Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DNSSEC v2
Search
Andreas Pfohl
July 27, 2015
Technology
0
52
DNSSEC v2
My second talk about DNSSEC at the Netz39 hackerspace.
Andreas Pfohl
July 27, 2015
Tweet
Share
More Decks by Andreas Pfohl
See All by Andreas Pfohl
The Event Language
apfohl
0
530
Kore
apfohl
0
230
DNSSEC
apfohl
0
170
Domain Name System
apfohl
1
220
FreeBSD
apfohl
0
260
Other Decks in Technology
See All in Technology
普通のチームがスクラムを会得するたった一つの冴えたやり方 / the best way to scrum
okamototakuyasr2
0
100
現場で効くClaude Code ─ 最新動向と企業導入
takaakikakei
1
260
Firestore → Spanner 移行 を成功させた段階的移行プロセス
athug
1
490
Oracle Base Database Service 技術詳細
oracle4engineer
PRO
10
75k
プラットフォーム転換期におけるGitHub Copilot活用〜Coding agentがそれを加速するか〜 / Leveraging GitHub Copilot During Platform Transition Periods
aeonpeople
1
210
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
8.8k
DDD集約とサービスコンテキスト境界との関係性
pandayumi
3
290
会社紹介資料 / Sansan Company Profile
sansan33
PRO
6
380k
Agile PBL at New Grads Trainings
kawaguti
PRO
1
440
Autonomous Database - Dedicated 技術詳細 / adb-d_technical_detail_jp
oracle4engineer
PRO
4
10k
Generative AI Japan 第一回生成AI実践研究会「AI駆動開発の現在地──ブレイクスルーの鍵を握るのはデータ領域」
shisyu_gaku
0
310
ハードウェアとソフトウェアをつなぐ全てを内製している企業の E2E テストの作り方 / How to create E2E tests for a company that builds everything connecting hardware and software in-house
bitkey
PRO
1
160
Featured
See All Featured
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
131
19k
Rails Girls Zürich Keynote
gr2m
95
14k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
31
2.2k
The Pragmatic Product Professional
lauravandoore
36
6.9k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
113
20k
Chrome DevTools: State of the Union 2024 - Debugging React & Beyond
addyosmani
7
850
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
Designing for Performance
lara
610
69k
The Art of Programming - Codeland 2020
erikaheidi
56
13k
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
15
1.7k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Rebuilding a faster, lazier Slack
samanthasiow
83
9.2k
Transcript
DNSSEC von Andreas Pfohl
Überblick • Wiederholung DNS • Was ist DNSSEC? • Was
kann ich mit DNSSEC machen? • Was sind die Probleme von DNSSEC? • Was muss ich tun, um DNSSEC zu nutzen?
• Domain Name System • Namensauflösung • Zone Records DNS
Namensauflösung - DNS www.netz39.de. 78.46.22.20
Records - DNS netz39.de. A 78.46.22.20 netz39.de. MX 10 mail
netz39.de. NS ns1.domain… mail A 78.46.22.20 www CNAME @
DNSSEC • DNS Security Extensions • Authentizität • Integrität
Man in the Middle - DNSSEC Client Nameserver Provider netz39.de.?
netz39.de.? 78.46.22.20 17.142.160.59
Key Man in the Middle - DNSSEC Client Nameserver Provider
netz39.de.? netz39.de.? 78.46.22.20 + Signatur 17.142.160.59 + Signatur Key failed
Schlüssel - DNSSEC • Public Key Cryptography • Zone-Signing-Key •
Key-Signing-Key • Chain of Trust
Chain of Trust - DNSSEC . ZSK DS com. KSK
ZSK DS example.com. KSK ZSK Trust Anchor KSK KSK A
Anwendungen • Sicherer Verbindungsaufbau • Mail Exchange • SSH Fingerprints
• GnuPG Schlüssel • DANE
Mail - Anwendungen • MX Record • Mailserver gehört zur
Domain
SSH - Anwendungen • SSHFP Record • Korrekte SSH-Keys •
Überprüfung bei Verbindungsaufbau
GnuPG - Anwendungen • OPENPGPKEY Record • Public-Keys im DNS
• Domain-Verifizierung
DANE - Anwendungen • DNS-based Auth. of Named Entities •
TLSA Record • Fingerprints von Zertifikaten • Zertifikat gehört zu Server/Port
Probleme • Denial of Service Angriffe • DNS Amplification Attacks
• Zone Walking • Verifizierung
Probleme • Root-Key von USA verwaltet • Hohe Fehlerrate bei
Implementierung • Schwer zu verstehen • Alte Kryptographie
Voraussetzungen • Registrar unterstützt DNSSEC • Registrar trägt DS-Records ein
• Eigene Domain • Eigene Nameserver
OwnDNS.io • Eigene Experimentier-Domain •
[email protected]
• Besseres Verständnis des
DNS • Verbreitung von DNSSEC • Tutorials
Workshop • September 2015 • Eigener Nameserver • Eigene Domain
• DNSSEC
Danke E-Mail:
[email protected]
Twitter: @andreaspfohl