Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| opennic:dnssec [2018-04-18T23:28:38Z] – add powerdns jonaharagon | opennic:dnssec [2026-04-29T17:49:34Z] (current) – update current keys and samples joestr1 | ||
|---|---|---|---|
| Line 16: | Line 16: | ||
| <file - named.conf.keys> | <file - named.conf.keys> | ||
| - | trusted-keys { | + | trust-anchors |
| - | . 257 3 8 "AwEAAaq+qqsdDHByq/ | + | . initial-key |
| - | | + | |
| - | Vfcovlx/ | + | |
| - | | + | I5yvU+5g+jVcjUsGwFn6xmuJC0Z33ABKsC8b1cjfcnvE4wP3CrXOlDQ+ |
| - | | + | |
| - | IEIRWcbdWN1FiCdy3L8CaHbZcttzx5lLOGrjPW+raXn+ | + | 0uS1beekejnttMsC4SHMCsiwMvigW2O54ByhzijU2v87d7U9WEMVfPvO |
| - | KaQSU+WW9n2PPOZbNUrQnsW/DJ+b+soNQQbhwFlp/ | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | XnTnJiR/yylhcE8rjPUtnf29NyDN7Co9JzPwnwE74F3k | + | BE7ff+Jkq7OMjTHjFhYivkJSv+8LEbkGjWoaMAS2CT3/ZVMYLiQn8THi |
| - | | + | ZUBF+aOzJMw0EGPag1Qq4vfGgFkQMM3hOaH6bWN1yCvmspuiwLYkNCZZ |
| - | | + | /l8ThKc57bGYy9TX"; |
| - | +Z44zrIP4CtNa0fL0AwJ/ | + | |
| - | | + | |
| - | | + | |
| }; | }; | ||
| </ | </ | ||
| Line 39: | Line 37: | ||
| > | > | ||
| > < | > < | ||
| - | dig DNSKEY . @45.56.116.224 +short | + | dig DNSKEY . @195.201.99.61 +short |
| </ | </ | ||
| > < | > < | ||
| - | 256 3 8 AwEAAaZnbL4yf5OZKLi/tjNBLKUwLuxhyvhildx0Efb/nMlRrCgafhCD 8A8tZkQLMQjQDu5Uckk/M1wCY5U8A9yvOapWMHx3S9dnFSvp4CFWitvo QYDJIMMooNGdYpljzKtR52wPdUpcqvSRwpp9a4gsoEx/r4jY9vyrT/SO 7yQuhh4uVKtZeHcXl/w2V14zVNUBoDl3SlSYIkVBa2HzponOsDlqJN6V QbZQ4mbvpnvbWOq55E/1pzIIrwp0X2VxSunhU/sGKpfiW9c5O6mPwUGl 1NDeYzycNKGy2Nsx4p4nkN43rRwjDBtD4CSUiTwtsMFTF5xKAbuUgSds BAQMyTnokYs= | + | 256 3 8 AwEAAeXw6/FhGTrrrowgiK/4mWwP76JM/Np6FwHmQ+Qn73wdOWT0d189 gkNeVNTVyQNU+q+MBnJ01OFbgQqsey6pd2OjAD5i8pDqZz/0zS7z70Uv eScfqLv08n8qoZOsv7QhytVE9qGqfXgeeGPUctOeqfdlJN/NXnU7crBT 6AxLg1FChV1m3dOcJwCW72XPi/Mbo9dsJSgbWZmVGCILBEQjVa13K4lt roHibq/1kUvmei0TLpzDpwu9OG3m50tAa+JTyId2vqopbCqEk2rQspQ/ TbewkG2jF7TRvDZbRje8Z2eA2HLW3ClrlIFBcyv/ |
| - | 257 3 8 AwEAAaq+qqsdDHByq/DFR5/ | + | 257 3 8 AwEAAbtbsu+wl3fbEDbgvMgJ1BDXeAk5t6BU7B1KGVvc13zMJtjvarxp WWrAb7fmWERX8kJawa3KpYty0EDFQ24nfQyhwEOld442ca89u4/ZU3jP uwKohbGn55vIQ7KjCIrDNvRYjGVn2MNwZnL4WVVclJYsa1cGwVQ9t575 I5yvU+5g+jVcjUsGwFn6xmuJC0Z33ABKsC8b1cjfcnvE4wP3CrXOlDQ+ Er4uPUtMKrmG+Sj1Bm5U+do78mwEXOlTz/sNj8tkpL0pYB2j+XNaDVrO 0uS1beekejnttMsC4SHMCsiwMvigW2O54ByhzijU2v87d7U9WEMVfPvO 6gearg1fo/1Tk4buzPZcS+W9WZgFAt7kT1ois3x0GGT7J55zENB9IZU4 tMmWdYbZJOZsdAzmshuWJIUlTZdNN5671Rhc6P9TWnMlvb9iNT7G3DZ9 PhBw1OF/OmmXobv3Wygbt5+u7q2CPPzwU4WTGpVNtr3Iry2SPW3XVpJS M3+nW7LfxxtWZJlN4MDQYC5IptU+A5EO80/yE38E9tKGDWC1+Nw59QLa BE7ff+Jkq7OMjTHjFhYivkJSv+8LEbkGjWoaMAS2CT3/ZVMYLiQn8THi ZUBF+aOzJMw0EGPag1Qq4vfGgFkQMM3hOaH6bWN1yCvmspuiwLYkNCZZ |
| </ | </ | ||
| Line 78: | Line 76: | ||
| <file lua config.lua> | <file lua config.lua> | ||
| - | addDS(' | + | addDS(' |
| </ | </ | ||
| Line 98: | Line 96: | ||
| < | < | ||
| dnssec | dnssec | ||
| - | trust-anchor=., | + | trust-anchor=., |
| - | trust-anchor=., | + | |
| </ | </ | ||
| + | |||
| + | ==== Unbound ==== | ||
| + | |||
| + | 1. Generate the ''/ | ||
| + | |||
| + | < | ||
| + | dig @195.201.99.61 . DNSKEY | dnssec-dsfromkey -2 -f - . > / | ||
| + | </ | ||
| + | |||
| + | 2. Edit ''/ | ||
| + | |||
| + | < | ||
| + | auto-trust-anchor-file: | ||
| + | </ | ||
| + | |||
| + | 3. Restart Unbound: '' | ||
| ===== Testing DNSSEC ===== | ===== Testing DNSSEC ===== | ||
| Line 107: | Line 120: | ||
| < | < | ||
| - | root@nyc3:~# dig pir.org +dnssec +multi @167.99.153.82 | + | root@korridor:~# dig pir.org +dnssec +multi @46.102.156.180 |
| - | ; <<>> | + | ; <<>> |
| ;; global options: +cmd | ;; global options: +cmd | ||
| ;; Got answer: | ;; Got answer: | ||
| - | ;; ->> | + | ;; ->> |
| - | ;; flags: qr rd ra ad; QUERY: 1, ANSWER: | + | ;; flags: qr rd ra ad; QUERY: 1, ANSWER: |
| ;; OPT PSEUDOSECTION: | ;; OPT PSEUDOSECTION: | ||
| - | ; EDNS: version: 0, flags: do; udp: 4096 | + | ; EDNS: version: 0, flags: do; udp: 65494 |
| + | ; COOKIE: 641abe6c795889030100000069f2434e9c48eb04cf870e99 (good) | ||
| ;; QUESTION SECTION: | ;; QUESTION SECTION: | ||
| - | ; | + | ;pir.org. IN A |
| ;; ANSWER SECTION: | ;; ANSWER SECTION: | ||
| - | pir.org. | + | pir.org. 299 IN A 141.193.213.20 |
| - | pir.org. | + | pir.org. 299 IN A 141.193.213.21 |
| - | | + | pir.org. 299 IN RRSIG A 5 2 300 ( |
| - | | + | 20260512204001 20260428204001 42621 pir.org. |
| - | itT5fJZjRypVJLfZrU73ng5J86dJCFEREk2k6I1lhmno | + | FnApY4+UtOcd3InElCd8W9+q8koa8vw5qt68ZETv+EcN |
| - | | + | ZnTzUm2qW+9AqE7R0YfS2ZBs9c9fn65CuFsRr+ynEyI/ |
| - | | + | OyekiTuLZhmgZjLR5bSlUi1dGPA0G1EUdBrZvaxJGb3z |
| + | UYcjWXGoi6zhX7vqzuFwJ0VN7B0aYhQnyvU+0v8= ) | ||
| - | ;; Query time: 4 msec | + | ;; Query time: 735 msec |
| - | ;; SERVER: | + | ;; SERVER: |
| - | ;; WHEN: Mon Apr 16 19:46:05 UTC 2018 | + | ;; WHEN: Wed Apr 29 19:43:42 CEST 2026 |
| - | ;; MSG SIZE rcvd: 21 | + | ;; MSG SIZE rcvd: 263 |
| </ | </ | ||
| Line 138: | Line 153: | ||
| < | < | ||
| - | root@nyc3:~# dig dnssec-failed.org +dnssec +multi @167.99.153.82 | + | root@korridor:~# dig dnssec-failed.org +dnssec +multi @46.102.156.180 |
| - | ; <<>> | + | ; <<>> |
| ;; global options: +cmd | ;; global options: +cmd | ||
| ;; Got answer: | ;; Got answer: | ||
| - | ;; ->> | + | ;; ->> |
| ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 | ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 | ||
| ;; OPT PSEUDOSECTION: | ;; OPT PSEUDOSECTION: | ||
| - | ; EDNS: version: 0, flags: do; udp: 4096 | + | ; EDNS: version: 0, flags: do; udp: 65494 |
| + | ; COOKIE: dd4e47674a1c21f40100000069f24389ffb0f254c877cb94 (good) | ||
| ;; QUESTION SECTION: | ;; QUESTION SECTION: | ||
| - | ; | + | ; |
| - | ;; Query time: 1029 msec | + | ;; Query time: 1555 msec |
| - | ;; SERVER: | + | ;; SERVER: |
| - | ;; WHEN: Mon Apr 16 19:48:04 UTC 2018 | + | ;; WHEN: Wed Apr 29 19:44:41 CEST 2026 |
| - | ;; MSG SIZE rcvd: 46 | + | ;; MSG SIZE rcvd: 74 |
| </ | </ | ||
| Line 160: | Line 176: | ||
| < | < | ||
| - | root@nyc3:~# dig google.com +dnssec +multi @167.99.153.82 | + | root@korridor:~# dig google.com +dnssec +multi @46.102.156.180 |
| - | ; <<>> | + | ; <<>> |
| ;; global options: +cmd | ;; global options: +cmd | ||
| ;; Got answer: | ;; Got answer: | ||
| - | ;; ->> | + | ;; ->> |
| ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 | ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 | ||
| ;; OPT PSEUDOSECTION: | ;; OPT PSEUDOSECTION: | ||
| - | ; EDNS: version: 0, flags: do; udp: 4096 | + | ; EDNS: version: 0, flags: do; udp: 1232 |
| + | ; COOKIE: 19b6c445faa8b2370100000069f2442a56ff0168fadfb041 (good) | ||
| ;; QUESTION SECTION: | ;; QUESTION SECTION: | ||
| - | ; | + | ; |
| ;; ANSWER SECTION: | ;; ANSWER SECTION: | ||
| - | google.com. | + | google.com. 285 IN A 142.251.38.142 |
| - | ;; Query time: 2 msec | + | ;; Query time: 3 msec |
| - | ;; SERVER: | + | ;; SERVER: |
| - | ;; WHEN: Mon Apr 16 19:48:56 UTC 2018 | + | ;; WHEN: Wed Apr 29 19:47:22 CEST 2026 |
| - | ;; MSG SIZE rcvd: 55 | + | ;; MSG SIZE rcvd: 83 |
| </ | </ | ||