Key takeaways
- DNSSEC is not encryption: it adds digital signatures that guarantee the authenticity and integrity of DNS answers. Queries stay readable on the wire, but cache poisoning becomes detectable.
- The key hierarchy comes down to three objects: the ZSK signs the zone records, the KSK only signs the ZSK, and the DS record is a hash of the KSK published at your registrar to hook the zone into the global chain of trust.
- On the BIND9 side, three directives are enough in the zone declaration:
inline-signing yes,auto-dnssec maintainandkey-directory. BIND then generates the keys and signs the zone on its own, with no zone file surgery. - The DS record is extracted with
dnssec-dsfromkey -2against the KSK.keyfile. You must carry the four values over to the registrar: key tag, algorithm, digest type and the digest itself. - Validation is checked with
dig +dnssec: the ad (Authenticated Data) flag in the header means the resolver verified the signature. ZSK rollover is automatic, KSK rollover stays manual because it requires a new DS at the registrar, typically every 1 to 2 years.
DNSSEC (Domain Name System Security Extensions) is a technology that strengthens authentication in the DNS by using digital signatures. It allows a DNS client to verify that the responses it receives from a DNS server are authentic and have not been tampered with. It does not encrypt queries, but it guarantees their integrity.
Why use DNSSEC?
The DNS was designed without security. An attacker can intercept a DNS query and return a fake IP address, redirecting a user to a malicious site. This is known as DNS cache poisoning. DNSSEC prevents this type of attack.
Prerequisites
- A working BIND9 DNS server, acting as master for a zone (e.g. `example.com`).
- Root access or sudo privileges.
- Your domain name registrar must support DNSSEC so you can publish your keys.
Premium Content
This advanced tutorial is reserved for premium members.
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime