Re: DNSSEC management
Henrique de Moraes Holschuh <[email protected]>
| Newsgroups | gmane.linux.debian.user.isp |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 02 May 2011, Marek Podmaka wrote: > What do you use for DNSSEC management of your/customer's domains? Is > there some existing tools/scripts ready or everyone has its own > self-made scripts? Well, you could roll out your own, of course, but there are good ones out there already. We're testing this one: http://registro.br/dnsshim/index-EN.html DNSSHIM is software maitained by NIC.br, responsible for all of the .br TLD operations. It works as a shadow master server, so it is extremely easy to deploy on BIND-like DNSSEC infrastructures. There are other such DNSSEC key lifetime management suites. I think RIPE has published one as well (but I am not sure it is FLOSS). Google will find them. -- "One disk to rule them all, One disk to find them. One disk to bring them all and in the darkness grind them. In the Land of Redmond where the shadows lie." -- The Silicon Valley Tarot Henrique Holschuh