29.03.2016 Views

Hands-on DNSSEC with DNSViz

1LXLQe2

1LXLQe2

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Z<strong>on</strong>e Enumerati<strong>on</strong> and NSEC3<br />

• NSEC records allow enumerati<strong>on</strong> of entire z<strong>on</strong>e c<strong>on</strong>tents.<br />

• NSEC3 standard introduces hashed denial of existence.<br />

• Joint effort between Verisign, Nominet (.uk), and DENIC (.de).<br />

• Chain is of hashes of names, not names themselves.<br />

(a hash is the output of a <strong>on</strong>e-way cryptographic functi<strong>on</strong>.)<br />

example.com.<br />

BFO8EKQ9L4V2N4AGI9RCMOTV32J8LJ4C.example.com.<br />

apple.example.com.<br />

V6AVHMGSO0IVEI55QMHIAM276OJJER6L.example.com.<br />

banana.example.com.<br />

VLN8BKFFT1FEVQOLFGOBKJKQA1JVNR86.example.com.<br />

grape.example.com.<br />

VLVVLES7LF0ARNU38OHRUP804KPEAGOE.examplec.com.<br />

example.com<br />

Verisign Public<br />

22

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!