DNSSEC signing of an internal zone gains nothing (unless??)

Mark Elkins mje at posix.co.za
Mon Aug 1 18:11:36 UTC 2022


Hmmm - might be saying the wrong thing but...

.SE was DNSSEC Signed waaay before the root, so if living in Sweden, one 
would prep your DNSSEC aware resolver with the DS Key of the .SE Zone. 
DNSSEC then worked for .SE domains. Perhaps do the same?

I do get confused further down in this email when one says you'll get 
back an "AA" flag in the answer. That will only happen if you ask the 
Authoritative Server for the domain you are looking in. That shouldn't 
be a Recursive server. It is terribly bad practice to have a BIND server 
running in both Authoritative and Recursive mode at the same time - 
should be two separate instances of BIND.

On 8/1/22 7:51 PM, John W. Blue via bind-users wrote:
> Also do not disagree.
>
> However, the intent of the thread is to talk about the lack of an AD flag from a non-public internal authoritative server.  Based upon what I am seeing only the AA flag is set.
>
> John
>
> -----Original Message-----
> From: John Franklin [mailto:franklin at sentaidigital.com]
> Sent: Monday, August 1, 2022 12:45 PM
> To: John W. Blue
> Cc: bind-users at lists.isc.org
> Subject: Re: DNSSEC signing of an internal zone gains nothing (unless??)
>
> On Aug 1, 2022, at 12:15, John W. Blue via bind-users <bind-users at lists.isc.org> wrote:
>> As some enterprise networks begin to engineer towards the concepts of ZeroTrust, one item caught me unaware:  PM’s asking for the DNSSEC signing of an internal zone.
>>   
>> Granted, it has long been considered unwise by DNS pro’s with a commonly stated reason that it increasing the size of the zone yadda, yadda, yadda.
>>   [snip]
>> Thoughts?
> DNSSEC enables use of certain security RRs, such as SSHA and TLSA, which can be used as part of a zero trust solution in DevOps pipelines.  It’s also good practice managing DNSSEC before deploying it in public production sites.
>
> jf
-- 

Mark James ELKINS  -  Posix Systems - (South) Africa
mje at posix.co.za       Tel: +27.826010496 <tel:+27826010496>
For fast, reliable, low cost Internet in ZA: https://ftth.posix.co.za 
<https://ftth.posix.co.za>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20220801/8324cc87/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0xB6FA15470B82C101.asc
Type: application/pgp-keys
Size: 627 bytes
Desc: not available
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20220801/8324cc87/attachment-0001.key>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 236 bytes
Desc: OpenPGP digital signature
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20220801/8324cc87/attachment-0001.sig>


More information about the bind-users mailing list