Global Information Lookup Global Information

OpenDNSSEC information


OpenDNSSEC
Initial releaseJuly 30, 2009; 14 years ago (2009-07-30)[1]
Stable release
2.1.13 / June 26, 2023; 10 months ago (2023-06-26)[2]
Repository
  • github.com/opendnssec/opendnssec Edit this at Wikidata
Written inC, C++
Operating systemLinux, FreeBSD, NetBSD, Mac OS X, Solaris
TypeDNSSEC
LicenseBSD
Websitewww.opendnssec.org
SoftHSM
Stable release
2.6.1 / April 29, 2020; 4 years ago (2020-04-29)[3]
Repositorygithub.com/opendnssec/SoftHSMv2
Written inC++
Operating systemLinux, FreeBSD, NetBSD, Mac OS X
LicenseBSD
Websitewww.opendnssec.org

OpenDNSSEC is a computer program that manages the security of domain names on the Internet. The project intends to drive adoption of Domain Name System Security Extensions (DNSSEC) to further enhance Internet security.

OpenDNSSEC was created as an open-source turn-key solution for DNSSEC. It secures DNS zone data just before it is published in an authoritative name server. OpenDNSSEC takes in unsigned zones, adds digital signatures and other records for DNSSEC and passes it on to the authoritative name servers for that zone. All keys are stored in a hardware security module and accessed via PKCS #11, a standard software interface for communicating with devices which hold cryptographic information and perform cryptographic functions. OpenDNSSEC can be paired with SoftHSM which provides a Software emulation of a hardware security module.[4]

OpenDNSSEC runs two dedicated daemons these are ods-enforcerd which acts as a enforcer Engine Daemon with the role of enforcing the KASP (Key and Signing Policy), and the ods-signerd which carries out actual signing of the zone. A DNS zone will failed to be signed if either process fail.

The ods-enforcer client program may be used to interact with the enforcer Engine and can be used to initiate such actions as a key rollover manually.

OpenDNSSEC uses the Botan cryptographic library, and SQLite or MySQL as database back-end. It is used on the .fr,[5].se, .dk, .nl,[6] .nz[7] and .uk top-level domains.[8]

  1. ^ "NEWS". OpenDNSSEC. 1.0.0. 9 February 2010. Retrieved 18 June 2022 – via GitHub.
  2. ^ "OpenDNSSEC 2.1.13".
  3. ^ "SoftHSM 2.6.1".
  4. ^ "OpenDNSSEC » SoftHSM". OpenDNSSEC.org. Retrieved 29 January 2024.
  5. ^ Levigneron, Vincent. "DNSSEC: change of algorithm for the .fr zone". Afnic. Retrieved 30 January 2024.
  6. ^ Ubbink, Stefan. "New DNSSEC algorithm for .nl". www.sidn.nl. Retrieved 10 February 2024.
  7. ^ "DNSSEC chain validation issue: technical incident report". InternetNZ. Retrieved 24 April 2024.
  8. ^ "OpenDNSSEC". Retrieved 17 September 2014.

and 21 Related for: OpenDNSSEC information

Request time (Page generated in 0.5876 seconds.)

OpenDNSSEC

Last Update:

Security Extensions (DNSSEC) to further enhance Internet security. OpenDNSSEC was created as an open-source turn-key solution for DNSSEC. It secures DNS zone...

Word Count : 334

Domain Name System Security Extensions

Last Update:

designed around DNSSEC concepts. mysqlBind, the GPL DNS management software for DNS ASPs, now supports DNSSEC. OpenDNSSEC is a designated DNSSEC signer tool...

Word Count : 7669

Hardware security module

Last Update:

to store the key material that is used to sign large zonefiles. OpenDNSSEC is an open-source tool that manages signing DNS zone files. On January 27,...

Word Count : 2046

ODS

Last Update:

House OpenDocument Spreadsheet file format Online dating service Operational data store, an intermediate data warehouse for databases OpenDNSSEC, a security...

Word Count : 267

NLnet Labs

Last Update:

members of NLnet. They develop DNS-related software, such as NSD, Unbound, OpenDNSSEC and getDNS. The roots of NLnet Labs have their origins in the NLnet Foundation...

Word Count : 267

List of applications using PKCS 11

Last Update:

Firefox – a web browser Mozilla Thunderbird – an email client OpenDNSSEC – a DNSSEC signer OpenSSL – TLS/SSL library (with engine_pkcs11) GnuTLS – TLS/SSL...

Word Count : 527

Public recursive name server

Last Update:

Cisco Online Privacy Statement OpenDNS: DNSSEC General Availability OpenDNS: Querying OpenDNS using DoH OpenDNS: OpenDNS and DNSCrypt Quad9: Compliance...

Word Count : 606

Web of trust

Last Update:

HKPS, HKPS+DNSSEC+DANE, HTTPS, HTTPS+HPKP or HTTPS+HPKP+DNSSEC+DANE. If a vast number of user's group create their own new DLV based DNSSEC registry, and...

Word Count : 3392

Google Public DNS

Last Update:

IETF. It fully supports the DNSSEC protocol since 19 March 2013. Previously, Google Public DNS accepted and forwarded DNSSEC-formatted messages but did...

Word Count : 983

OpenWrt

Last Update:

project to resolve bufferbloat in home networking, support IPv6, integrate DNSSEC, for wired and wireless, to complement the debloat-testing kernel tree and...

Word Count : 3136

Domain Name System

Last Update:

in DNSSEC Delegation Signer (DS) Resource Records RFC 4470, Minimally Covering NSEC Records and DNSSEC On-line Signing RFC 5155, DNS Security (DNSSEC) Hashed...

Word Count : 9106

List of DNS record types

Last Update:

DNS as KEY RRs and a private key is stored at the signer." RFC 3445, §1. "DNSSEC will be the only allowable sub-type for the KEY RR..." RFC 3755, §3. "DNSKEY...

Word Count : 667

Comparison of DNS server software

Last Update:

supports DNSSEC signing and among others hosts root zone (B, K, and L root name servers), several top-level domains. Knot Resolver is an open source modern...

Word Count : 3324

OpenDNS

Last Update:

and 4th) OpenDNS Addresses". OpenDNS. Archived from the original on 2013-05-27. Retrieved 2011-09-21. "Setup Guide". OpenDNS. "OpenDNS DNSSEC General Availability"...

Word Count : 2359

Alternative DNS root

Last Update:

top-level resource records to delegate authoritative name servers and set up DNSSEC zone signing directly. Existing TLDs are reserved in the Handshake blockchain...

Word Count : 1655

PowerDNS

Last Update:

management interfaces for PowerDNS. The PowerDNS Authoritative Server supports DNSSEC as of version 3.0. While pre-signed zones can be served, it is also possible...

Word Count : 667

DNS spoofing

Last Update:

Secure DNS (DNSSEC) uses cryptographic digital signatures signed with a trusted public key certificate to determine the authenticity of data. DNSSEC can counter...

Word Count : 1405

Internet Key Exchange

Last Update:

authentication ‒ either pre-shared or distributed using DNS (preferably with DNSSEC) ‒ and a Diffie–Hellman key exchange to set up a shared session secret from...

Word Count : 2339

Opportunistic TLS

Last Update:

addressed by DNS-based Authentication of Named Entities (DANE), a part of DNSSEC, and in particular by RFC 7672 for SMTP. DANE allows to advertise support...

Word Count : 1228

CNAME record

Last Update:

2, RFC 1912 section 2.4) The exception is when DNSSEC is being used, in which case there can be DNSSEC related records such as RRSIG, NSEC, etc. (RFC...

Word Count : 1474

Djbdns

Last Update:

version. While djbdns does not directly support DNSSEC, there are third party patches to add DNSSEC support to djbdns' authoritative-only tinydns component...

Word Count : 805

PDF Search Engine © AllGlobal.net