Skip to content

DNSSEC signing #878

@mweinelt

Description

@mweinelt

Investigate signing our zones with DNSSEC. This allows authenticity checks from the root zone down to our zone contents, by transitively verifying signatures.

This would prevent third-parties from tampering with our DNS records for resolvers that validate DNSSEC.

The risk is that mishandling DNSSEC can cause the zone to become unavailable until DNSSEC is fixed or TTLs expire.

Small survey among popular distros

  • alpinelinux.org
  • archlinux.org
  • debian.org
  • fedoraproject.org
  • freebsd.org
  • gentoo.org
  • opensuse.org
  • ubuntu.com

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions