DNSSec: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
No edit summary |
||
| Line 22: | Line 22: | ||
Adding DANE/TLSA record for mail server certificate verification | Adding DANE/TLSA record for mail server certificate verification | ||
openssl x509 -in /etc/ssl/certs/ssl-mail.pem -outform DER | openssl sha256 | |||
Add TLSA record to DNS: | |||
_25._tcp.conti.work. IN TLSA 3 0 1 9bcd8c83d61e414bd5d935545637a2a98d3f38aaaf5ff9af415ddc574e28ae80 | |||
Howto [https://sys4.de/de/blog/2014/05/24/einen-tlsa-record-fuer-dane-mit-bind-9-publizieren/#den-tlsa-record-erstellen] and [http://www.internetsociety.org/deploy360/resources/dane/] | Howto [https://sys4.de/de/blog/2014/05/24/einen-tlsa-record-fuer-dane-mit-bind-9-publizieren/#den-tlsa-record-erstellen] and [http://www.internetsociety.org/deploy360/resources/dane/] | ||
Verify with [http://www.internetsociety.org/deploy360/blog/2014/02/nist-offers-new-tool-to-verify-tlsa-records-for-dane-dnssec/] | Verify with [http://www.internetsociety.org/deploy360/blog/2014/02/nist-offers-new-tool-to-verify-tlsa-records-for-dane-dnssec/] | ||
Revision as of 21:58, 12 February 2015
How to setup DNSSEC with powerdns:
- Add dnssec to pdns.conf:
gpgsql-dnssec=yes
sudo pdnssec add-zone-key conti.work zsk 1024 active rsasha256 sudo pdnssec add-zone-key conti.work ksk 2048 active rsasha256 sudo pdnssec secure-zone conti.work sudo pdnssec rectify-zone conti.work
Upload public KSK ZSK [1]
dig DNSKEY conti.work
Check if it worked [2] or here [3]
Set nsec3 parameter [4]
sudo pdnssec set-nsec3 conti.work '1 0 10 db7fcd8a'
Adding DANE/TLSA record for mail server certificate verification
openssl x509 -in /etc/ssl/certs/ssl-mail.pem -outform DER | openssl sha256
Add TLSA record to DNS:
_25._tcp.conti.work. IN TLSA 3 0 1 9bcd8c83d61e414bd5d935545637a2a98d3f38aaaf5ff9af415ddc574e28ae80
Verify with [8]