Re: NSD and DNSSEC signature refreshing and ZSK rotation

Paul Wouters <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
On Thu, 15 Feb 2018, Michael A. Peters wrote:

> I believe the fear was abuse in DDoS amplification attacks.

That is addressed with DNS-COOKIES and RRL:

https://tools.ietf.org/html/rfc7873

https://kb.isc.org/article/AA-01000/0/A-Quick-Introduction-to-Response-Rate-Limiting.html

And of course, one can use ECC based algorithms to reduce the remaining
amplification. DNS software is getting pretty good at reducing this
harm. Good enough to not use 1024 bit RSA anymore.

Paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.