14
Roland van Rijswijk [email protected] c b Future DNS update TF-MNM, November 9 th 2011, Bologna

Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

Roland van [email protected] b

Future DNS updateTF-MNM, November 9th 2011, Bologna

Page 2: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Topics

- Research at SURFnet

- Bouncing a DANE idea around

- DNSSEC signing-as-a-service

2

Page 3: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Research at SURFnet

- End of last year and in March this year we had “issues” with a large ISP in The Netherlands

- Customers of the ISP were unable to resolve names in surfnet.nl

- The cause turned out to be an issue with the ISP’s firewall

3

Page 4: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

Research at SURFnet

4

Recursive CachingName Server

(resolver)

AuthoritativeName Server

Firewall

min(MTU) = 1500 bytes(somewhere in transit)

! "

#

$

%

&

Internet

Page 5: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Research at SURFnet

- Short student assignment to confirm the problemhttp://bit.ly/dnssec-frags

- Currently: MSc. student working on problem mitigation options and better detection

- Request: can we get traces from the NREN crowd for signed top-level domains or academic subdomains (.ac.*)

5

Page 6: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Bouncing a DANE idea around- DANE =

DNS-based Authentication of Named Entities

- Draft RFCs bouncing around the IETF

- Seen by many as an alternative to CA-based PKIs for TLS certificates

- Problem 1: trust framework in DNSSEC not (as) well defined

- Problem 2: lack of control/trust over all links in the chain of trust

6

Page 7: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Traditional trust chain

7

root (.)

org

eduroam

Secure Delegation

Secure Delegation

nl

Secure Delegation

RADIUS certificate

DNSSEC policy

DNSSEC policy

DNSSEC policy

Page 8: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Out-of-chain TTP

8

root (.)

org

eduroam

Secure Delegation

Secure Delegation

nl

Secure Delegation

RADIUS certificate

DNSSEC policy

DNSSEC policy

DNSSEC policy

TTPSecure Delegation

TTP referenceTrust anchor

repository

Page 9: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Scaling to multiple TTPs

9

root (.)

org

eduroam

Secure Delegation

Secure Delegation

nl

Secure Delegation

RADIUS certificate

DNSSEC policy

DNSSEC policy

DNSSEC policy

TTP 2

Trust anchorrepository

TTP n

Trust anchorrepository

TTP 3

Trust anchorrepository

TTP 1

Trust anchorrepository

Page 10: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

Technical elements- It is possible to re-use existing DNS(SEC)

technologies:- DLV- Secure Delegation- DNSSEC signing policy framework

- Requires a means to reference a TTP

- Requires a validation framework

- Has similarities to Convergence (see convergence.io) but re-uses DNS(SEC) rather than establishing a whole new framework

10

Page 11: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

DNSSEC uptake...- DNSSEC uptake is still very slow (or has more

or less ground to a halt)

- DNSSEC is complex; there is a willingness but a lack of understanding/know-how

11

Page 12: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

DNSSEC signing-as-a-service

- Interesting market development: DNSSEC signing-as-a-service

- Registries starting to offer it (e.g. Nominet)

- Independent vendors also offering it

- Why not tender for such a service with the NREN community? (like we did with TCS)

12

Page 13: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

SURFnet. We make innovation work c b

DNSSEC signing-as-a-service

- Is there an interest in such a service?

- If so: what are requirements?

- How to tender for such a service? How to consider contract duration for instance?

- What can we learn from the market?

13

Page 14: Future DNS update - TERENA...- Bouncing a DANE idea around - DNSSEC signing-as-a-service 2 SURFnet. We make innovation work c b Research at SURFnet - End of last year and in March

c b

nl.linkedin.com/in/rolandvanrijswijk

@reseauxsansfil

[email protected]? Comments?

Please contact me!