RIPE 43, September 2002, Ρόδος. nsd a Name Service Daemon Alexis Yushin, Daniel Karrenberg, Olaf Kolkman,

Slides:



Advertisements
Similar presentations
Olaf M. Kolkman. APNIC, 6 February 2014, Bangkok. DNSSEC and in-addr an update Olaf M. Kolkman
Advertisements

Reverse DNS SIG Summary Report APNIC Annual Member Meeting Bangkok, March
Naming: The Domain Name System Nick Feamster CS 4251 Fall 2008.
© NLnet Labs, Licensed under a Creative Commons Attribution 3.0 Unported License.Creative Commons Attribution 3.0 Unported License Introduction.
State of DNS Security Extensions Edward Lewis February 26, 2001 APRICOT 2001 Panel.
Sergei Komarov. DNS  Mechanism for IP hostname resolution  Globally distributed database  Hierarchical structure  Comprised of three components.
February 2003slideset 1 Introduction to the DNS system Olaf M. Kolkman
The new APNIC DNS generation system. Previous System Direct access to backend whois.db files – Constructed radix tree in memory from domain objects –
DNS Security Extension (DNSSEC). Why DNSSEC? DNS is not secure –Applications depend on DNS ►Known vulnerabilities DNSSEC protects against data spoofing.
© Afilias Limitedwww.afilias.info SM Challenges of Deploying DNSSEC: Prepare your ccTLD with Secondary DNS services LACNIC Meeting May 2010 Presented by:
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
DNS Security Extensions (DNSSEC) Ryan Dearing. Topics History What is DNS? DNS Stats Security DNSSEC DNSSEC Validation Deployment.
25.1 Chapter 25 Domain Name System Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Domain Name System ( DNS )  DNS is the system that provides name to address mapping for the internet.
1 Secure DNS Solutions Rooster. 2 Introduction What does security mean for DNS? What security problems exist for DNS, what is being done about them, and.
Domain Name Services Oakton Community College CIS 238.
Peter Janssen, EURid.eu Ljubljana, RIPE 64, 2012 Peter Janssen, EURid.eu Ljubljana, RIPE 64, April
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Domain Name System | DNSSEC. 2  Internet Protocol address uniquely identifies laptops or phones or other devices  The Domain Name System matches IP.
Module 10 Advanced Topics. DNS and DHCP DHCP can be configured to auto- update (using DDNS) the forward and reverse map zones Can be secured using allow-update.
Module 3 DNS Types.
Olaf M. Kolkman. Apricot 2003, February 2003, Amsterdam. /disi Steps towards a secured DNS Olaf M. Kolkman, Henk Uijterwaal, Daniel.
Domain Names System The Domain Name System (DNS) is a hierarchical distributed naming system for computers, services, or any resource connected to the.
Microsoft Windows Server 2003 TCP/IP Protocols and Services Technical Reference Slide: 1 Lesson 17 Domain Name System (DNS)
DNS: Domain Name System
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Olaf M. Kolkman. Domain Pulse, February 2005, Vienna. DNSSEC Basics, Risks and Benefits Olaf M. Kolkman
Architecture of DNS CS 718 Activity 4 Submitted by Parag Abhyankar Anup S. Kunte
25.1 Chapter 25 Domain Name System Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Module 5: Planning a DNS Strategy. Overview Planning DNS Servers Planning a Namespace Planning Zones Planning Zone Replication and Delegation Integrating.
AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – , NTP, cDNS, RIPE Atlas Database - behind of scene.
25.1 Chapter 25 Domain Name System Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
CcTLD/ICANN Contract for Services (Draft Agreements) A Comparison.
TCP/IP Protocol Suite 1 Chapter 17 Upon completion you will be able to: Domain Name System: DNS Understand how the DNS is organized Know the domains in.
Olaf M. Kolkman. Apricot 2005, February 2005, Kyoto. DNSSEC An Update Olaf M. Kolkman
DNS Dynamic Update Performance Study The Purpose Dynamic update and XFR is key approach to perform zone data replication and synchronization,
Olaf Kolkman. APNIC 15, February 2003, Taipei. 1 RIPE Database Operations Update Olaf Kolkman RIPE NCC.
Karrenberg et. Al.. RIPE 43, September 2002, Ρόδος. DISTEL Domain Name Server Testing Lab Daniel Karrenberg with Alexis Yushin, Ted.
© NLnet Labs, Licensed under a Creative Commons Attribution 3.0 Unported License.Creative Commons Attribution 3.0 Unported License Practicalities.
Module 6: Managing and Monitoring Domain Name System (DNS)
AU, March 2, DNSSEC, APNIC, & how EPP might play a Role Ed Lewis DNS SIG APNIC 21.
1 Discussion of the new DNS generation system DNS Operations SIG APNIC 18 2nd September 2004, Fiji.
* Agenda  What is the DNS ?  Poisoning the cache  Short term solution  Long term solution.
DNS Session 5 Additional Topics Joe Abley AfNOG 2006, Nairobi, Kenya.
A study of caching behavior with respect to root server TTLs Matthew Thomas, Duane Wessels October 3 rd, 2015.
Computer Networks Fall, 2007 Prof Peterson. CIS 235: Networks Fall, 2007 Western State College How’s it going??
Mitigating DNS DoS Attacks Hitesh Ballani, Paul Francis 1.
HIDDEN DESCRIPTION SLIDE — NOT TO BE SHOWN TO THE PUBLIC Closing Info Catalogue code: C03 Full presentation or module? module Slide numbers: C03-1 to C03-2.
1 CMPT 471 Networking II DNS © Janice Regan,
Module 4 DNS Installation. DNS Software BIND (80+ %) Berkeley Internet Name Domain NSD (Name Server Daemon)
Olaf M. Kolkman. IETF58, Minneapolis, November DNSSEC Operational Practices draft-ietf-dnsop-dnssec-operational-practices-00.txt.
TCP/IP Protocol Suite 1 Chapter 17 Upon completion you will be able to: Domain Name System: DNS Understand how the DNS is organized Know the domains in.
DNS Cache Poisoning (pretending to be the authoritative zone) ns.example.co m Webserver ( ) DNS Caching Server Client I want to access
The Design and Implementation of a Next Generation Name Service for the Internet V. Ramasubramanian, E. Gun Sirer Cornell Univ. SIGCOMM 2004 Ciprian Tutu.
Mirjam KuehneRIPE Meeting # 31 RIPE ncc Internet Administration and the RIPE NCC Daniel Karrenberg.
So DNS is A client-server application that maps domain names into their corresponding IP addresses with the help of name servers. Mapping domain names.
Workshop Overview & Registry Model Model by Jaap Akkerhuis Related by Daniel Karrenberg.
Principles of Computer Security
Chapter 25 Domain Name System.
DNS Session 5 Additional Topics
CoreDNS and Kubernetes
DNSSEC Basics, Risks and Benefits
nsd a Name Service Daemon
Root KSK Roll Update DNS-OARC 27 Matt Larson, VP of Research
Introduction to the DNS system
Chapter 25 Domain Name System
Chapter 25 Domain Name System.
Chapter 25 Domain Name System
Introduction to the DNS system
Presentation transcript:

RIPE 43, September 2002, Ρόδος. nsd a Name Service Daemon Alexis Yushin, Daniel Karrenberg, Olaf Kolkman, Ted Lindgreen with Erik Rozendaal, Jaap Akkerhuis, Miek Gieben, …

RIPE 43, September 2002, Ρόδος. Presentation Outline Why nsd ? What is nsd ? Who should use nsd ?

RIPE 43, September 2002, Ρόδος. Why nsd? Code Diversity Simplicity Performance Open Source

RIPE 43, September 2002, Ρόδος. What is nsd? Authoritative-Only DNS Name Server –No recursion –No caching –No dynamic update –No zone transfers Implemented from Scratch High Performance Design DNSSec Ready Well Tested

RIPE 43, September 2002, Ρόδος. Basic nsd Design Zone Compiler bserved Loads Zone Files Responses daemon Queries Responses

RIPE 43, September 2002, Ρόδος. Performance Results

Performance Results

RIPE 43, September 2002, Ρόδος. Performance Results

RIPE 43, September 2002, Ρόδος. Performance Results “Marketing Version”

Goals Achieved ? Code Diversity –Totally New Design –Bug Diversity Simplicity –Daemon kept as small as possible (~1000 lines C) –No creeping featurism (total 5684 lines C) Performance –See above Open Source –Yes (BSD License)

RIPE 43, September 2002, Ρόδος. Who should use NSD? Publishers of authoritative zone info –Root Servers (some) –TLD servers –…–… Who should not use nsd –Recursing name servers –Servers really needing dynamic updates nsd is available. It is stable.

RIPE 43, September 2002, Ρόδος. Questions??? Slides and other information (will be) available from Nsd-1.0.1: nsd/index.en.html