networking:dnssec
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| networking:dnssec [2026/07/22 19:46] – external edit 127.0.0.1 | networking:dnssec [2026/07/22 20:46] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== DNSSEC Explained ====== | ||
| - | **DNS Security Extensions (DNSSEC)** is a set of extensions to the Domain Name System (DNS) that allows DNS responses to be **cryptographically verified**. | ||
| - | |||
| - | DNSSEC helps ensure that DNS records have not been modified or forged while they travel across the Internet. | ||
| - | |||
| - | DNSSEC provides: | ||
| - | |||
| - | * Data authenticity | ||
| - | * Data integrity | ||
| - | * Protection against DNS spoofing and cache poisoning | ||
| - | |||
| - | DNSSEC **does not** provide encryption or privacy. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Why Was DNSSEC Created? ===== | ||
| - | |||
| - | Traditional DNS was designed without security. | ||
| - | |||
| - | An attacker may attempt to convince a recursive resolver that a fake IP address belongs to a domain. | ||
| - | |||
| - | Example: | ||
| - | |||
| - | < | ||
| - | Attacker | ||
| - | |||
| - | example.com | ||
| - | │ | ||
| - | ▼ | ||
| - | |||
| - | 203.0.113.200 | ||
| - | |||
| - | instead of | ||
| - | |||
| - | 93.184.216.34 | ||
| - | </ | ||
| - | |||
| - | If the resolver accepts the forged response, users may be redirected to a malicious website. | ||
| - | |||
| - | DNSSEC prevents this by allowing DNS responses to be digitally signed. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== How DNSSEC Works ===== | ||
| - | |||
| - | Each DNS zone has a pair of cryptographic keys. | ||
| - | |||
| - | * Private Key | ||
| - | * Public Key | ||
| - | |||
| - | The authoritative DNS server signs its DNS records using the private key. | ||
| - | |||
| - | Resolvers verify the signatures using the corresponding public key. | ||
| - | |||
| - | < | ||
| - | Authoritative Server | ||
| - | |||
| - | DNS Record | ||
| - | │ | ||
| - | ▼ | ||
| - | Digital Signature | ||
| - | │ | ||
| - | ▼ | ||
| - | Recursive Resolver | ||
| - | │ | ||
| - | Verify Signature | ||
| - | │ | ||
| - | ▼ | ||
| - | Trusted Answer | ||
| - | </ | ||
| - | |||
| - | If verification fails, the resolver rejects the response. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Chain of Trust ===== | ||
| - | |||
| - | DNSSEC works through a **chain of trust**. | ||
| - | |||
| - | Each level of the DNS hierarchy signs the next level. | ||
| - | |||
| - | < | ||
| - | Root Zone | ||
| - | │ | ||
| - | ▼ | ||
| - | .com | ||
| - | │ | ||
| - | ▼ | ||
| - | example.com | ||
| - | </ | ||
| - | |||
| - | The root zone is the trust anchor for the entire DNSSEC system. | ||
| - | |||
| - | If every signature is valid, the resolver can trust the final DNS record. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== DNSSEC Record Types ===== | ||
| - | |||
| - | DNSSEC introduces several additional DNS record types. | ||
| - | |||
| - | ^ Record ^ Purpose ^ | ||
| - | | **DNSKEY** | Public key for the DNS zone | | ||
| - | | **DS** | Delegation Signer (links parent and child zones) | | ||
| - | | **RRSIG** | Digital signature for DNS records | | ||
| - | | **NSEC** | Authenticated proof that a record does not exist | | ||
| - | | **NSEC3** | Similar to NSEC, but hides zone contents | | ||
| - | | **CDS** | Child Delegation Signer (automation) | | ||
| - | | **CDNSKEY** | Child DNSKEY (automation) | | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== DNSSEC Validation ===== | ||
| - | |||
| - | When a resolver receives a DNS response, it performs validation. | ||
| - | |||
| - | Steps: | ||
| - | |||
| - | - Retrieve the requested DNS record. | ||
| - | - Retrieve its RRSIG record. | ||
| - | - Retrieve the DNSKEY. | ||
| - | - Verify the signature. | ||
| - | - Verify the chain of trust up to the root zone. | ||
| - | |||
| - | If validation succeeds, the response is accepted. | ||
| - | |||
| - | Otherwise the resolver returns an error. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== DNSSEC Does NOT Encrypt DNS ===== | ||
| - | |||
| - | A common misconception is that DNSSEC encrypts DNS traffic. | ||
| - | |||
| - | It does not. | ||
| - | |||
| - | DNSSEC provides: | ||
| - | |||
| - | * Authentication | ||
| - | * Integrity | ||
| - | |||
| - | It does **not** provide: | ||
| - | |||
| - | * Confidentiality | ||
| - | * Privacy | ||
| - | * Encryption | ||
| - | |||
| - | DNS queries remain visible on the network. | ||
| - | |||
| - | For encrypted DNS, technologies such as **DNS over HTTPS (DoH)** and **DNS over TLS (DoT)** are used. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== DNSSEC vs DoH vs DoT ===== | ||
| - | |||
| - | ^ Technology ^ Authentication ^ Encryption ^ | ||
| - | | DNS | No | No | | ||
| - | | DNSSEC | Yes | No | | ||
| - | | DNS over TLS (DoT) | No | Yes | | ||
| - | | DNS over HTTPS (DoH) | No | Yes | | ||
| - | | DNSSEC + DoH | Yes | Yes | | ||
| - | |||
| - | DNSSEC and DoH solve different security problems and are often used together. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Advantages ===== | ||
| - | |||
| - | DNSSEC provides: | ||
| - | |||
| - | * Protection against cache poisoning | ||
| - | * Protection against forged DNS responses | ||
| - | * Verification that DNS records originate from the authoritative server | ||
| - | * Increased trust in DNS infrastructure | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Limitations ===== | ||
| - | |||
| - | DNSSEC does not: | ||
| - | |||
| - | * Hide DNS queries. | ||
| - | * Encrypt DNS traffic. | ||
| - | * Prevent DDoS attacks. | ||
| - | * Protect websites against compromise. | ||
| - | |||
| - | It only verifies the authenticity of DNS data. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== How Can I Check Whether a Domain Uses DNSSEC? ===== | ||
| - | |||
| - | A domain usually supports DNSSEC if: | ||
| - | |||
| - | * A **DS** record exists in the parent zone. | ||
| - | * The zone publishes **DNSKEY** records. | ||
| - | * DNS responses contain **RRSIG** records. | ||
| - | |||
| - | Example: | ||
| - | |||
| - | < | ||
| - | example.com | ||
| - | |||
| - | DNSKEY | ||
| - | RRSIG | ||
| - | DS | ||
| - | </ | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== DNSSEC and Telenegar ===== | ||
| - | |||
| - | Telenegar DNS Check can help determine whether a domain supports DNSSEC by: | ||
| - | |||
| - | * Querying DNSSEC-related record types. | ||
| - | * Displaying DNSKEY records. | ||
| - | * Displaying DS records. | ||
| - | * Displaying RRSIG records. | ||
| - | * Indicating whether DNSSEC appears to be enabled. | ||
| - | |||
| - | Future versions may also perform DNSSEC validation. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Common Misconceptions ===== | ||
| - | |||
| - | * **DNSSEC encrypts DNS traffic.** | ||
| - | * False. DNSSEC only authenticates DNS data. | ||
| - | |||
| - | * **DNSSEC prevents every DNS attack.** | ||
| - | * False. It prevents forged DNS responses but not every attack. | ||
| - | |||
| - | * **DoH replaces DNSSEC.** | ||
| - | * False. DNSSEC and DoH provide different security properties. | ||
| - | |||
| - | ----- | ||
| - | |||
| - | ===== Related Topics ===== | ||
| - | |||
| - | * [[networking: | ||
| - | * [[networking: | ||
| - | * [[networking: | ||
| - | * [[tools: | ||
| - | |||
| - | ----- | ||
| - | |||
| - | {{tag> | ||
networking/dnssec.1784749579.txt.gz · Last modified: by 127.0.0.1 · Currently locked by: 216.73.217.88
