29.03.2016 Views

Hands-on DNSSEC with DNSViz

1LXLQe2

1LXLQe2

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authenticated Denial of Existence<br />

• How do you prove something doesn’t exist?<br />

• “Chain” of names of z<strong>on</strong>e formed using NSEC records.<br />

• NSEC records form comprehensive chain of names (and<br />

their record types) in z<strong>on</strong>e in can<strong>on</strong>ical ordering.<br />

• Server uses NSEC records to prove n<strong>on</strong>-existence.<br />

Query: coc<strong>on</strong>ut.example.com/A ?<br />

NXDOMAIN: banana.example.com/NSEC<br />

Query: example.com/DNSKEY ?<br />

RRSIG<br />

example.com.<br />

apple.example.com.<br />

banana.example.com.<br />

validate<br />

Answer: DNSKEY…<br />

RRSIG<br />

grape.example.com.<br />

Verisign Public<br />

recursive/validating<br />

resolver<br />

example.com<br />

authoritative server<br />

20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!