Top Banner
DNSSEC for the Root Zone LACNIC XIII Curacao, Netherlands Antilles May 2010 Mehmet Akc cin, ICANN Tuesday, May 18, 2010
26

Signing the Root

Nov 28, 2014

Download

Technology

Mehmet Akcin

DNSSEC Signing the Root
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Signing the Root

DNSSECfor the Root Zone

LACNIC XIII Curacao, Netherlands Antilles

May 2010

Mehmet Akcin, ICANNMehmet Akcin, ICANN

Tuesday, May 18, 2010

Page 2: Signing the Root

This design is the result of a cooperation between ICANN & VeriSign withsupport from the U.S. DoC NTIA

Tuesday, May 18, 2010

Page 3: Signing the Root

Quick Recap

• 2048-bit RSA KSK, 1024-bit RSA ZSK

• Signatures with RSA/SHA-256

• Split ZSK/KSK operations

• Incremental deployment

• Deliberately Unvalidatable Root Zone (DURZ)

• more information @ www.root-dnssec.org

Tuesday, May 18, 2010

Page 4: Signing the Root

DURZ Deployment

• The Deliberately Unvalidatable Root Zone (DURZ) deployment started on 27 January.

• As of 5 May, all 13 root servers are serving the DURZ.

Tuesday, May 18, 2010

Page 5: Signing the Root

Pre-DURZ 2010-01-19 ✔

L 2010-01-27 ✔

A 2010-02-10 ✔

I,M 2010-03-03 ✔

D, E, K 2010-03-24 ✔

B,C,F,G,H 2010-04-14 ✔

J 2010-05-05 ✔

DURZ Data Collections

Tuesday, May 18, 2010

Page 6: Signing the Root

Tuesday, May 18, 2010

Page 7: Signing the Root

L-Root’s DURZ Date01/26/10

Tuesday, May 18, 2010

Page 8: Signing the Root

Tuesday, May 18, 2010

Page 9: Signing the Root

Tuesday, May 18, 2010

Page 10: Signing the Root

All Roots serving DURZ Date 05/05/10

Tuesday, May 18, 2010

Page 11: Signing the Root

Tuesday, May 18, 2010

Page 12: Signing the Root

L-Root’s DURZ Date01/26/10

Tuesday, May 18, 2010

Page 13: Signing the Root

All Roots serving DURZ Date 05/05/10

Tuesday, May 18, 2010

Page 14: Signing the Root

Tuesday, May 18, 2010

Page 15: Signing the Root

Tuesday, May 18, 2010

Page 16: Signing the Root

UDP Priming Query Ratefor the previous month

as of 2010 05 01 00:00:00

Date/Time, UTC

MAR31 APR5 APR10 APR15 APR20 APR25 APR30

Que

ries

Per S

econ

d

0

50

100

150

200

250

300

350

400

450A rootC rootD rootE rootF rootG rootH rootJ rootL rootM root

Tuesday, May 18, 2010

Page 17: Signing the Root

UDP Priming Query Ratefor the previous month

as of 2010 05 01 00:00:00

Date/Time, UTC

MAR31 APR5 APR10 APR15 APR20 APR25 APR30

Que

ries

Per S

econ

d

0

50

100

150

200

250

300

350

400

450A rootC rootD rootE rootF rootG rootH rootJ rootL rootM root

A single nameserver instance with

max-cache-ttl=0

Tuesday, May 18, 2010

Page 18: Signing the Root

DS Change Requests

• Approach likely to be based on existing methods for TLD managers to request changes in root zone.

• Anticipate being able to accept DS requests in early June.

Tuesday, May 18, 2010

Page 19: Signing the Root

Policy Update

• Updated versions of the draft KSK and ZSK DNSSEC Practice Statements (DPS) will be published shortly.

‣ Not much has changed substantively, but please read these practice statements – answers to most questions regarding DNSSEC for the Root Zone can be found in the DPS.

Tuesday, May 18, 2010

Page 20: Signing the Root

TCR Update

• Trusted Community Representative Applications were submitted between 13-24 April 2010.

• 61 Total Applications

‣ 5 from LACNIC

‣ Background checks are being completed.

Tuesday, May 18, 2010

Page 21: Signing the Root

KSK Ceremonies

• First ceremony will take a place in ICANN KSK East Coast Facility in Culpeper, Virginia

• 16 June 2010

‣ More information will be posted on website http://www.root-dnssec.org

Tuesday, May 18, 2010

Page 22: Signing the Root

DocumentationAvailable at www.root-dnssec.org

• Requirements

• High Level Technical Architecture

• DNSSEC Practice Statements (DPS)

• Trust Anchor Publication

• Deployment Plan

• KSK Ceremonies Guide

• TCR Proposal

• Resolver Testing with a DURZ

• DS Record Handling

• DNSSEC Key Management Implementation

Tuesday, May 18, 2010

Page 23: Signing the Root

Next Steps

• 2010-06-16: First Key Signing Key (KSK) Ceremony

‣ Culpeper, US (ICANN East Coast KSK facility)

• 2010-07-15: Distribution of validatable, production, signed root zone; publication of root zone trust anchor

‣ More data analysis and dodging meetings and holidays.

Tuesday, May 18, 2010

Page 24: Signing the Root

Questions & Answers

Tuesday, May 18, 2010

Page 25: Signing the Root

[email protected]

Tuesday, May 18, 2010

Page 26: Signing the Root

Root DNSSEC Design Team

Joe AbleyMehmet AkcinDavid BlackaDavid ConradRichard LambMatt Larson

Fredrik LjunggrenDave Knight

Tomofumi OkuboJakob SchlyterDuane Wessels

Tuesday, May 18, 2010