1 |
lo, |
2 |
|
3 |
On Monday 30 May 2005 19:33, Thilo Bangert wrote: |
4 |
> okay, but how does DNSSEC help you establish that? and what is it that |
5 |
> you are securing... |
6 |
|
7 |
By cryptographically signing zones you can be assured of the integrity of the |
8 |
domains. You are basically securing yourself against dns spoofing. Google |
9 |
around for more information on the benefits of dnssec. |
10 |
|
11 |
> |
12 |
> i don't know much about DNSSEC, but |
13 |
> from my understanding can DNSSEC establish cryptographic authority about |
14 |
> a DNS record, iff you can trust the master of the zone. since non of |
15 |
> the root servers supports DNSSEC, your zone can still be subject to |
16 |
> forgery... |
17 |
> |
18 |
> or are you running your own root zone? i guess using split-horizon |
19 |
> resolvers could be another setup in which this would work... ? |
20 |
|
21 |
Running our own root zone. |
22 |
|
23 |
On a side note courses such as |
24 |
(http://secure.interop.com/catalog/sessionDetail.do?SESSION_ID=1087) more |
25 |
information about DNSSEC. |
26 |
|
27 |
b |
28 |
-- |
29 |
Benjamin Smee (strerror) |
30 |
497F 5E98 1FA0 C313 EA0B 08C7 004A 66ED 448B E78C |