3 ms·
Broad DNSSEC adoption would have to include NSEC, which is needed to authenticate that the resource does indeed not exist. More on NSEC here: "All records are
by SnowLprd 14y ago
Broad DNSSEC adoption would have to include NSEC, which is needed to authenticate that the resource does indeed not exist. More on NSEC here:
"All records are signed offline. When a nameserver receives a query it looks up the answer plus the signature and returns the two (RRSIG + RRset) to the resolver. The signature is thus not created in real time. How can a secure-aware nameserver then respond to a query for something it does not know (that is, give an NXDOMAIN answer)? The only way to have offline signing and NXDOMAIN answers work together is to somehow sign the data you do not have.
In DNSSEC this is accomplished by the Next SECure (NSEC) record. This NSEC record holds information about the next record; it spans the nonexistence gaps in a zone, so to say."
Source: https://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_7-2/dnssec.html https://www.cisco.com/web/about/ac123/ac147/archived_issues/...
- tptacek 14y agoThis is outdated information. The NSEC record did confirm the nonexistence of DNS names. It also confirmed the identity of every record in your zone; in other words, it allowed anyone in the world to dump your whole zone. The namedroppers working group eventually conceded that, no, it wasn't OK to disclose every domain name signed under DNSSEC; that, for instance, virtually every large enterprise in the world had made a practice of setting up dual-facing DNS so that the world only saw a preapproved subset of their name. And so we got the NSEC3 protocol, which uses a hashing scheme similar to Unix password files. So now, instead of directly dumping domains, attackers get to crack them. Daniel J. Bernstein has a couple presentations about how easy this is. DNSSEC is a bit of a debacle.
- SnowLprd 14y agoIt does indeed seem that way, unfortunately. Is too optimistic to think a better standard might emerge?