Neustar announced today that it has implemented DNSSEC in the .US country-code top level domain registry.
"This is an important step for Neustar, and gives .US domain name holders a significant way to differentiate their businesses," said Tim Switzer, vice president of registry services at Neustar. ".US now stands for unprecedented Internet security."
Source: Neustar Implements DNS Security Extensions in the .US Registry, Neustar, Inc., Retrieved on December 15, 2009 from prnewswire.com/news-releases/neustar-implements-dns-security-extensions-in-the-us-registry-79308817.html
Search DNSSEC Blog
DNSSEC NEWSFLASH
Tuesday, December 15, 2009
Neustar Implements DNSSEC in the .US Registry
Monday, December 14, 2009
Infoblox Delivers the Industry's Most Automated DNSSEC Solution
Infoblox Inc. today announced availability of additional functionality to help organizations simplify deployment of the Domain Name System Security Extensions (DNSSEC), a suite of IETF specifications for securing information provided by DNS.
Infoblox addresses this with its "one-click DNSSEC" solution that replaces manual key generation and zone signing with a one-click process that generates and securely distributes encryption keys to all appliances in the Infoblox grid that serve DNSSEC data. Infoblox also automates the critical process of periodically changing keys, also known as "key rollover," which is essential to ensuring that secure DNS data cannot be compromised. Keys are rolled over automatically according to best practices recommended by the National Institute of Standards and Technology (NIST-800-81) and RFC 4641 standards. DNSSEC records are signed and re-signed automatically each time DNS data are changed. This eliminates dozens of error-prone, manual operations and eliminates the need to write and maintain custom scripts.
Further, configuring a secondary and/or recursive name server for DNSSEC can also be accomplished with a single click. The solution also automates important administrative functions including easy importing of trust anchors.
Infoblox Vice President of Architecture and DNS expert, Cricket Liu, commented: "Addressing the most threatening DNS security concerns requires a globally coordinated effort to deploy DNSSEC. The functionality Infoblox provides in its purpose-built, highly automated solutions helps organizations overcome deployment challenges by eliminating the complex tasks required to support DNSSEC with conventional solutions."
Pricing and Availability
The most comprehensive DNSSEC functionality is now available in Infoblox NIOS software version 5.0r1, the only core network services solution on the market with a single Web-based graphical user interface (GUI) that provides management of all aspects of the domain name system (DNS), IP address assignment (DHCP) and IP address management (IPAM) infrastructure and data.
The NIOS software version 5.0r1 will be available Dec. 21, 2009. Pricing for the solution on the Infoblox-250 appliance starts at $2,495 in the U.S. Software upgrades are available free of charge for all current customers with a valid maintenance contract.
For more information about Infoblox products, visit: http://www.infoblox.com/products/.
Source: Marketwire, Infoblox Delivers the Industry's Most Automated DNSSEC Solution, Retrieved on December 14, 2009 from marketwire.com/press-release/Infoblox-1090225.html
Tuesday, December 1, 2009
Secure64 DNS Signer Earns FIPS 140-2 Level 2 Security Certification
Product Meets Stringent Cryptographic Security Standards Required for Federal Agencies
Secure64 Software Corporation today announced that the company's Secure64 DNS Signer software appliance will receive FIPS 140-2 Level 2 certification from the National Institute of Standards and Technology (NIST) and the Communications Security Establishment Canada (CSEC). Secure64 DNS Signer is the first commercial DNSSEC software appliance certified to Level 2. U.S. federal agencies are required to utilize only FIPS-certified products in any federal system that uses cryptography to protect sensitive or valuable information.
"This FIPS certification recognizes the security inherent in Secure64's architecture, which is able to store sensitive information online safely. By combining this security with high speed cryptography, our DNSSEC signing software is able to offer better cryptographic security and performance than other software solutions without the added cost and complexity of cryptographic hardware," said Steve Goodbarn, Secure64 CEO.
FIPS 140-2 is a NIST standard for cryptographic security that defines four levels of compliance ranging from Level 1 to Level 4. Level 1 certification provides assurance that the most basic security requirements have been met, while security requirements become more stringent as the certification levels increase. DNSSEC products use cryptographic digital signatures to protect the DNS, so FIPS 140-2 certification is a good measure of the degree of private key protection provided. No software cryptographic module has ever been certified to Level 3 or 4.
"FIPS certification is increasingly an important foundational technology requirement to drive adoption across the federal government marketplace," said Rishi Sood, Research Vice President at Gartner.
Public key cryptography is commonly used in computer systems to ensure the authenticity, integrity or confidentiality of data communicated across a network. Trust in the security of network communications depends on the degree of security those computer systems provide to protect their cryptographic keys. Without sufficient security, messages could easily be forged or confidential information intercepted.
"Most of our competitors simply use the cryptographic module that ships with the underlying operating system, or an OpenSSL cryptographic module," said Joe Gersch, Secure64 COO and nationally-recognized DNSSEC expert. "These modules may have been certified by NIST to Level 1, but the version of the module that was certified may or may not be the one actually used by the vendor. In contrast, Secure64 DNS Signer actually met the requirements for Level 3 in four of ten categories, and provides mitigation of attacks beyond what is required for certification. This means our software provides significantly more cryptographic security than any other commercial DNSSEC signing software available today."
For more information about DNSSEC and Secure64 DNS Signer, visit www.secure64.com.
SOURCE: Secure64 Software Corporation, PR NReswire, Retrieved on December 1, 2009 from prnewswire.com/news-releases/secure64-dns-signer-earns-fips-140-2-level-2-security-certification-78209882.html
Secure64 Software Corporation today announced that the company's Secure64 DNS Signer software appliance will receive FIPS 140-2 Level 2 certification from the National Institute of Standards and Technology (NIST) and the Communications Security Establishment Canada (CSEC). Secure64 DNS Signer is the first commercial DNSSEC software appliance certified to Level 2. U.S. federal agencies are required to utilize only FIPS-certified products in any federal system that uses cryptography to protect sensitive or valuable information.
"This FIPS certification recognizes the security inherent in Secure64's architecture, which is able to store sensitive information online safely. By combining this security with high speed cryptography, our DNSSEC signing software is able to offer better cryptographic security and performance than other software solutions without the added cost and complexity of cryptographic hardware," said Steve Goodbarn, Secure64 CEO.
FIPS 140-2 is a NIST standard for cryptographic security that defines four levels of compliance ranging from Level 1 to Level 4. Level 1 certification provides assurance that the most basic security requirements have been met, while security requirements become more stringent as the certification levels increase. DNSSEC products use cryptographic digital signatures to protect the DNS, so FIPS 140-2 certification is a good measure of the degree of private key protection provided. No software cryptographic module has ever been certified to Level 3 or 4.
"FIPS certification is increasingly an important foundational technology requirement to drive adoption across the federal government marketplace," said Rishi Sood, Research Vice President at Gartner.
Public key cryptography is commonly used in computer systems to ensure the authenticity, integrity or confidentiality of data communicated across a network. Trust in the security of network communications depends on the degree of security those computer systems provide to protect their cryptographic keys. Without sufficient security, messages could easily be forged or confidential information intercepted.
"Most of our competitors simply use the cryptographic module that ships with the underlying operating system, or an OpenSSL cryptographic module," said Joe Gersch, Secure64 COO and nationally-recognized DNSSEC expert. "These modules may have been certified by NIST to Level 1, but the version of the module that was certified may or may not be the one actually used by the vendor. In contrast, Secure64 DNS Signer actually met the requirements for Level 3 in four of ten categories, and provides mitigation of attacks beyond what is required for certification. This means our software provides significantly more cryptographic security than any other commercial DNSSEC signing software available today."
SOURCE: Secure64 Software Corporation, PR NReswire, Retrieved on December 1, 2009 from prnewswire.com/news-releases/secure64-dns-signer-earns-fips-140-2-level-2-security-certification-78209882.html
Wednesday, November 18, 2009
F5 Highlights New Security Features In BIG-IP 10.1
"Application Delivery Network vendor F5 has rolled out a number of security functionality features on their BIG-IP appliances. Along with enhanced protection against automated scanners and bots, the 10.1 release also delivers DNSSEC compliance, expanded IP geolocation and improved reporting.
For many enterprises, the DNSSEC updates are likely going to be the biggest draw to 10.1. The added security extension, meant to protect domain names from spoofing attacks, provides a trusted link between user and host. Unfortunately, this level of trust does not exist when a traffic manager, such as the BIG-IP's Global Traffic Manager, is redirecting traffic based on location or traffic load. F5's solution is to deliver the signed responses from the BIG-IP itself, making it the trusted host, ensuring compliance without having to re-engineer the application server environment behind it. F5 claims that their BIG-IP DNSSEC solution is the first to market among competitors in the load balancing space."
Source: F5 Highlights New Security Features In BIG-IP 10.1, Michael Brandenburg, Retrieved on November 18, 2009 from networkcomputing.com/wan-optimization-and-application-acceleration/f5-highlights-new-security-features-in-big-ip-101.php
For many enterprises, the DNSSEC updates are likely going to be the biggest draw to 10.1. The added security extension, meant to protect domain names from spoofing attacks, provides a trusted link between user and host. Unfortunately, this level of trust does not exist when a traffic manager, such as the BIG-IP's Global Traffic Manager, is redirecting traffic based on location or traffic load. F5's solution is to deliver the signed responses from the BIG-IP itself, making it the trusted host, ensuring compliance without having to re-engineer the application server environment behind it. F5 claims that their BIG-IP DNSSEC solution is the first to market among competitors in the load balancing space."
Source: F5 Highlights New Security Features In BIG-IP 10.1, Michael Brandenburg, Retrieved on November 18, 2009 from networkcomputing.com/wan-optimization-and-application-acceleration/f5-highlights-new-security-features-in-big-ip-101.php
Tuesday, November 17, 2009
VeriSign to offer DNSSEC by Q1 2011
VeriSign announced Monday that it will meet its goal of supporting DNS Security Extensions – dubbed DNSSEC -- in the .net and .com top-level domains by March 2011.
VeriSign has been working on DNSSEC deployment with Educause, a non-profit organization that operates the .edu domain for universities and colleges. VeriSign and Educause are hosting a DNSSEC testbed for universities to trial new DNS authentication mechanisms. VeriSign says it will have DNSSEC fully operational on .edu by March.
“Signing the root is in a testbed right now,” says Pat Kane, vice president of naming at VeriSign. “We will have a deliberate, pragmatic rollout by July 1. Then the entire DNS root zone across the globe will be signed.”
Kane says the trickiest part of deploying DNSSEC across .com and .net is allowing domain name registrars—such as Go Daddy, Network Solutions and Register.com—to do the key management for their customers.
Kane says VeriSign plans to have DNSSEC deployed across .net by the fourth quarter of 2010 and .com by the first quarter of 2011.
DNSSEC also needs to be deployed across more domains. VeriSign says it will add these DNS security mechanisms to two more domains that it operates -- .tv and .cc – by the end of 2011.
Corporations with large portfolios of domain names need to make sure that their registrars are rolling out DNSSEC, Kane advises. “These companies don’t just have .com and .net names, but also .info and .biz names,” he adds. “They should be encouraging their registrars to get other [top-level domains] working on this.”
The U.S. federal government is deploying DNSSEC on the .gov domain this year, and the Public Interest Registry announced support for DNSSEC on the .org domain in June. Other countries such as Sweden, Puerto Rico, Bulgaria, Brazil and Czech Republic already support this added layer of security for DNS look-ups.
Source: VeriSign bolsters security for .com, .net sites, Carolyn Duffy Marsan, Network World , Retrived on November 17, 2009 from networkworld.com/news/2009/111609-verisign-dnssec.html?hpg1=bn
VeriSign has been working on DNSSEC deployment with Educause, a non-profit organization that operates the .edu domain for universities and colleges. VeriSign and Educause are hosting a DNSSEC testbed for universities to trial new DNS authentication mechanisms. VeriSign says it will have DNSSEC fully operational on .edu by March.
“Signing the root is in a testbed right now,” says Pat Kane, vice president of naming at VeriSign. “We will have a deliberate, pragmatic rollout by July 1. Then the entire DNS root zone across the globe will be signed.”
Kane says the trickiest part of deploying DNSSEC across .com and .net is allowing domain name registrars—such as Go Daddy, Network Solutions and Register.com—to do the key management for their customers.
Kane says VeriSign plans to have DNSSEC deployed across .net by the fourth quarter of 2010 and .com by the first quarter of 2011.
DNSSEC also needs to be deployed across more domains. VeriSign says it will add these DNS security mechanisms to two more domains that it operates -- .tv and .cc – by the end of 2011.
Corporations with large portfolios of domain names need to make sure that their registrars are rolling out DNSSEC, Kane advises. “These companies don’t just have .com and .net names, but also .info and .biz names,” he adds. “They should be encouraging their registrars to get other [top-level domains] working on this.”
The U.S. federal government is deploying DNSSEC on the .gov domain this year, and the Public Interest Registry announced support for DNSSEC on the .org domain in June. Other countries such as Sweden, Puerto Rico, Bulgaria, Brazil and Czech Republic already support this added layer of security for DNS look-ups.
Source: VeriSign bolsters security for .com, .net sites, Carolyn Duffy Marsan, Network World , Retrived on November 17, 2009 from networkworld.com/news/2009/111609-verisign-dnssec.html?hpg1=bn
Subscribe to:
Posts (Atom)
