Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DNSSEC v2
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Andreas Pfohl
July 27, 2015
Technology
0
55
DNSSEC v2
My second talk about DNSSEC at the Netz39 hackerspace.
Andreas Pfohl
July 27, 2015
Tweet
Share
More Decks by Andreas Pfohl
See All by Andreas Pfohl
The Event Language
apfohl
0
570
Kore
apfohl
0
230
DNSSEC
apfohl
0
170
Domain Name System
apfohl
1
230
FreeBSD
apfohl
0
260
Other Decks in Technology
See All in Technology
マーケットプレイス版Oracle WebCenter Content For OCI
oracle4engineer
PRO
5
1.5k
Bedrock PolicyでAmazon Bedrock Guardrails利用を強制してみた
yuu551
0
160
Stately
mu7889yoon
1
110
セキュリティについて学ぶ会 / 2026 01 25 Takamatsu WordPress Meetup
rocketmartue
1
290
AIと新時代を切り拓く。これからのSREとメルカリIBISの挑戦
0gm
0
800
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
280
GSIが複数キー対応したことで、俺達はいったい何が嬉しいのか?
smt7174
3
150
なぜ今、コスト最適化(倹約)が必要なのか? ~AWSでのコスト最適化の進め方「目的編」~
htan
1
110
Meshy Proプラン課金した
henjin0
0
250
顧客の言葉を、そのまま信じない勇気
yamatai1212
1
340
GitLab Duo Agent Platform × AGENTS.md で実現するSpec-Driven Development / GitLab Duo Agent Platform × AGENTS.md
n11sh1
0
120
Context Engineeringの取り組み
nutslove
0
290
Featured
See All Featured
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
1
120
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
231
22k
Ethics towards AI in product and experience design
skipperchong
2
190
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
0
170
The untapped power of vector embeddings
frankvandijk
1
1.6k
Breaking role norms: Why Content Design is so much more than writing copy - Taylor Woolridge
uxyall
0
160
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
47
7.9k
How to optimise 3,500 product descriptions for ecommerce in one day using ChatGPT
katarinadahlin
PRO
0
3.4k
Fireside Chat
paigeccino
41
3.8k
Mozcon NYC 2025: Stop Losing SEO Traffic
samtorres
0
140
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
110
What's in a price? How to price your products and services
michaelherold
247
13k
Transcript
DNSSEC von Andreas Pfohl
Überblick • Wiederholung DNS • Was ist DNSSEC? • Was
kann ich mit DNSSEC machen? • Was sind die Probleme von DNSSEC? • Was muss ich tun, um DNSSEC zu nutzen?
• Domain Name System • Namensauflösung • Zone Records DNS
Namensauflösung - DNS www.netz39.de. 78.46.22.20
Records - DNS netz39.de. A 78.46.22.20 netz39.de. MX 10 mail
netz39.de. NS ns1.domain… mail A 78.46.22.20 www CNAME @
DNSSEC • DNS Security Extensions • Authentizität • Integrität
Man in the Middle - DNSSEC Client Nameserver Provider netz39.de.?
netz39.de.? 78.46.22.20 17.142.160.59
Key Man in the Middle - DNSSEC Client Nameserver Provider
netz39.de.? netz39.de.? 78.46.22.20 + Signatur 17.142.160.59 + Signatur Key failed
Schlüssel - DNSSEC • Public Key Cryptography • Zone-Signing-Key •
Key-Signing-Key • Chain of Trust
Chain of Trust - DNSSEC . ZSK DS com. KSK
ZSK DS example.com. KSK ZSK Trust Anchor KSK KSK A
Anwendungen • Sicherer Verbindungsaufbau • Mail Exchange • SSH Fingerprints
• GnuPG Schlüssel • DANE
Mail - Anwendungen • MX Record • Mailserver gehört zur
Domain
SSH - Anwendungen • SSHFP Record • Korrekte SSH-Keys •
Überprüfung bei Verbindungsaufbau
GnuPG - Anwendungen • OPENPGPKEY Record • Public-Keys im DNS
• Domain-Verifizierung
DANE - Anwendungen • DNS-based Auth. of Named Entities •
TLSA Record • Fingerprints von Zertifikaten • Zertifikat gehört zu Server/Port
Probleme • Denial of Service Angriffe • DNS Amplification Attacks
• Zone Walking • Verifizierung
Probleme • Root-Key von USA verwaltet • Hohe Fehlerrate bei
Implementierung • Schwer zu verstehen • Alte Kryptographie
Voraussetzungen • Registrar unterstützt DNSSEC • Registrar trägt DS-Records ein
• Eigene Domain • Eigene Nameserver
OwnDNS.io • Eigene Experimentier-Domain •
[email protected]
• Besseres Verständnis des
DNS • Verbreitung von DNSSEC • Tutorials
Workshop • September 2015 • Eigener Nameserver • Eigene Domain
• DNSSEC
Danke E-Mail:
[email protected]
Twitter: @andreaspfohl