< Back to LISTSERV archives

NETMAN@LISTSERV.EDUCAUSE.EDU


View:

:

[

|

Previous Message

|

Next Message

|

]

:

[

|

Previous Message

|

Next Message

|

]

:

[

|

Previous Message

|

Next Message

|

]

:

Proportional Font

LISTSERV Archives

LISTSERV Archives

NETMAN Home

NETMAN Home

NETMAN  2013

NETMAN 2013

Subject:

Re: Blocking outside DNS servers

From:

Kevin Wilcox <[log in to unmask]>

Reply-To:

The EDUCAUSE Network Management Constituent Group Listserv <[log in to unmask]>

Date:

Mon, 9 Sep 2013 18:33:53 -0400

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (33 lines)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Sep 09, 2013 at 02:07:53PM -0700, Michael Sinatra wrote:
 
> What happens if people want to do DNSSEC validation?  Do you let them
> use your canonical DNS servers as forwarders?  Will those servers
> return DNSSEC records (e.g. DNSKEYs and RRSIGs) if a forwarder or stub
> resolver requests them?

Right now they just get the RRSIG without an AD bit set.

A few years ago, when the root zone was signed, I tried to get adoption
for us to do a full DNSSEC deployment and it rocked the boat a little;
since then I've stayed away from bringing up anything else DNSSEC related.

When our users start saying they need validated queries then we'll
probably toggle the option on our secondary servers and after a delta of
no issues we'd toggle it on our primaries. It will have to be driven by
user requests, though.

kmw

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAlIuTNAACgkQsKMTOtQ3fKHtDQCeJB9aRy4paoI0jdt7nXhLwkpF
prkAn1qjXPndVqLYnWT3AWDlrwfdBZWQ
=iQQx
-----END PGP SIGNATURE-----

**********
Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/.

Top of Message | Previous Page | Permalink


Options

Log In

Log In

Get Password

Get Password


Search Archives

Search Archives


Join or Leave NETMAN

Join or Leave NETMAN


Archives

2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998

ATOM RSS1 RSS2