Download presentation
Presentation is loading. Please wait.
1
DNSSEC Status Update in UA
Dmitry Kohmanyuk Feb 7, 2012
2
Zone UA Key Generation Ceremony
December 2, 2011 Key parameters: RSASHA512 (algorithm 10) KSK bits: ZSK bits: 1024
3
Test zone UA.UA Zone UA.UA signed, keys in DLV (dlv.isc.org) UA has DS records for ua.ua and rovno.ua Test web site (can use Firefox plugin to verify)
4
Zone UA DNSSEC Tested Test signing environment running: BIND 9.8 NSEC3 (with opt-out)
5
Public server with signed UA for testing
ho1.ua.ua :67c:258::17 Test anchor: ua. IN DS B5F97978F45398C9C EA3AB4A882011DCAA4F D D58FE2AD This is not a production zone, use as your own risk (but NS records are same)
6
Public resolver with enabled DNSSEC validation
lh.cctld.ua :7f8:55:7::71
7
What next Using production keys and signer DS publication in root zone Profit!
8
Questions? Whois.ua
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.