`

dnssec

 
阅读更多
Domain Name System Security Extensions (DNSSEC)DNS安全扩展

DNSKEY:用于存储验证 DNS数据的公钥

RRSIG(Resource Record),即资源记录,用于存储 DNS资源记录的签名信息

KSK:表示密钥签名密钥 (Key Signing key) (一种长期密钥)

ZSK:表示区域签名密钥 (Zone Signing Key) (一种短期密钥)

DS(Delegation Signer)记录:授权签名者,DS记录存储DNSKEY的散列值,用于验证DNSKEY的真实性

1.DNSSEC 使用短期密钥(即区域签名密钥 (ZSK) ) 来定期计算 DNS 记录的签名
2.同时使用长期密钥(即密钥签名密钥 (KSK) ) 来计算 ZSK 上的签名

[root@localhost ~]# dig paypal.com @8.8.8.8 +dnssec ds

; <<>> DiG 9.9.3 <<>> paypal.com @8.8.8.8 +dnssec ds
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38668
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 512
;; QUESTION SECTION:
;paypal.com. IN DS

;; ANSWER SECTION:
paypal.com. 57156 IN DS 21037 5 2 0DF17B28554954D819E0CEEAB98FCFCD56572A4CF4F551F0A9BE6D04 DB2F65C3
paypal.com. 57156 IN RRSIG DS 8 2 86400 20170829041641 20170822030641 5528 com. HDB5dzNMA7mXV7qjhkcX0W/KnzvcvITTQWAP/s/wZ6n55NwHi9QYMBTb EHFQq+KSG2hoWWugHA8QF5zmehLgS4Z+uhnUNaGEYORcC5GXpWB4mO1d gK3aAEsv5mRxQw6Ddjjp/U6vsTHO+q2J257v5aD9vkvE/t2UEWEFYRX5 hcc=


去com的授权上查:

[root@localhost ~]# dig paypal.com @a.gtld-servers.net +dnssec ds

; <<>> DiG 9.9.3 <<>> paypal.com @a.gtld-servers.net +dnssec ds
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15090
;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 14, ADDITIONAL: 27
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;paypal.com. IN DS

;; ANSWER SECTION:
paypal.com. 86400 IN DS 21037 5 2 0DF17B28554954D819E0CEEAB98FCFCD56572A4CF4F551F0A9BE6D04 DB2F65C3
paypal.com. 86400 IN RRSIG DS 8 2 86400 20170829041641 20170822030641 5528 com. HDB5dzNMA7mXV7qjhkcX0W/KnzvcvITTQWAP/s/wZ6n55NwHi9QYMBTb EHFQq+KSG2hoWWugHA8QF5zmehLgS4Z+uhnUNaGEYORcC5GXpWB4mO1d gK3aAEsv5mRxQw6Ddjjp/U6vsTHO+q2J257v5aD9vkvE/t2UEWEFYRX5 hcc=
分享到:
评论

相关推荐

Global site tag (gtag.js) - Google Analytics