Reply

Implementing DNSSEC for 500+ Zones

Techie
Posts: 3
4053     0

In the process of implementing DNSSEC on 500+ Zones in NIOS 7.2.5.  I can sign multiple Zones at a time, but must export the DS record one Zone at a time.  A very tideous process.  What have others done in similiar situations?  Is the KSK rollover process going to be as tedious?  Thanks.

Re: Implementing DNSSEC for 500+ Zones

Authority
Posts: 46
4054     0

I think we need a little more info before anyone can give you a good answer I think.

 

Can you tell us if the is a parent/child zone releationship to these 500 zones?

If there is a child zone, is the child on the same Infoblox Grid or is it delegated out somewhere else?

Re: Implementing DNSSEC for 500+ Zones

Techie
Posts: 3
4054     0

These are all parent zones.

Re: Implementing DNSSEC for 500+ Zones

Community Manager
Community Manager
Posts: 248
4054     0

You can use the WAPI to get all the DNSSEC zones within a rollover window using "dnssec_ksk_rollover > = ..."

 

/wapi/v2.0/zone_auth?_return_type=json-pretty&_return_fields%2B=dnssec_keys,dnssec_ksk_rollover_date,dnssec_zsk_rollover_date&dnssec_ksk_rollover_date>=1498060000

 

That will export the public keys.

 

 

 

 

Re: Implementing DNSSEC for 500+ Zones

Authority
Posts: 46
4054     0

I was just writing that it looks like the API is the only way to do this in a sane manor for that many zones but GHorne beat me to it Smiley Happy.  

 

As far as the question about ksk rolling goes, that should be handled with caution.  Much of it depends on the registrar's support, they may or may not have an automated way to tell when you are rolling your KSKs and sign the new KSK (DS).  I see you can set automaitc rolling for the KSK using the API, but I don't see a manual way to initiate the KSK roll via the API.

Re: Implementing DNSSEC for 500+ Zones

Techie
Posts: 3
4054     0

Are there any Infoblox customers in this community that can share their experiences in implementing a large database of parent Zones to DNSSEC?

Showing results for 
Search instead for 
Did you mean: 

Recommended for You