[Dnssec-deployment] dnssec deployment for ccTLD

Dan York york at isoc.org
Tue May 8 09:59:05 EDT 2012


Shidiq,

In addition to all the excellent references Phil just mentioned, you may want to look at the detailed DNSSEC deployment document from SURFnet:

https://dnssec.surfnet.nl/?p=675

We also have a range of DNSSEC tutorials and resources at Deploy360:

http://www.internetsociety.org/deploy360/dnssec/

The DNSSEC HOWTO from NLNet Labs may be of use to you:

http://www.nlnetlabs.nl/publications/dnssec_howto/

And the Internet2 DNSSEC SIG also has a page up listing many resources:

https://spaces.internet2.edu/display/DNSSEC/Internet2+DNSSEC+SIG

On your specific request about a step-by-step tutorial for a ccTLD, that's one of the documents I've identified that I'd like to see us add to the tutorials at Deploy360.  If you are interested in being part of creating such a tutorial, I'd be interested to work with you as you move through the process to document the steps you are taking.  Please drop me an email directly if you are interested.

As Phil noted, one way to learn may be to look at what other TLDs many of them have posted "DNSSEC Policy & Practice Statements" (DPS). The folks at .SE have one up at:

https://www.iis.se/dl/DPS-PA9-ENG.pdf

and the .NL DPS is at:

https://www.sidn.nl/fileadmin/docs/PDF-files_UK/DNSSEC%20Policy%20and%20Practice%20Statement.pdf

Many others can be found out there.

Regards,
Dan

P.S. If anyone else is aware of a specific step-by-step tutorial for a TLD, I, too, would love to hear about it.

--
Dan York
Senior Content Strategist, Internet Society
york at isoc.org   +1-802-735-1624 
Jabber: york at jabber.isoc.org 
Skype: danyork   http://twitter.com/danyork

http://www.internetsociety.org/deploy360/

On May 8, 2012, at 6:09 AM, Phil Regnauld wrote:

> shidiq (shidiq) writes:
>> Hi All,
>> 
>> where i can get information (step by step, requirements etc) from
>> deployment dnssec for ccTLD.
> 
> Hello Shidiq,
> 
> Would you have more details about what you're trying to achieve ? There
> are a few aspects to consider.
> 
> Signing the zone for a ccTLD is no different technically from
> signing any other top-level zone, or any DNS zone for that matter.
> 
> It will differ mainly in the type of data you are signing: top level
> and ccTLD zones typically contain many NS records (so called delegation
> centric zones) and very little "data" to speak off (A, CNAME, MX, ...).
> 
> Also, as a ccTLD or top level zone, delegation holders must be able
> to submit Delegation Signer records (hashes of their public key signing
> keys) for inclusion into the zone.
> 
> There are several good guides out there to getting started with DNSSEC:
> 
> https://www.dnssec-deployment.org/index.php/presentations-events-and-newsletters/deployment-guidlines/
> 
> ... and (plug!) you may want to check out the recent DNS/DNSSEC deployment
> workshop we (NSRC) ran at MENOG 10 in Dubai last month.
> 
> https://nsrc.org/workshops/2012/menog-dns-dnssec/wiki
> https://nsrc.org/workshops/2012/menog-dns-dnssec/wiki/Agenda
> 
> This includes guides for signing with both BIND and OpenDNSSEC, and
> some rather useful presentations by Rick Lamb from ICANN on key
> management and ceremonies.
> 
> Also, the FCC has recently published a DNSSEC deployment guide for
> ISPs:
> 
> http://transition.fcc.gov/bureaus/pshs/advisory/csric3/CSRIC-III-WG5-Final-Report.pdf
> 
> Requirements vary, but it also depends on what your policy is. You may
> want to start looking at what other countries such as .NZ have been doing
> there:
> 
> http://nzrs.net.nz/dns/dnssec/dps
> 
> http://dnc.org.nz/story/consultation-dnssec-implementation
> 
> Don't hesitate to write back here, as I'm sure the awesome folks on this list 
> can help you with your questions!
> 
> Cheers,
> Phil Regnauld
> Network Startup Resource Center

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://dnssec-deployment.org/pipermail/dnssec-deployment/attachments/20120508/61edd58d/attachment.html 


More information about the Dnssec-deployment mailing list