Actions
Task #5813
closedResearch whether DNSSEC with NSEC5 is interesting for us
Start date:
10/11/2018
Due date:
01/18/2019
% Done:
0%
Estimated time:
PM Check date:
01/28/2019
Description
- dnssec-old led to zone walking
- dnssec with nsec3 requires online signing -> private key on dns servers
- dnssec with nsec5 sounds promising, but we need to investigate whether
- bind9 on our servers properly supports it
- there are no other attacks against nsec5
- nsec5 is actually usable within .ch domain
Updated by Nico Schottelius about 6 years ago
- Priority changed from Normal to Low
Updated by Jason Kim almost 6 years ago
- Due date changed from 10/31/2018 to 01/18/2019
- PM Check date set to 01/10/2019
Updated by Jason Kim almost 6 years ago
- PM Check date changed from 01/10/2019 to 01/28/2019
Updated by Nico Schottelius almost 6 years ago
- Status changed from Seen to Closed
Seems to be unusable for further time.
Actions