DNSSEC

From ArchWiki
Revision as of 21:14, 31 July 2010 by Harvie (Talk | contribs) (Howto enable DNSSEC in specific software)

Jump to: navigation, search

Tango-document-new.pngThis article is a stub.Tango-document-new.png

Notes: please use the first argument of the template to provide more detailed indications. (Discuss in Talk:DNSSEC#)

Facts

DNSSEC Packages

  • dnssec-root-zone-trust-anchors http://aur.archlinux.org/packages.php?ID=39315
    • essential package contains keys to internet stored in /usr/share/dnssec-trust-anchors/
    • VERY important!
  • ldns http://aur.archlinux.org/packages.php?ID=18996
    • DNS(SEC) library libldns
    • drill tool (like dig with DNSSEC support)
      • can be used for basic DNSSEC validation. eg.:
        • Should success (return 0):
          • drill -TD nic.cz #valid DNSSEC key
          • drill -TD google.com #not signed domain
        • Should fail (simulating fraudent DNS records):
          • drill -TD rhybar.cz
          • drill -TD badsign-a.test.dnssec-tools.org
        • to use root-zone trust anchor add option -k /usr/share/dnssec-trust-anchors/root-zone.key
  • dnssec-tools https://www.dnssec-tools.org/ (package not yet)
    • another good library libval which can add DNSSEC support to lots of programs
  • openssh-dnssec http://aur.archlinux.org/packages.php?ID=39296
    • see lower on this page
  • sshfp http://aur.archlinux.org/packages.php?ID=29185
    • Generates DNS SSHFP-type records from SSH public keys from public keys from a known_hosts file or from scanning the host's sshd daemon.
    • not directly related to DNSSEC, but i guess this will become very popular because of DNSSEC

Howto enable DNSSEC in specific software

OpenSSH

Firefox

Postfix (fight spam and frauds)

  • dnssec-tools + patch

jabberd

  • dnssec-tools + patch

Thunderbird

  • dnssec-tools + patch

lftp

  • dnssec-tools + patch

wget

  • dnssec-tools + patch

proftpd

  • dnssec-tools + patch

Sendmail

  • dnssec-tools + patch

LibSPF

  • dnssec-tools + patch

ncftp

  • dnssec-tools + patch