DNSSEC Provisioning for ERX Space Held with APNIC
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear colleagues, APNIC has just enabled support for DNSSEC-enabled delegations for their reverse space. This means that RIPE NCC members with ERX space assignments in the APNIC region can now also make use of DNSSEC. To do so, please submit a domain object which includes the ds-rdata field as you would for any other DNSSEC-enabled delegation. For more information on how to do this, see: http://www.ripe.net/data-tools/dns/dnssec/procedure-for-requesting-dnssec-de... We will enable this service for ERX space held in other RIR regions as soon as DNSSEC becomes available with those RIRs. For more information on ERX space in the RIPE NCC service region, see: http://www.ripe.net/lir-services/resource-management/erx Regards, Wolfgang Nagele DNS Group Manager, RIPE NCC -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.8 (Darwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk3D5+wACgkQjO7G63Byy8eSEACdG1WodVCXlhENcALS3hG83OHs E04AoLIZ8nBrb/95tD2htmrCo45tj3c8 =PJRg -----END PGP SIGNATURE-----
Wolfgang, On Fri, 2011-05-06 at 14:22 +0200, Wolfgang Nagele wrote:
APNIC has just enabled support for DNSSEC-enabled delegations for their reverse space.
This means that RIPE NCC members with ERX space assignments in the APNIC region can now also make use of DNSSEC.
To do so, please submit a domain object which includes the ds-rdata field as you would for any other DNSSEC-enabled delegation.
Very cool. I'm thinking of the case where someone has old space, across several RIRs, and some ERX space can have reverse DNS secured with DNSSEC and some cannot. Does the update check that a given DOMAIN object is actually secure before accepting a "ds-rdata:" field? Or is there any warning or other indication on the reply from the RIPE database? I don't know what the timelines are for the remaining RIRs to implement DNSSEC for the reverse tree, so maybe this is not important. :) Thanks, -- Shane
Hi Shane,
Does the update check that a given DOMAIN object is actually secure before accepting a "ds-rdata:" field? Or is there any warning or other indication on the reply from the RIPE database? There are two things. One is that we only accept the ds-rdata once we have the OK from the RIR receiving that space that they can support it. This is what this announcement was about. So if you would try to submit ERX domain objects for space with for instance AfriNIC the database would refuse the ds-rdata there because AfriNIC does not yet support it.
The other thing is that the delegation checker like for any other delegation checks if the ds-rdata (at least one of them) corresponds to a DNSKEY in that zone. Cheers, W
participants (2)
-
Shane Kerr
-
Wolfgang Nagele