|
How do I find guides?
Deploying DNSSEC is part of a portfolio of tools that you can use to enhance the security of your system. This page offers guides to understanding your system, how DNSSEC fits into the larger security framework and some basic how-to materials. Some of them contain information specific to certain audiences as well as more general discussions. (Background on the protocol and some of the supporting materials are found at About DNSSEC.) Check back often. As experience deepens, we expect to add more resources to this list.
NIST Special Publication 800-81: Secure Domain Name System (DNS) Deployment Guide. This publication from the US National Institute of Standards and Technology presents an overview of the key protocols and how they are used.
DNSSEC HOWTO: A Tutorial in Disguise (April 2005). Overview/tutorial based on RIPE’s experience deploying DNSSEC.
Step-by-Step guides, SPARTA, Inc. Guides for zone operation using BIND and the DNSSEC-Tools suite. There are two guides: The first targets DNS security operators. The second is more detailed and written for users of the dnssec-tools "tool suite". Its structured along the lines of the first document but it describes how the different operations can be performed using some of the tools available in the dnssec-tools distribution.
DNSSEC Operational Practices. This Internet Draft targets zone operators but also discusses broader issues in key management.
DNSSEC: DNS Security Extensions, Securing the Domain Name System. This site provides an in-depth collection of resources relating to DNSSEC, including background, technical papers and specifications, training resources, how-tos and pointers to major DNS-related sites on the Internet.
DNS Books. There are several good books that describe both DNS and DNSSEC, including configuration information for popular software. These include the following.
DNS and BIND by Cricket Liu, Paul Albitz.
DNS in Action: A Detailed and Practical Guide to DNS Implementation, Configuration, and Administration by A. Kabelova.
Pro DNS and BIND by Ron Aitchison.
|