KSK Rollover Update David Conrad, CTO ICANN 59 – GAC 29 June 2017.

Slides:



Advertisements
Similar presentations
Mobile phone based real time solution to track completed / in progress work The programme officer initiates the work by capturing the site image, GPS.
Advertisements

Deploying DNSSEC in Windows Server 2012 David Cates Platform Services Group Microsoft Corporation.
DNSSEC & Validation Tiger Team DHS Federal Network Security (FNS) & Information Security and Identity Management Committee (ISIMC) Earl Crane Department.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Information Networking Security and Assurance Lab National Chung Cheng University 1 Top Vulnerabilities in Web Applications (I) Unvalidated Input:  Information.
© Afilias Limitedwww.afilias.info SM Challenges of Deploying DNSSEC: Prepare your ccTLD with Secondary DNS services LACNIC Meeting May 2010 Presented by:
Deploying DNSSEC in Windows Server 2012 Rob Kuehfus Program Manager Microsoft Corporation WSV325.
Domain Name System | DNSSEC. 2  Internet Protocol address uniquely identifies laptops or phones or other devices  The Domain Name System matches IP.
Why Johnny Can’t Encrypt A Usability Evaluation of GPG 5.0 Presented by Yin Shi.
Tyre Kicking the DNS Testing Transport Considerations of Rolling Roots Geoff Huston APNIC.
Lecture 23 Internet Authentication Applications modified from slides of Lawrie Brown.
© 2015 ISC November 2013 Sunset for the DLV?. © 2015 ISC Background (c) Interested
Certificate-Based Operations. Module Objectives By the end of this module participants will be able to: Define how cryptography is used to secure information.
International Telecommunication Union ENUM Implementation Robert Shaw ITU Internet Strategy and Policy Advisor International Telecommunication Union ICANN.
Root Zone KSK: The Road Ahead Edward Lewis | DNS-OARC & RIPE DNSWG | May 2015
Milestone SAP Portal Learning at the Lakes August 12, 2009.
© 2004 VeriSign, Inc. RAPID GROWTH: LESSONS LEARNED FROM.COM/.NET VeriSign Bart Mackay February 2005.
DNSSEC-Deployment.org Secure Naming Infrastructure Pilot (SNIP) A.gov Community Pilot for DNSSEC Deployment JointTechs Workshop July 18, 2007 Scott Rose.
1 DNSSEC Transforming a protocol bug into an admin tool Lutz Donnerhacke db089309: 1c1c 6311 ef09 d819 e029 65be bfb6 c9cb.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
By Team Trojans -1 Arjun Ashok Priyank Mohan Balaji Thirunavukkarasu.
Root Zone KSK Maintenance Jaap Akkerhuis | ENOG -10 | October 2015.
Root Zone KSK: After 5 years Elise Gerich | APNIC 40 | September 2015.
1 eSchoolPLUS User Group Meeting March 17, Agenda Regional Active Directory Summer Project Schoology Integration with eSchoolPLUS Process for.
Rolling the Root Geoff Huston APNIC Labs March 2016.
Increasing the Zone Signing Key Size for the Root Zone
TAG Presentation 18th May 2004 Paul Butler
Chapter 40 Internet Security.
Trust Profiling for Adaptive Trust Negotiation
Security Issues with Domain Name Systems
Rolling the Root Zone DNSSEC Key Signing Key
KSK Rollover Update David Conrad, CTO ICANN 59 – ccNSO Members Meeting
A longitudinal, End-to-End View of the DNSSEC Ecosystem
SaudiNIC Riyadh, Saudi Arabia May 2017
DNS Team IETF 99 Hackathon.
IT443 – Network Security Administration Instructor: Bo Sheng
Community Session - Next-Generation gTLD Registration Directory Service (RDS) to replace WHOIS
Root Zone KSK Rollover: delay and next steps
TAG Presentation 18th May 2004 Paul Butler
Cybersecurity and Governance
Geoff Huston APNIC Labs September 2017
Root Zone KSK Rollover Update
GAC Website Beta Demo 18 April 2017.
draft-huston-kskroll-sentinel
DANE: The Future of Transport Layer Security (TLS)
A Longitudinal, End-to-End View of the DNSSEC Ecosystem
R. Kevin Oberman ESnet February 5, 2009
Unit 1.4 Wired and Wireless Networks Lesson 1
A high-tech accounting software, QuickBooks is a highly trusted software by small and medium sized business. It streamlines accounting processes of a.
ICANN62 GAC Capacity Building
TRA, UAE May 2017 DNSSEC Introduction TRA, UAE May 2017
Managing Name Resolution
.edu DNSSEC Testbed Lessons Learned
Martus Account Set Up Benetech is a non-profit organization that develops and supports Martus, a secure information management software for human rights.
GAC Underserved Regions Working Group Meeting
Finance Presentations
Root KSK Roll Update DNS-OARC 27 Matt Larson, VP of Research
What DNSSEC Provides Cryptographic signatures in the DNS
Network Security – Kerberos
Measuring KSK Roll Readiness
Geoff Huston APNIC Labs
Measuring KSK Roll Readiness
DNS operator transfers with DNSSEC
DNSSEC & KSK Rollover Patrick Jones Middle East DNS Forum & APTLD 75
Welcome to the .vu ccTLD news
DNSSEC Status Update in UA
Computer Networks Presentation
The Curious Case of the Crippling DS record
Trust Anchor Signals from Custom Applications
Presentation transcript:

KSK Rollover Update David Conrad, CTO ICANN 59 – GAC 29 June 2017

KSK Rollover: An Overview ICANN is in the process of performing a Root Zone DNS  Security Extensions (DNSSEC) Key Signing Key (KSK) rollover The Root Zone DNSSEC Key Signing Key “KSK” is the top most cryptographic key in the DNSSEC hierarchy The KSK is a cryptographic public-private key pair: Public part: trusted starting point for DNSSEC validation Private part: signs the Zone Signing Key (ZSK) Builds a “chain of trust” of successive keys and signatures to validate the authenticity of any DNSSEC signed data DATA This is a stylized agenda slide for your presentation. To delete a box, if there are too many boxes, click the edge of the box, ensure the entire box is highlighted, then DELETE. To update the numbers and text, click inside the circle for the numbers or in the box for the text, revise the text.

Why is ICANN Rolling the KSK? As with passwords, the cryptographic keys used in DNSSEC- signing DNS data should be changed periodically Ensures infrastructure can support key change in case of emergency This type of change has never before occurred at the root level There has been one functional, operational Root Zone DNSSEC KSK since 2010 The KSK rollover must be widely and carefully coordinated to ensure that it does not interfere with normal operations

When Does the Rollover Take Place? The KSK rollover is a process, not a single event The following dates are key milestones in the process when end users may experience interruption in Internet services: ICANN is executing an extensive outreach campaign to ensure that those who currently use the KSK know about the pending change

Who Will Be Impacted? DNS Software Developers & Distributors System Integrators Network Operators Internet Service Providers End Users (if no action taken by resolver operators) ICANN is executing an extensive outreach campaign to ensure that those who currently use the KSK know about the pending change Root Server Operators

Why You Need to Prepare If you have enabled DNSSEC validation, you must update your systems with the new KSK to help ensure trouble-free Internet access for users Currently, 25 percent of global Internet users, or 750 million people, use DNSSEC-validating resolvers that could be affected by the KSK rollover If these validating resolvers do not have the new key when the KSK is rolled, end users relying on those resolvers will encounter errors and be unable to access the Internet ICANN is executing an extensive outreach campaign to ensure that those who currently use the KSK know about the pending change

What Do Resolver Operators Need to Do? Be aware whether DNSSEC is enabled in your servers Be aware of how trust is evaluated in your operations Test/verify your set ups Make sure trust anchor can be changed Inspect configuration files, are they (also) up to date? If DNSSEC validation is enabled or planned in your system Have a plan for participating in the KSK rollover Know the dates, know the symptoms, solutions This is a stylized agenda slide for your presentation. To delete a box, if there are too many boxes, click the edge of the box, ensure the entire box is highlighted, then DELETE. To update the numbers and text, click inside the circle for the numbers or in the box for the text, revise the text.

Letter to Government Regulators Göran correspondence to government regulators (coped to GAC representatives). Requests help in assuring every Internet service provider or network operator in their country that has enabled DNSSEC validation, update their systems with the new KSK. Requests regulators to contact operators in their country and inquire if they are ready for the KSK rollover. Encourages the use of ICANN’s testing platform so regional operators can confirm their infrastructure can handle the rollover.

Engage with ICANN – Thank You and Questions