DNSSec
Jump to navigation
Jump to search
How to setup DNSSEC with powerdns:
- Add dnssec to pdns.conf:
gpgsql-dnssec=yes
sudo pdnssec add-zone-key conti.work zsk 1024 active rsasha256 sudo pdnssec add-zone-key conti.work ksk 2048 active rsasha256 sudo pdnssec secure-zone conti.work sudo pdnssec rectify-zone conti.work
Upload public KSK ZSK [1]
dig DNSKEY conti.work
Check if it worked [2] or here [3]
Set nsec3 parameter [4]
sudo pdnssec set-nsec3 conti.work '1 0 10 db7fcd8a'
Adding DANE/TLSA record for mail server certificate verification
Verify with [8]