NSEC3 Project
ANNOUNCEMENT: 2nd NSEC3 Workshop
ANNOUNCEMENT: 2nd NSEC3 Workshop Report (draft)
What
NSEC3 is an addition to the DNS Security Extensions described in RFCs 4033, 4034 and 4035. It is described in http://www.nsec3.org/cgi-bin/trac.cgi/attachment/wiki/WikiStart/draft-ietf-dnsext-nsec3-13.txt?format=raw.
Why
The DNS Security Extensions included the NSEC RR to provide authenticated denial of existence. Though the NSEC RR meets the requirements for authenticated denial of existence, it introduces a side-effect in that the contents of a zone can be enumerated. This property introduces undesired policy issues.
A second problem is that the cost to cryptographically secure delegations to unsigned zones is high for large delegation-centric zones and zones where insecure delegations will be updated rapidly. For these zones, the costs of maintaining the NSEC record chain may be extremely high relative to the gain of cryptographically authenticating existence of unsecured zones.
Where
This is currently being stardardized in the IETF DNS Extensions workgroup
There is a mailing list available: http://www.nsec3.org/mailman/listinfo/nsec3-testing
Drafts
Current NSEC3 draft (31 August 2006)
Older and Related Drafts
Software
- Validating Full Resolver (java), from SVN
- Signing Tools (java). Contains a zone signer that will sign zones using NSEC3.
- Signing Tools (perl). Contains a zone signer as well.
- LDNS, contains NSEC3 by default from NLnetLabs.
- NSD with NSEC3. NLNetLabs NSD with Ben Laurie's patches.
- Old Implementations Link
Starting Points
- Testing -- NSEC3 testing resources
- Presentations? - NSEC3 presentations
- NSEC3 Workshops
- FAQ? - Frequently Asked Questions
- Issues - Current NSEC3 Issues List
- Links
For a complete list of local wiki pages, see TitleIndex.
Attachments
- sigtstfull.tar.gz (3.4 kB) - added by roy on 09/19/06 14:47:37.
- sigtstempty.tar.gz (1.3 kB) - added by roy on 09/19/06 15:08:37.
- optout-empty.gz (5.8 kB) -
optout w/ empty non terminals
, added by roy on 09/19/06 18:29:51. - brokenpackets.txt (1.9 kB) - added by roy on 09/20/06 14:01:58.
- nsec3-workshop-agenda.txt (6.8 kB) - added by roy on 09/20/06 17:32:36.
- Signing_report.txt (4.2 kB) -
Report on the Signing test done at the Second NSEC3 workshop
, added by nsec3 on 09/20/06 18:05:59. - report-axfr.txt (3.5 kB) -
Report on the loading and zone transfer tests in the second workshop.
, added by nsec3 on 09/20/06 18:09:11. - NSEC_to_NSEC3_Roll_Test_Report.txt (1.6 kB) - added by geoff on 09/20/06 18:18:58.
- signed-zones.tgz (26.6 kB) -
signed zones for workshop 2
, added by jad on 09/20/06 18:51:52. - broken-rep.txt (2.9 kB) - added by roy on 09/20/06 19:27:31.
- nsec3-workshop2-report-draft.txt (25.4 kB) -
First draft of the workshop results report
, added by matt on 09/20/06 19:54:13. - signal-traverse-notes.txt (5.3 kB) -
Signal Traversing Test
, added by nsec3 on 09/20/06 20:00:45. - draft-ietf-dnsext-nsec3-13.txt (110.7 kB) - added by roy on 11/30/07 00:15:51.
