"When you type www.irs.gov—or the Web address of your bank or an e-commerce site—into your web browser, you want to be sure that no one is hijacking your request and sending you to a bogus look-alike page. You’re relying on the integrity of the Internet’s “phone book,” the Domain Name System (DNS).
Computer scientists at the National Institute of Standards and Technology (NIST) are playing a major role in making sure that what you type is what you get by providing standards, guidance and testing necessary to bolster the trustworthiness of the global DNS. A draft update of NIST’s guidelines for DNS security is now available for public comment. "
Search DNSSEC Blog
DNSSEC NEWSFLASH
Monday, March 16, 2009
NIST SP 800-81 Revision 1
Thursday, March 12, 2009
ISC Introduces DLV Web Interface for Rapid DNSSEC Deployment
ISC announced a new web-based interface for its DNSSEC Look-aside Validation (DLV) registry, a mechanism to allow domain holders to secure their domain information using the DNSSEC protocol extension to DNS in advance of a signed root or TLD zone.
ISC is introducing DLV and other DNSSEC and secure DNS services at the Government Security (GovSec) Expo and Conference in Washington, D.C. The new interface makes it easier for DNS administrators to join the DLV registry and maintain their data. DLV means that DNS administrators aren't dependent on others to get the full benefit of DNSSEC for their own portion of the name space.
For more information about ISC's DLV registry and DNSSEC services, please visit https://dlv.isc.org/
Friday, March 6, 2009
Kaminsky Reluctant on DNSSEC

Thursday, March 5, 2009
dot-GOV DNSSEC Signed
A GSA hosted website has been developed (dotgov.gov/dnssecinfo.aspx) to support the project and for hosting a link to the current dot-GOV public key (plain text file - dotgov.gov/publickey.txt), which should be used as the published trust anchor for dot-GOV. The site also includes additional links and help pages for implementing DNSSEC for U.S. federal agencies dot-GOV domains.
Wednesday, March 4, 2009
Government implements DNSSEC on the .gov domain
The government has digitally signed the .gov top-level domain, effectively implementing the Domain Name System Security Extensions (DNSSEC) protocols throughout the top tier of the federal Internet space.
“On Feb. 28, 2009, DNSSEC became operational on .gov after the program successfully completed all required DNSSEC testing,” the General Services Administration, lead agency in the program, said today in a statement.
The signing came one month after the January deadline set by the Office of Management and Budget in August. The deadline had been pushed back when GSA officials found during testing that an additional feature was needed in the DNSSEC software being used.
“The .gov DNSSEC public key was registered [Feb. 28] with the Internet Assigned Numbers Authority (IANA) Interim Trust Anchor Repository (iTAR) and became available for use as the published trust anchor for .gov validation,” GSA said in its statement. “The .gov Top Level Domain is now considered an active DNSSEC signed zone.”
The next step in the governmentwide effort to better secure its DNS is for agencies to begin deploying DNSSEC within their second-level domains, such as gsa.gov, by the end of the year.
Source: Government Computer News, "Government implements DNSSEC on the .gov domain", William Jackson, Retrieved from gcn.com/articles/2009/03/05/dnssec-on-dot-gov.aspx from Mar 05, 2009
