Presentation is loading. Please wait.

Presentation is loading. Please wait.

DNSSEC Status Update in UA

Similar presentations


Presentation on theme: "DNSSEC Status Update in UA"— Presentation transcript:

1 DNSSEC Status Update in UA
Dmitry Kohmanyuk Feb 7, 2012

2 Zone UA Key Generation Ceremony
December 2, 2011 Key parameters: RSASHA512 (algorithm 10) KSK bits: ZSK bits: 1024

3 Test zone UA.UA Zone UA.UA signed, keys in DLV (dlv.isc.org) UA has DS records for ua.ua and rovno.ua Test web site (can use Firefox plugin to verify)

4 Zone UA DNSSEC Tested Test signing environment running: BIND 9.8 NSEC3 (with opt-out)

5 Public server with signed UA for testing
ho1.ua.ua :67c:258::17 Test anchor: ua. IN DS B5F97978F45398C9C EA3AB4A882011DCAA4F D D58FE2AD This is not a production zone, use as your own risk (but NS records are same)

6 Public resolver with enabled DNSSEC validation
lh.cctld.ua :7f8:55:7::71

7 What next Using production keys and signer DS publication in root zone Profit!

8 Questions? Whois.ua


Download ppt "DNSSEC Status Update in UA"

Similar presentations


Ads by Google