Project

General

Profile

Actions

Task #5813

closed

Research whether DNSSEC with NSEC5 is interesting for us

Added by Nico Schottelius about 6 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Low
Assignee:
Target version:
-
Start date:
10/11/2018
Due date:
01/18/2019
% Done:

0%

Estimated time:
PM Check date:
01/28/2019

Description

  • dnssec-old led to zone walking
  • dnssec with nsec3 requires online signing -> private key on dns servers
  • dnssec with nsec5 sounds promising, but we need to investigate whether
    • bind9 on our servers properly supports it
    • there are no other attacks against nsec5
    • nsec5 is actually usable within .ch domain
Actions #1

Updated by Nico Schottelius about 6 years ago

  • Priority changed from Normal to Low
Actions #2

Updated by Yury Komarov about 6 years ago

  • Status changed from New to Seen
Actions #3

Updated by Jason Kim almost 6 years ago

  • Due date changed from 10/31/2018 to 01/18/2019
  • PM Check date set to 01/10/2019
Actions #4

Updated by Jason Kim almost 6 years ago

  • PM Check date changed from 01/10/2019 to 01/28/2019
Actions #5

Updated by Nico Schottelius almost 6 years ago

  • Status changed from Seen to Closed

Seems to be unusable for further time.

Actions

Also available in: Atom PDF