SlideShare una empresa de Scribd logo
1 de 28
Descargar para leer sin conexión
DNS Security
Wolfgang Nagele
DNS Services Manager
DNS: the Domain Name System
    •   Specified by Paul Mockapetris in 1983
    •   Distributed Hierarchical Database
         –   Main purpose: Translate names to IP addresses
         –   Since then: Extended to carry a multitude of
             information (such as SPF, DKIM)
    •   Critical Internet Infrastructure
         –   Used by most systems (in the background)




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   2
DNS Tree Structure




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   3
How does it work?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   4
What is the problem?
    •   UDP transport can be spoofed
         –   Anybody can pretend to originate a response
    •   If a response is modified the user will connect to
        a possibly malicious system




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   5
The Solution
    •   Make the responses verifiable
         –   Cryptographic signatures
    •   Hierarchy exists so a Public Key Infrastructure is
        the logical choice
         –   Same concept as used in eGovernment infrastructures




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   6
How does it work with DNSSEC?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   7
How does it work with DNSSEC?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   8
How does it work with DNSSEC?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   9
How does it work with DNSSEC?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   10
How does it work with DNSSEC?




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   11
DNS Security Extensions: A Long Story
    •   2005: Theoretical problem discovered (Bellovin)
    •   1995: Work on DNSSEC started
    •   1999: First support for DNSSEC in BIND
    •   2005: Standard is redesigned to better meet
              operational needs
               RIPE NCC along with .SE among the
        first to deploy it in their zones



Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   12
DNS Security Extensions
    •   2005 - 2008: Stalled deployments due to the
                     lack of a signed root zone
    •   2008:                            D. Kaminsky shows the practical
                                         use of the protocol weakness
                                         Focus comes back to DNSSEC
    •   July 2010:                       Root Zone signed with DNSSEC
    •   March 2011: 69/306 signed TLDs



Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011        13
DNSSEC and the RIPE NCC
    •   Sponsor development of NSD DNS software
    •   Participated in the “Deployment of Internet
        Security Infrastructure” project
         –   Signed all our DNS zones
               –   IPv4 & IPv6 reverse space
               –   E164.arpa
               –   ripe.net
    •   K-root server readiness for a signed root zone


Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   14
Singing of the Root Zone
    •   Shared custody by Root Zone maintainers
         –   Currently: U.S. DoC NTIA, IANA/ICANN, VeriSign
    •   Split key among 21 Trusted Community
        Representatives
    •   In production since July 2010




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   15
Deployment in ccTLDs: Europe




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   16
Deployment in ccTLDs: Middle East




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   17
Deployment in ccTLDs: Asia Pacfic




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   18
Deployment in ccTLDs




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   19
Deployment in ccTLDs




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   20
Deployment in ccTLDs




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   21
Deployment in gTLDs
    •   .com/.net/.org (57% of world wide total domains)
    •   .asia
    •   .cat
    •   .biz
    •   .edu
    •   .gov
    •   .info
    •   .museum
    •   .mobi (Planned)
Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   22
Deployment in Infrastructure TLD .arpa
    •   E164.arpa
         –   ENUM number mapping
         –   signed by the RIPE NCC
    •   in-addr.arpa
         –   Reverse DNS for IPv4
    •   ip6.arpa
         –   Reverse DNS for IPv6




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   23
Are We Done?
    •   Signed TLD is not the same as a signed domain
         –   Thick registry model (Registry-Registrar-Registrant)
         –   Registrars need to enable their customers to provide
             public key data to registry




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   24
Are We Done?
    •   Ultimately responses should be verified by the
        end user
         –   Home routers need to support DNS specifications with
             large response packets




Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   25
Leverage Infrastructure
    •   DNS is a cross organisational data directory
    •   DNSSEC adds trust to this infrastructure
         –   Anybody can verify data published under ripe.net was
             originated by the domain holder
         –   Could be used to make DKIM and SPF widely used
             and trusted
         –   SSL certificates can be trusted through the DNS
         –   More ideas to come …



Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   26
What about SSL/TLS?
    •   SSL as a transport is well established
    •   CA system currently in use is inherently broken
         –   Any Certificate Authority delivered with a browser to
             date can issue a certificate for any domain
               –   100 and more shipped in every Browser
         –   If any one of them fails - security fails with it
               –   Recent incident with Comodo CA is one example
    •   DANE working group at IETF


Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011   27
Questions?
wnagele@ripe.net

Más contenido relacionado

Destacado (12)

Domain name server
Domain name serverDomain name server
Domain name server
 
Dns
DnsDns
Dns
 
CCNAv5 - S2: Chapter10 DHCP
CCNAv5 - S2: Chapter10 DHCPCCNAv5 - S2: Chapter10 DHCP
CCNAv5 - S2: Chapter10 DHCP
 
Configuration DHCP
Configuration DHCPConfiguration DHCP
Configuration DHCP
 
The Application Layer
The Application LayerThe Application Layer
The Application Layer
 
DHCP Server & Client Presentation
DHCP Server & Client PresentationDHCP Server & Client Presentation
DHCP Server & Client Presentation
 
Basics about IP address, DNS and DHCP.
Basics about IP address, DNS and DHCP.Basics about IP address, DNS and DHCP.
Basics about IP address, DNS and DHCP.
 
Dhcp presentation
Dhcp presentationDhcp presentation
Dhcp presentation
 
Domain name system
Domain name systemDomain name system
Domain name system
 
Dhcp ppt
Dhcp pptDhcp ppt
Dhcp ppt
 
Domain Name System DNS
Domain Name System DNSDomain Name System DNS
Domain Name System DNS
 
DNS - Domain Name System
DNS - Domain Name SystemDNS - Domain Name System
DNS - Domain Name System
 

Similar a DNSSEC - Amsterdam Roundtable 2011

ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...
ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...
ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...Deploy360 Programme (Internet Society)
 
RIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarRIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarMen and Mice
 
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenchesInternet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenchesAPNIC
 
RIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC
 
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무OpenStack Korea Community
 
OSNF - Open Sensor Network Framework
OSNF - Open Sensor Network FrameworkOSNF - Open Sensor Network Framework
OSNF - Open Sensor Network FrameworkAntonio Di Cello
 
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...eNovance
 
Irati fire-engineering-workshop-nov2012
Irati fire-engineering-workshop-nov2012Irati fire-engineering-workshop-nov2012
Irati fire-engineering-workshop-nov2012Eleni Trouva
 
XPDDS18: Xen Project Weather Report 2018
XPDDS18: Xen Project Weather Report 2018XPDDS18: Xen Project Weather Report 2018
XPDDS18: Xen Project Weather Report 2018The Linux Foundation
 
The Future of Networks is Open...Source
The Future of Networks is Open...SourceThe Future of Networks is Open...Source
The Future of Networks is Open...SourceFrancois Duthilleul
 
Have You Driven an SELinux Lately? - An Update on the SELinux Project - OLS ...
Have You Driven an SELinux Lately? - An Update on the SELinux Project -  OLS ...Have You Driven an SELinux Lately? - An Update on the SELinux Project -  OLS ...
Have You Driven an SELinux Lately? - An Update on the SELinux Project - OLS ...James Morris
 

Similar a DNSSEC - Amsterdam Roundtable 2011 (20)

ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...
ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...
ION Santiago: What's Happening at the IETF? Internet Standards and How to Get...
 
RIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarRIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinar
 
ION Malta - IETF Update
ION Malta - IETF UpdateION Malta - IETF Update
ION Malta - IETF Update
 
After summit catch up
After summit catch upAfter summit catch up
After summit catch up
 
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenchesInternet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
Internet Week 2018: 1.1.1.0/24 A report from the (anycast) trenches
 
RIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An UpdateRIPE NCC Tools and Services - An Update
RIPE NCC Tools and Services - An Update
 
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무
[OpenInfra Days Korea 2018] (NetApp) Open Source with NetApp - 전국섭 상무
 
ION Costa Rica - About the IETF and How to Get Involved
ION Costa Rica - About the IETF and How to Get InvolvedION Costa Rica - About the IETF and How to Get Involved
ION Costa Rica - About the IETF and How to Get Involved
 
ION Belgrade - IETF Update
ION Belgrade - IETF UpdateION Belgrade - IETF Update
ION Belgrade - IETF Update
 
OSNF - Open Sensor Network Framework
OSNF - Open Sensor Network FrameworkOSNF - Open Sensor Network Framework
OSNF - Open Sensor Network Framework
 
ION Belfast - IETF Update - Chris Grundemann
ION Belfast - IETF Update - Chris GrundemannION Belfast - IETF Update - Chris Grundemann
ION Belfast - IETF Update - Chris Grundemann
 
ION Islamabad - What's Happening at the IETF?
ION Islamabad - What's Happening at the IETF?ION Islamabad - What's Happening at the IETF?
ION Islamabad - What's Happening at the IETF?
 
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...
OpenStack in Action 4! Daniel Pays & Régis Allègre - Cloudwatt Public Cloud: ...
 
Irati fire-engineering-workshop-nov2012
Irati fire-engineering-workshop-nov2012Irati fire-engineering-workshop-nov2012
Irati fire-engineering-workshop-nov2012
 
OFC 2014 Dinesh Dutt
OFC 2014 Dinesh DuttOFC 2014 Dinesh Dutt
OFC 2014 Dinesh Dutt
 
OpenStack Summit Austin 2016 v1.3
OpenStack Summit Austin 2016 v1.3 OpenStack Summit Austin 2016 v1.3
OpenStack Summit Austin 2016 v1.3
 
Dns firewalls null-may2020
Dns firewalls null-may2020Dns firewalls null-may2020
Dns firewalls null-may2020
 
XPDDS18: Xen Project Weather Report 2018
XPDDS18: Xen Project Weather Report 2018XPDDS18: Xen Project Weather Report 2018
XPDDS18: Xen Project Weather Report 2018
 
The Future of Networks is Open...Source
The Future of Networks is Open...SourceThe Future of Networks is Open...Source
The Future of Networks is Open...Source
 
Have You Driven an SELinux Lately? - An Update on the SELinux Project - OLS ...
Have You Driven an SELinux Lately? - An Update on the SELinux Project -  OLS ...Have You Driven an SELinux Lately? - An Update on the SELinux Project -  OLS ...
Have You Driven an SELinux Lately? - An Update on the SELinux Project - OLS ...
 

Más de RIPE NCC

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryRIPE NCC
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionRIPE NCC
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in TechRIPE NCC
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfRIPE NCC
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISRIPE NCC
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopRIPE NCC
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfRIPE NCC
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfRIPE NCC
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsRIPE NCC
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing SecurityRIPE NCC
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfRIPE NCC
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasRIPE NCC
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasRIPE NCC
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet InfrastructureRIPE NCC
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenRIPE NCC
 

Más de RIPE NCC (20)

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet Registry
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate Action
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in Tech
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement Tools
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the Baltics
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing Security
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE Atlas
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement Services
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in Sweden
 

Último

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Bhuvaneswari Subramani
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Angeliki Cooney
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 

Último (20)

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 

DNSSEC - Amsterdam Roundtable 2011

  • 2. DNS: the Domain Name System • Specified by Paul Mockapetris in 1983 • Distributed Hierarchical Database – Main purpose: Translate names to IP addresses – Since then: Extended to carry a multitude of information (such as SPF, DKIM) • Critical Internet Infrastructure – Used by most systems (in the background) Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 2
  • 3. DNS Tree Structure Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 3
  • 4. How does it work? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 4
  • 5. What is the problem? • UDP transport can be spoofed – Anybody can pretend to originate a response • If a response is modified the user will connect to a possibly malicious system Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 5
  • 6. The Solution • Make the responses verifiable – Cryptographic signatures • Hierarchy exists so a Public Key Infrastructure is the logical choice – Same concept as used in eGovernment infrastructures Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 6
  • 7. How does it work with DNSSEC? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 7
  • 8. How does it work with DNSSEC? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 8
  • 9. How does it work with DNSSEC? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 9
  • 10. How does it work with DNSSEC? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 10
  • 11. How does it work with DNSSEC? Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 11
  • 12. DNS Security Extensions: A Long Story • 2005: Theoretical problem discovered (Bellovin) • 1995: Work on DNSSEC started • 1999: First support for DNSSEC in BIND • 2005: Standard is redesigned to better meet operational needs RIPE NCC along with .SE among the first to deploy it in their zones Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 12
  • 13. DNS Security Extensions • 2005 - 2008: Stalled deployments due to the lack of a signed root zone • 2008: D. Kaminsky shows the practical use of the protocol weakness Focus comes back to DNSSEC • July 2010: Root Zone signed with DNSSEC • March 2011: 69/306 signed TLDs Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 13
  • 14. DNSSEC and the RIPE NCC • Sponsor development of NSD DNS software • Participated in the “Deployment of Internet Security Infrastructure” project – Signed all our DNS zones – IPv4 & IPv6 reverse space – E164.arpa – ripe.net • K-root server readiness for a signed root zone Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 14
  • 15. Singing of the Root Zone • Shared custody by Root Zone maintainers – Currently: U.S. DoC NTIA, IANA/ICANN, VeriSign • Split key among 21 Trusted Community Representatives • In production since July 2010 Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 15
  • 16. Deployment in ccTLDs: Europe Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 16
  • 17. Deployment in ccTLDs: Middle East Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 17
  • 18. Deployment in ccTLDs: Asia Pacfic Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 18
  • 19. Deployment in ccTLDs Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 19
  • 20. Deployment in ccTLDs Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 20
  • 21. Deployment in ccTLDs Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 21
  • 22. Deployment in gTLDs • .com/.net/.org (57% of world wide total domains) • .asia • .cat • .biz • .edu • .gov • .info • .museum • .mobi (Planned) Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 22
  • 23. Deployment in Infrastructure TLD .arpa • E164.arpa – ENUM number mapping – signed by the RIPE NCC • in-addr.arpa – Reverse DNS for IPv4 • ip6.arpa – Reverse DNS for IPv6 Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 23
  • 24. Are We Done? • Signed TLD is not the same as a signed domain – Thick registry model (Registry-Registrar-Registrant) – Registrars need to enable their customers to provide public key data to registry Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 24
  • 25. Are We Done? • Ultimately responses should be verified by the end user – Home routers need to support DNS specifications with large response packets Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 25
  • 26. Leverage Infrastructure • DNS is a cross organisational data directory • DNSSEC adds trust to this infrastructure – Anybody can verify data published under ripe.net was originated by the domain holder – Could be used to make DKIM and SPF widely used and trusted – SSL certificates can be trusted through the DNS – More ideas to come … Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 26
  • 27. What about SSL/TLS? • SSL as a transport is well established • CA system currently in use is inherently broken – Any Certificate Authority delivered with a browser to date can issue a certificate for any domain – 100 and more shipped in every Browser – If any one of them fails - security fails with it – Recent incident with Comodo CA is one example • DANE working group at IETF Wolfgang Nagele, RIPE NCC Roundtable Meeting, Amsterdam, April 2011 27