1087) more
25 information about DNSSEC.
26
27 b
28 --
29 Benjamin Smee (strerror)
30 497F 5E98 1FA0 C313 EA0B 08C7 004A 66ED 448B E78C