29.03.2016 Views

Hands-on DNSSEC with DNSViz

1LXLQe2

1LXLQe2

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>DNSSEC</strong> Chain of Trust<br />

• DNSKEY must be<br />

authenticated.<br />

• Trust extends through<br />

ancestry to a trust anchor<br />

at resolver.<br />

.<br />

DNSKEY<br />

Z<strong>on</strong>e data<br />

DS<br />

• DS resource record –<br />

provides digest of<br />

DNSKEY in child z<strong>on</strong>e.<br />

• Resolver must start <strong>with</strong><br />

trusted key, at root.<br />

com<br />

DNSKEY<br />

Z<strong>on</strong>e data<br />

DNSKEY<br />

DS<br />

Resolver<br />

trust anchor<br />

example.com<br />

Z<strong>on</strong>e data<br />

Verisign Public<br />

18

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!