Dnssec signed diferents zone with diferents keys

22 views
Skip to first unread message

Leandro Totino

unread,
Aug 30, 2015, 11:57:52 AM8/30/15
to AtomiaDNS
We are testing atomic dns and it looks like very good and there is the one in the market which can create zones, records by api,

I would like to create many keys (KSK e ZSK) by zones and signed them , soo I got a question about atomia dnssec, Can we sign dns zones with diferents keys (KSK and ZSK) in atomia?  Does Atomia just suport a key (ZSK e KSK) to sign all zone in the host?




Regards.

Jimmy Bergman

unread,
Aug 31, 2015, 1:32:38 AM8/31/15
to atom...@googlegroups.com
Hi

Yes, we have made the concious decision to make the set of keys global, not per zone, because we believe it greatly simplifies management and reduces operational risk related to DNSSEC.

Best regards,
Jimmy

--
You received this message because you are subscribed to the Google Groups "AtomiaDNS" group.
To unsubscribe from this group and stop receiving emails from it, send an email to atomiadns+...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Leandro Totino

unread,
Sep 10, 2015, 7:55:44 AM9/10/15
to AtomiaDNS
Hi Jimmy,

There are zones signed by dnssec and there are other which we are not. How AtomiaDNS can solve this problem because if you create a dnskey all zone will be signed. I got other question about if I can share all zone for all user through atomiaDNS webserver panel like if user A create a zone another user B can see as well and vice versa.

Jimmy Bergman

unread,
Sep 10, 2015, 8:00:30 AM9/10/15
to atom...@googlegroups.com
Hi

All zones are signed, but you can still enable/disable DNSSEC per zone by selectively publishing DS records to the parent only
for the ones which you want DNSSEC enabled on.

It is not possible to share a zone with the example webapp.

Best regards,
Jimmy

Leandro Totino

unread,
Sep 10, 2015, 12:30:51 PM9/10/15
to AtomiaDNS
Hi Jimmy,

I would like to know if i can specify RRSIG records expirtion date when I create the key or you have another aproach for that and I just tested atomia dnssec and didn´t work. 

I created the keys as documentation but after that if I tried to dig someregister +dnssec I didn´t get any RRSIG lie example below:


; <<>> DiG 9.9.5-3ubuntu0.4-Ubuntu <<>> teste.toto.com.br @172.16.95.97 +dnssec
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 32723
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 2800
;; QUESTION SECTION:
;teste.toto.com.br.             IN      A

;; ANSWER SECTION:
teste.toto.com.br.      3600    IN      A       2.2.2.2

Jimmy Bergman

unread,
Sep 11, 2015, 2:09:08 AM9/11/15
to atom...@googlegroups.com
Hi

You have to configure PowerDNS to use DNSSEC, although if you install the sync agent with our package, then
the atomiadns-powerdns-database package tries top set it up for you.

Our setup usess the PowerDNS live signing mode and a description about how the RRSIGs are constructed is available at

Best regards,
Jimmy
Reply all
Reply to author
Forward
0 new messages