29.03.2016 Views

Hands-on DNSSEC with DNSViz

1LXLQe2

1LXLQe2

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Key Roles – KSK/ZSK<br />

• DNSKEY RRset usually<br />

has multiple keys, often<br />

<strong>with</strong> split roles.<br />

• KSK (Key signing key)<br />

• Signs (<strong>on</strong>ly) the DNSKEY<br />

RRset.<br />

• Corresp<strong>on</strong>ds to DS records<br />

in parent, providing “secure<br />

entry point” into z<strong>on</strong>e.<br />

• ZSK (Z<strong>on</strong>e signing key)<br />

• Signs the rest of the z<strong>on</strong>e.<br />

com<br />

example.com<br />

…<br />

DNSKEY<br />

Z<strong>on</strong>e data<br />

DS<br />

DNSKEY (KSK)<br />

DNSKEY (ZSK)<br />

Z<strong>on</strong>e data<br />

Verisign Public<br />

19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!