Search DNSSEC Blog
DNSSEC NEWSFLASH
Wednesday, October 28, 2009
.eu plans to support DNSSEC
accredited registrars now have access to a .eu DNSSEC testbed.
Providing this access is the first step in .eu support for Domain
Name System Security Extensions (DNSSEC), a protocol that is intended
to make the domain name system more secure.
The testbed will help EURid understand the technical demands of
running the NSEC3 version of DNSSEC in combination with dynamic
updates. It will also help the registry evaluate response times and
measure the performance of zone file generation in the specific .eu
environment. Finally, it will help EURid learn more about certain
administrative processes required by DNSSEC. That includes the
recalculation of signatures during a process which is known as key
roll over.
"We want to work closely with our registrars to find out the best way
to launch DNSSEC together to benefit .eu users," comments Marc Van
Wesemael, EURid General Manager. "At this time, few top-level domain
registries offer DNSSEC support. We encourage all in the community to
help Internet users by embracing DNSSEC."
Full Article
Source: Retrieved on October 28, 2009 from pr-inside.com/eu-plans-to-support-dnssec-r1551606.htm
Tuesday, October 27, 2009
ICANN Wants To Fast Track Non-Latin Character Domain Names
You may soon see URLs with Arabic characters and other non-Latin letters. The Internet Corporation for Assigned Names and Numbers is pushing a proposal to include Internationalized Domain Names that have native language scripts. Thursday, October 22, 2009
Internationalization of the Internet Takes Center Stage at ICANN Seoul Meeting
A program that is expected to make the Internet far more accessible to millions of people in regions such as Asia and the Middle East will be one of the central topics of ICANN’s 36th International Public Meeting in Seoul, October 25-30, 2009. Wednesday, October 21, 2009
US Department of the Interior To Use Secure64 DNSSEC Appliance
The US Department of the Interior has purchased Secure64 Software Corporation's DNS Signer product to meet the Office of Management and Budget's December 2009 mandate that requires all federal agencies to add Domain Name System Security Extensions (or DNSSEC).
The Department of Interior is the latest in a growing list of government agencies that has selected Secure64 DNS Signer, according to its Wednesday announcement. With DNS responsible for translating between host names and IP addresses on Internet-connected systems, the OMB issued a mandate that all federal agencies must implement DNSSEC by December 2009 as part of its cyber security strategy.
"DOI required a solution able to sign for the entire department, including all component bureaus and offices, so scalability was a factor in our decision," Department of Interior chief technology officer William Corrington said in a statement. "Even more importantly, we needed an automated product with the highest level of security to prevent signature forging. We selected Secure64 DNS Signer because it met all of our requirements and successfully completed a pilot deployment in three days."
In addition to managing the natural resources of the US, Secure64 chief executive officer and director Steve Goodbarn said DOI has been prepared for natural disasters, such as floods, wildfires, and earthquakes. "The resiliency of their Internet communications is critical to meet these missions and the department has taken a leadership role in deploying an efficient and reliable IT architecture," Goodbarn said in a statement. "We are proud to be part of these efforts and to enable reliable, timely, and cost-effective deployment of DNSSEC."
Source: "US Department of the Interior To Use Secure64 DNSSEC Appliance", David Hamilton, Retrieved on October 21, 2009 from thewhir.com/web-hosting-news/102109_US_Department_of_the_Interior_To_Use_Secure64_DNSSEC_Appliance
Thursday, October 8, 2009
First root server provides a DNSSEC-signed zone as of December 1st
"Joe Abley of ICANN and VeriSign manager Matt Larson announced, at the 59th meeting of the "Réseaux IP Européens" (RIPE) in Lisbon, that, starting on the 1st of December, the central root zone of the Domain Name System (DNS) will be signed, deploying the DNS Security Extensions (DNSSEC) protocol, which has been discussed for years. However, the signed root zone will be distributed only gradually to a total of 13 root servers, while the public key is slated for distribution starting on the first of July, 2010. Responses cannot actually be validated until then. DNSSEC is designed to ensure that responses to DNS requests only come from authorised servers.
Ever since security expert Dan Kaminsky showed how easy it was to falsify such responses and deceive users issuing requests, experts have been under pressure to introduce DNSSEC. The US Department of Commerce released the date of the accelerated implementation, and also decided that VeriSign and ICANN should work together to sign the root zone.
Attendees at RIPE welcomed the news that DNSSEC was finally being deployed. Olaf Kolkman of Nlnet Labs called the gradual approach, "smart". Abley explained that the decision to proceed gradually was intended to prevent DNS from buckling under the load of the anticipated huge number of responses to root server requests. He said that, it is important to observe how many servers on the net re-route the signed responses and use unsigned variants whenever a root server provides the signed zone.
The design choice of a 1024 bit RSA root zone key, rather than the longer 2048 bit key, may have also been due to the ambitious deployment date. The zone will be signed with NSEC instead of the next generation NSEC3 standard. Because it is valid for only four months, the chosen key should be adequate, despite directives from US authorities to migrate to longer keys. The master key, however, will use the longer variant (2048 bit RSA). That key will only be changed every two to five years.
In recent months, increasing numbers of ccTLD managers have announced plans to sign their zones with DNSSEC. Most recently, the Swiss .ch and .li registry switch announced the change to DNSSEC. At the RIPE meeting in Lisbon, Sara Monteiro of the FCCN .pt registry, said that she was just months away from DNSSEC signing. DeNIC, on the other hand, recently started a two-year trial programme. The more dense the DNSSEC chain becomes, the more secure it will be. However, experts expect some drawbacks as well; especially domains that cannot be accessed because responses are not signed on time."
Source: h-online.com/security/First-root-server-provides-a-DNSSEC-signed-zone-as-of-December-1st--/news/114416