Infoblox’s global team of threat hunters uncovers a DNS operation with the ability to bypass traditional security measures and control the Great Firewall of China. Read about “Muddling Meerkat” and the many other threat actors discovered by Infoblox Threat Intel here.

NIOS DNS DHCP IPAM

Reply

DNSSEC - KSK Rollover

[ Edited ]
New Member
Posts: 1
1324     0

Hello,

 

I have a DNSSEC singed zone with the default KSK Rollover period of 1 year. I want to know what happens after 1 year when the rollover period expires naturally.

 

I understand that a new KSK key pair gets generated and the DNSKEY record set is signed with it and since Double-Sign method is used the old KSK is also valid until the grace period. 

 

So what is the grace period when the KSK expires naturally? 

 

If its half the rollover period i.e 182.5 days then do I have this much time to update the registrar with the new DS record? 

 

Once the new DS record has been updated at the registar I wait for the TTL and then remove the old DS record. Then again wait for the TTL to expire and then remove the old KSK from the zone? Is this the correct way to perform a seamless rollover?

 

Thank you.

Re: DNSSEC - KSK Rollover

New Member
Posts: 1
1324     0

Giving this thread a bump, as I have the exact same questions and I am working on deploying DNSSEC on several of our zones.

Re: DNSSEC - KSK Rollover

[ Edited ]
Authority
Posts: 9
1324     0

I am currently testing on this in my lab according to manual that supplied by Infoblox. https://insights.infoblox.com/resources-deployment-guides/infoblox-deployment-guide-dnssec

 

What i noticed if KSK expired (assuming after 365 days), the entire signed zones will become BOGUS. You should be able to noticed the validity of your DNSSEC record through dig www.example.com +dnssec

www.example.com. 300 IN RRSIG A 8 3 300 20231116065751(valid before) 20231114055751(valid after)

 

Just to share the below link for more reads-up

https://pi-hole.net/blog/2021/12/12/understanding-dnssec-validation-using-pi-holes-query-log/#page-c...

Showing results for 
Search instead for 
Did you mean: 

Recommended for You