User Tools

Site Tools


networking:dnssec

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
networking:dnssec [2026/07/22 15:35] – created - external edit 127.0.0.1networking:dnssec [2026/07/22 20:46] (current) – removed - external edit (Unknown date) 127.0.0.1
Line 1: Line 1:
-====== DNSSEC Explained ====== 
  
-**DNS Security Extensions (DNSSEC)** is a set of extensions to the Domain Name System (DNS) that allows DNS responses to be **cryptographically verified**. 
- 
-DNSSEC helps ensure that DNS records have not been modified or forged while they travel across the Internet. 
- 
-DNSSEC provides: 
- 
-  * Data authenticity 
-  * Data integrity 
-  * Protection against DNS spoofing and cache poisoning 
- 
-DNSSEC **does not** provide encryption or privacy. 
- 
------ 
- 
-===== Why Was DNSSEC Created? ===== 
- 
-Traditional DNS was designed without security. 
- 
-An attacker may attempt to convince a recursive resolver that a fake IP address belongs to a domain. 
- 
-Example: 
- 
-<code> 
-Attacker 
- 
-example.com 
-        │ 
-        ▼ 
- 
-203.0.113.200  (Fake) 
- 
-instead of 
- 
-93.184.216.34 
-</code> 
- 
-If the resolver accepts the forged response, users may be redirected to a malicious website. 
- 
-DNSSEC prevents this by allowing DNS responses to be digitally signed. 
- 
------ 
- 
-===== How DNSSEC Works ===== 
- 
-Each DNS zone has a pair of cryptographic keys. 
- 
-  * Private Key 
-  * Public Key 
- 
-The authoritative DNS server signs its DNS records using the private key. 
- 
-Resolvers verify the signatures using the corresponding public key. 
- 
-<code> 
-Authoritative Server 
- 
-DNS Record 
-      │ 
-      ▼ 
-Digital Signature 
-      │ 
-      ▼ 
-Recursive Resolver 
-      │ 
-Verify Signature 
-      │ 
-      ▼ 
-Trusted Answer 
-</code> 
- 
-If verification fails, the resolver rejects the response. 
- 
------ 
- 
-===== Chain of Trust ===== 
- 
-DNSSEC works through a **chain of trust**. 
- 
-Each level of the DNS hierarchy signs the next level. 
- 
-<code> 
-Root Zone 
-     │ 
-     ▼ 
-.com 
-     │ 
-     ▼ 
-example.com 
-</code> 
- 
-The root zone is the trust anchor for the entire DNSSEC system. 
- 
-If every signature is valid, the resolver can trust the final DNS record. 
- 
------ 
- 
-===== DNSSEC Record Types ===== 
- 
-DNSSEC introduces several additional DNS record types. 
- 
-^ Record ^ Purpose ^ 
-| **DNSKEY** | Public key for the DNS zone | 
-| **DS** | Delegation Signer (links parent and child zones) | 
-| **RRSIG** | Digital signature for DNS records | 
-| **NSEC** | Authenticated proof that a record does not exist | 
-| **NSEC3** | Similar to NSEC, but hides zone contents | 
-| **CDS** | Child Delegation Signer (automation) | 
-| **CDNSKEY** | Child DNSKEY (automation) | 
- 
------ 
- 
-===== DNSSEC Validation ===== 
- 
-When a resolver receives a DNS response, it performs validation. 
- 
-Steps: 
- 
-  - Retrieve the requested DNS record. 
-  - Retrieve its RRSIG record. 
-  - Retrieve the DNSKEY. 
-  - Verify the signature. 
-  - Verify the chain of trust up to the root zone. 
- 
-If validation succeeds, the response is accepted. 
- 
-Otherwise the resolver returns an error. 
- 
------ 
- 
-===== DNSSEC Does NOT Encrypt DNS ===== 
- 
-A common misconception is that DNSSEC encrypts DNS traffic. 
- 
-It does not. 
- 
-DNSSEC provides: 
- 
-  * Authentication 
-  * Integrity 
- 
-It does **not** provide: 
- 
-  * Confidentiality 
-  * Privacy 
-  * Encryption 
- 
-DNS queries remain visible on the network. 
- 
-For encrypted DNS, technologies such as **DNS over HTTPS (DoH)** and **DNS over TLS (DoT)** are used. 
- 
------ 
- 
-===== DNSSEC vs DoH vs DoT ===== 
- 
-^ Technology ^ Authentication ^ Encryption ^ 
-| DNS | No | No | 
-| DNSSEC | Yes | No | 
-| DNS over TLS (DoT) | No | Yes | 
-| DNS over HTTPS (DoH) | No | Yes | 
-| DNSSEC + DoH | Yes | Yes | 
- 
-DNSSEC and DoH solve different security problems and are often used together. 
- 
------ 
- 
-===== Advantages ===== 
- 
-DNSSEC provides: 
- 
-  * Protection against cache poisoning 
-  * Protection against forged DNS responses 
-  * Verification that DNS records originate from the authoritative server 
-  * Increased trust in DNS infrastructure 
- 
------ 
- 
-===== Limitations ===== 
- 
-DNSSEC does not: 
- 
-  * Hide DNS queries. 
-  * Encrypt DNS traffic. 
-  * Prevent DDoS attacks. 
-  * Protect websites against compromise. 
- 
-It only verifies the authenticity of DNS data. 
- 
------ 
- 
-===== How Can I Check Whether a Domain Uses DNSSEC? ===== 
- 
-A domain usually supports DNSSEC if: 
- 
-  * A **DS** record exists in the parent zone. 
-  * The zone publishes **DNSKEY** records. 
-  * DNS responses contain **RRSIG** records. 
- 
-Example: 
- 
-<code> 
-example.com 
- 
-DNSKEY 
-RRSIG 
-DS 
-</code> 
- 
------ 
- 
-===== DNSSEC and Telenegar ===== 
- 
-Telenegar DNS Check can help determine whether a domain supports DNSSEC by: 
- 
-  * Querying DNSSEC-related record types. 
-  * Displaying DNSKEY records. 
-  * Displaying DS records. 
-  * Displaying RRSIG records. 
-  * Indicating whether DNSSEC appears to be enabled. 
- 
-Future versions may also perform DNSSEC validation. 
- 
------ 
- 
-===== Common Misconceptions ===== 
- 
-  * **DNSSEC encrypts DNS traffic.** 
-    * False. DNSSEC only authenticates DNS data. 
- 
-  * **DNSSEC prevents every DNS attack.** 
-    * False. It prevents forged DNS responses but not every attack. 
- 
-  * **DoH replaces DNSSEC.** 
-    * False. DNSSEC and DoH provide different security properties. 
- 
------ 
- 
-===== Related Topics ===== 
- 
-  * [[networking:dns|DNS Explained]] 
-  * [[networking:recursive-authoritative|Recursive vs Authoritative DNS]] 
-  * [[networking:dns_propagation|DNS Propagation]] 
-  * [[tools:dnscheck|DNS Check]] 
- 
------ 
- 
-{{tag>dns dnssec dnskey ds rrsig nsec doh dot security}} 
networking/dnssec.1784734546.txt.gz · Last modified: by 127.0.0.1 · Currently locked by: 216.73.217.88