From ArchWiki
Revision as of 16:46, 31 July 2010 by Harvie (talk | contribs) (created)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search



  • dnssec-root-zone-trust-anchors http://aur.archlinux.org/packages.php?ID=39315
    • essential package contains keys to internet stored in /usr/share/dnssec-trust-anchors/
    • VERY important!
  • ldns http://aur.archlinux.org/packages.php?ID=18996
    • DNS(SEC) library libldns
    • drill tool (like dig with DNSSEC support)
      • can be used for basic DNSSEC validation. eg.:
        • Should success:
          • drill -TD nic.cz #valid DNSSEC key
          • drill -TD google.com #not signed domain
        • Should fail (simulating fraudent DNS records):
          • drill -TD rhybar.cz
          • drill -TD badsign-a.test.dnssec-tools.org
        • to use root-zone trust anchor add option -k /usr/share/dnssec-trust-anchors/root-zone.key
  • dnssec-tools https://www.dnssec-tools.org/ (package not yet)
    • another good library which can add DNSSEC support to lots of programs
  • openssh-dnssec http://aur.archlinux.org/packages.php?ID=39296
    • DNSSEC (ldns) wrapper for OpenSSH client.
    • instantly adds minimal DNSSEC support to ssh (no SSHFP support).
    • usage: alias ssh=ssh-dnssec