Re: DNSSEC and DLZ

"[email protected]" <[email protected]> Thu, 31 Dec 2015 14:20:36 +0100 (CET)
Newsgroups gmane.network.dns.bind9.dlz
Message-ID <1031609955.6434371451568036082.JavaMail.httpd@webmail-21.iol.local>
--===============5666925117564472500==
Content-Type: multipart/alternative; 
	boundary="----=_Part_736165_794554943.1451568036081"

------=_Part_736165_794554943.1451568036081
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

Hi all,
Evan, Mark, thanks for your replies.
I will try to apply Evan suggestion about master/slave configuration to solve the issue, even if I don't know if I can apply it to my specific case.I will also have a look to this new mechanism called DynDB.

Kind regards--Fab--


On Thu, Dec 31, 2015 at 04:15:20PM +1300, Mark Goldfinch wrote:
> Alternatively you will need to flow your DNS zone data through a system
> like OpenDNSSec before publishing it within your DLZ Bind database.

No, I'm afraid that still wouldn't work.  DLZ databases cannot answerDNSSEC queries, except as a back-end server for zone transfers.To serve DNSSEC, if you're answering a query for a name that doesn't exist,you have to be able to prove that the name doesn't exist.  That involvessearching backward through the database for the closest previous record,and then lookuping the NSEC record that's there, or using deliberatelyobscure cryptographic hashing to find the associated NSEC3 record, and aDLZ database can do neither -- the required database primitives simplydon't exist.(There is a new mechanism called DynDB being introduced in the upcomingBIND 9.11 which will be able to answer DNSSEC queries from an externaldatabase; it was developed by Red Hat as part of their FreeIPA project.However, the 
 only DynDB driver that's been written so far is one theydeveloped for LDAP.)

--
Evan Hunt -- [email protected]
Internet Systems Consortium, Inc.

------=_Part_736165_794554943.1451568036081
Content-Type: text/html;charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div><span class=3D"im" style=3D"color: rgb(80, 0, 80); font-family: arial,=
 sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, 34, 34); fon=
t-size: 12.8px;">Hi all,</span><div style=3D"color: rgb(34, 34, 34); font-s=
ize: 12.8px;"><br></div><div style=3D"color: rgb(34, 34, 34); font-size: 12=
.8px;">Evan, Mark, thanks for your replies.</div><div style=3D"color: rgb(3=
4, 34, 34); font-size: 12.8px;"><br></div><div style=3D"color: rgb(34, 34, =
34); font-size: 12.8px;">I will try to apply Evan suggestion about master/s=
lave configuration to solve the issue, even if I don't know if I can apply =
it to my specific case.</div><div style=3D"color: rgb(34, 34, 34); font-siz=
e: 12.8px;">I will also have a look to this new mechanism called DynDB.</di=
v><div style=3D"color: rgb(34, 34, 34); font-size: 12.8px;"><br></div><div =
style=3D"color: rgb(34, 34, 34); font-size: 12.8px;"><br></div><div style=
=3D"color: rgb(34, 34, 34); font-size: 12.8px;">Kind regards</div><div styl=
e=3D"color: rgb(34, 34, 34); font-size: 12.8px;">--Fab--</div><div style=3D=
"color: rgb(34, 34, 34); font-size: 12.8px;"><br></div><div style=3D"color:=
 rgb(34, 34, 34); font-size: 12.8px;"><br></div></span></div><div></div><sp=
an class=3D"im" style=3D"color: rgb(80, 0, 80); font-family: arial, sans-se=
rif; font-size: 12.8px;"><div><span class=3D"im" style=3D"color: rgb(80, 0,=
 80); font-family: arial, sans-serif; font-size: 12.8px;"><br></span></div>=
On Thu, Dec 31, 2015 at 04:15:20PM +1300, Mark Goldfinch wrote:<br>&gt; Alt=
ernatively you will need to flow your DNS zone data through a system<br>&gt=
; like OpenDNSSec before publishing it within your DLZ Bind database.<br><b=
r></span><span style=3D"color: rgb(34, 34, 34); font-family: arial, sans-se=
rif; font-size: 12.8px;">No, I'm afraid that still wouldn't work.&nbsp; DLZ=
 databases cannot answer</span><br style=3D"color: rgb(34, 34, 34); font-fa=
mily: arial, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, =
34, 34); font-family: arial, sans-serif; font-size: 12.8px;">DNSSEC queries=
, except as a back-end server for zone transfers.</span><br style=3D"color:=
 rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8px;"><br s=
tyle=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: =
12.8px;"><span style=3D"color: rgb(34, 34, 34); font-family: arial, sans-se=
rif; font-size: 12.8px;">To serve DNSSEC, if you're answering a query for a=
 name that doesn't exist,</span><br style=3D"color: rgb(34, 34, 34); font-f=
amily: arial, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34,=
 34, 34); font-family: arial, sans-serif; font-size: 12.8px;">you have to b=
e able to prove that the name doesn't exist.&nbsp; That involves</span><br =
style=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size:=
 12.8px;"><span style=3D"color: rgb(34, 34, 34); font-family: arial, sans-s=
erif; font-size: 12.8px;">searching backward through the database for the c=
losest previous record,</span><br style=3D"color: rgb(34, 34, 34); font-fam=
ily: arial, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, 3=
4, 34); font-family: arial, sans-serif; font-size: 12.8px;">and then lookup=
ing the NSEC record that's there, or using deliberately</span><br style=3D"=
color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8px;"=
><span style=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; fon=
t-size: 12.8px;">obscure cryptographic hashing to find the associated NSEC3=
 record, and a</span><br style=3D"color: rgb(34, 34, 34); font-family: aria=
l, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, 34, 34); f=
ont-family: arial, sans-serif; font-size: 12.8px;">DLZ database can do neit=
her -- the required database primitives simply</span><br style=3D"color: rg=
b(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8px;"><span st=
yle=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 1=
2.8px;">don't exist.</span><br style=3D"color: rgb(34, 34, 34); font-family=
: arial, sans-serif; font-size: 12.8px;"><br style=3D"color: rgb(34, 34, 34=
); font-family: arial, sans-serif; font-size: 12.8px;"><span style=3D"color=
: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8px;">(The=
re is a new mechanism called DynDB being introduced in the upcoming</span><=
br style=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; font-si=
ze: 12.8px;"><span style=3D"color: rgb(34, 34, 34); font-family: arial, san=
s-serif; font-size: 12.8px;">BIND 9.11 which will be able to answer DNSSEC =
queries from an external</span><br style=3D"color: rgb(34, 34, 34); font-fa=
mily: arial, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, =
34, 34); font-family: arial, sans-serif; font-size: 12.8px;">database; it w=
as developed by Red Hat as part of their FreeIPA project.</span><br style=
=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8=
px;"><span style=3D"color: rgb(34, 34, 34); font-family: arial, sans-serif;=
 font-size: 12.8px;">However, the only DynDB driver that's been written so =
far is one they</span><br style=3D"color: rgb(34, 34, 34); font-family: ari=
al, sans-serif; font-size: 12.8px;"><span style=3D"color: rgb(34, 34, 34); =
font-family: arial, sans-serif; font-size: 12.8px;">developed for LDAP.)</s=
pan><div class=3D"yj6qo ajU" style=3D"cursor: pointer; outline: none; paddi=
ng: 10px 0px; width: 22px; color: rgb(34, 34, 34); font-family: arial, sans=
-serif; font-size: 12.8px;"><div id=3D":1wi" class=3D"ajR" role=3D"button" =
tabindex=3D"0" aria-label=3D"Hide expanded content" data-tooltip=3D"Hide ex=
panded content" style=3D"border: 1px solid rgb(221, 221, 221); clear: both;=
 line-height: 6px; outline: none; position: relative; width: 20px; backgrou=
nd-color: rgb(241, 241, 241);"><img class=3D"ajT" src=3D"https://ssl.gstati=
c.com/ui/v1/icons/mail/images/cleardot.gif" style=3D"height: 8px; opacity: =
0.3; width: 20px; background: url(&quot;//ssl.gstatic.com/ui/v1/icons/mail/=
ellipsis.png&quot;) no-repeat;"></div></div><div class=3D"adL" style=3D"col=
or: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 12.8px;"><b=
r></div><div class=3D"HOEnZb adL" style=3D"color: rgb(34, 34, 34); font-fam=
ily: arial, sans-serif; font-size: 12.8px;"><div class=3D"adm" style=3D"mar=
gin: 5px 0px;"></div><div class=3D"im" style=3D"color: rgb(80, 0, 80);"><br=
>--<br>Evan Hunt --&nbsp;<a href=3D"mailto:[email protected]" style=3D"color: rg=
b(17, 85, 204);">[email protected]</a><br>Internet Systems Consortium, Inc.</div=
></div>

------=_Part_736165_794554943.1451568036081--



--===============5666925117564472500==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============5666925117564472500==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Bind-dlz-testers mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers

--===============5666925117564472500==--