60 likes | 168 Views
Learn how to configure and maintain trust anchors for secure DNS operations, including recommended practices and maintenance strategies. Presented by Matt Larson and Ólafur Guðmundsson. Recommended for DNS administrators.
E N D
Trust anchor configuration and maintenance Matt Larson (mlarson@verisign.com) Ólafur Guðmundsson (ogud@ogud.com) DNSOP @ IETF68
Motivations • Certain Trust Anchors need to be distributed out-of-band • One universal mechanism is better than many DNSOP @ IETF68
What to configure for a TA? • Public key of the trust anchor (DNSKEY) • Cryptographic hash (DS) DNSOP @ IETF68
Recommendations • Use DS SHA256 as the TA configuration format. • Perform priming queries on demand and repeat when DNSKEY set expires due to TTL DNSOP @ IETF68
TA Maintenance • Use the timers mechanism promoted by DNSEXT to go forward when possible • Get root key TA via trusted update mechanism (examples) • Software/OS updates • Specialized small software module checks for changes periodically DNSOP @ IETF68
Next Steps • Would like DNSOP to adopt document • Open issues: • Alternate more human friendly hash than DS? • More operational recommendations ? DNSOP @ IETF68