A second draft of the proposed revision of Special Publication 800-81 has been released for public comment. This release incorporates suggestions received on the first draft, released in March, and also includes guidance on migrating to a new cryptographic algorithm for signing a zone, for migrating to NSEC3 hashing specifications to provide authenticated denial of existence response, and a discussion of DNS Security Extensions (DNSSEC) in split view deployments.
The draft is expected to be finalized and published as SP 800-81r1 following the close of the public comment period on Sept. 30. Comments should be sent to SecureDNS@nist.gov
NIST SP 800-81 R1 Round 2 DRAFT Download
Source: NIST releases new draft of Special Publication 800-81 on securing DNS, Government Computer News, William Jackson, Retrieved on Aug 27, 2009 from gcn.com/articles/2009/08/27/dns-security-updates.aspx
Search DNSSEC Blog
DNSSEC NEWSFLASH
Friday, August 28, 2009
NIST releases new draft of Special Publication 800-81 on securing DNS
Thursday, August 20, 2009
Nominum to offer DNS 'blacklist' capability

Nominum's Trusted Response and Universal Enforcement (TRUE) architecture is already in use by several ISPs supporting a combined 100 million broadband households. Nominum wouldn't identify these ISPs, but its Web site says its carrier customers include Verizon, Sprint, NTT Communications and other major industry players.
Now Nominum is making its third-generation DNS software that features the TRUE architecture available to corporations and other enterprise customers.
Source: Computer World -computerworld.com/s/article/9136786/Nominum_to_offer_DNS_blacklist_capability
Wednesday, July 29, 2009
High-risk DNS exploit goes wild
BIND Dynamic Update DoS
CVE: CVE-2009-0696
CERT: VU#725188
Program Impacted: BIND
Versions affected: BIND 9 (all versions)
Severity: High
Exploitable: remotely
Summary: BIND denial of service (server crash) caused by receipt of a specific remote dynamic update message
Description:
Urgent: this exploit is public. Please upgrade immediately.
Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert.
This vulnerability affects all servers that are masters for one or more zones – it is not limited to those that are configured to allow dynamic updates. Access controls will not provide an effective workaround.
dns_db_findrdataset() fails when the prerequisite section of the dynamic update message contains a record of type “ANY” and where at least one RRset for this FQDN exists on the server.
db.c:659: REQUIRE(type != ((dns_rdatatype_t)dns_rdatatype_any)) failed
exiting (due to assertion failure).
Workarounds:
None.
(Some sites may have firewalls that can be configured with packet filtering techniques to prevent nsupdate messages from reaching their nameservers.)
Active exploits:
An active remote exploit is in wide circulation at this time.
Solution:
Upgrade BIND to one of 9.4.3-P3, 9.5.1-P3 or 9.6.1-P1. These versions can be downloaded from:
http://ftp.isc.org/isc/bind9/9.6.1-P1/bind-9.6.1-P1.tar.gz
http://ftp.isc.org/isc/bind9/9.5.1-P3/bind-9.5.1-P3.tar.gz
http://ftp.isc.org/isc/bind9/9.4.3-P3/bind-9.4.3-P3.tar.gz
Source: https://www.isc.org/node/474
Tuesday, July 28, 2009
Experts Show the Way Towards a Better, More Secure Internet for Everyone
Internet Society - STOCKHOLM - Some of the world's leading experts met in Stockholm today to discuss how the Internet can become more secure through a full implementation of new security standards in the Domain Name System (DNS).
The Domain Name System is a critical operational element of the Internet, creating a user-friendly environment that allows names to be mapped to host addresses (for example, web and email servers). However, this system is not safe from tampering. Earlier this year, one of Brazil's biggest banks suffered an attack that redirected its customers to fraudulent websites that attempted to steal passwords and install malware.
Many experts are calling for a full-scale implementation of Domain Name Security Extensions (DNSSEC) which could protect the Internet from these types of attacks, such as the Kaminsky Bug. Patrik Wallström of .SE (the Top Level Domain Registrar for Sweden) explained that Kaminsky attacks can trick Internet users by taking over domain names and redirecting queries to another server. All applications are at risk including among others our email and online transactions.
Leslie Daigle, Chief Internet Technology Officer of The Internet Society (ISOC), which organized the event: "DNSSEC effectively wraps tamper proof packaging around the data being requested to assure the user that the information is what was shipped from the authentic source."
"While DNSSEC isn't a magic bullet, it is a very important starting point that allows us to start evaluating how to secure the many applications that are intertwined with the Domain Name System," explained Jim Galvin, speaking on behalf of the Public Interest Registry that manages the .org domain name.
Richard Lamb, DNSSEC Programme Manager of ICANN added that "momentum has been building up. Today there is a generalized awareness that we need to implement the security extensions already at the root of the domain name system. With the widespread deployment of DNSSEC, we will be able to create a platform for innovation, new product development and international cooperation."
Matt Larson, Vice President of DNS research at VeriSign, one of the world's leading providers of network infrastructure services discussed VeriSign's plans for deploying DNSSEC in .com and .net. He said: "We are committed to the application of DNSSEC and have had a long history of involvement in its development. We are planning to have .net signed by the end of 2010 and .com signed in early 2011."
Securing the DNS panelists:
Patrick Wallström, SE Richard Lamb, ICANN Olaf Kolkman, NLnet Labs Leslie Daigle, The Internet Society Jim Galvin, Public Interest Registry Matt Larson, VeriSign
More details of the event, including presentations at: isoc.org/dns
Source: Internet Society - Retrieved on July 28th from businesswire.com/portal/site/google/?ndmViewId=news_view&newsId=20090728005890&newsLang=en
Friday, June 26, 2009
International politics slows full deployment of DNSSEC
A growing number of generic top-level domains, including .gov and .org, are deploying DNS Security Extensions to help ensure the reliability of the Domain Name System. But full deployment of the extensions is moving at a glacial pace. Part of the problem is the complexity of managing the cryptographic keys used to sign DNS data and authenticate queries and responses. But one Commerce Department official said another part of the problem is international concern about the United States controlling the Internet. In many cases, the challenges faced are diplomatic rather than technical. The official likened the process of bringing the international community on board to herding cats.
Commerce has put much of the job of managing the Internet into the hands of the Internet Corporation for Assigned Names and Numbers, a nonprofit organization formed for that purpose. But Congress is unwilling to give up its oversight of a network the Defense Department originally created, and that worries some who see the Internet as a global resource.
Individual entities can handle many aspects of Internet security at the endpoints. But because DNS underlies virtually all Internet activity, securing it effectively is best done at a higher level. Hopefully, deploying DNSSEC won’t prove to be as challenging as achieving peace in the Middle East.
Source: Government Computer News, By William JacksonJun 25, 2009 Retrieved from gcn.com/articles/2009/06/29/cybereye-box-dnssec-politics.aspx