Hello everyone!

After months of keeping our secrets, we would like to share with you a preview 
of a new DNSSEC implementation in Knot DNS. The new DNSSEC will be one of the 
key features for the upcoming Knot DNS 2.0.

If you are watching our source repository, you may have noticed a tag v1.99.0 
appearing silently at the end of 2014. At that time, Knot DNS was already 
using the newly implemented DNSSEC, but the only visible change was a 
different key format. And internally, GnuTLS/Nettle was replaced OpenSSL for 
cryptographic operations.

Today, CZ.NIC Labs releases Knot DNS 1.99.1. The next step towards the 2.0. 

Knot DNS 1.99.1 adds initial support for DNSSEC KASP (Key And Signature 
Policy). This is our vision of real-world DNSSEC deployment. Essentially, you 
define a policy (used algorithm, key sizes, key lifetime, signature lifetime, 
etc.) and the server will do the heavy lifting. It will generate keys and 
publish/roll them correctly, so you don't have to compute and set timing
meta-data on private keys manually.

At the moment, the KASP support is quite limited: Single algorithm, single 
KSK, and single ZSK can be specified in the policy. The server is able to 
generate initial keys and perform ZSK rollovers (key pre-publish method).
More features are coming soon.

A documentation on KASP [1] is currently available on the project wiki, 
including the reference manual for a new management utility keymgr [2].

[1] https://gitlab.labs.nic.cz/labs/knot/wikis/kasp-setup
[2] https://gitlab.labs.nic.cz/labs/knot/wikis/kasp-keymgr-reference

Source archives are available as usual:

https://secure.nic.cz/files/knot-dns/knot-1.99.1.tar.xz
https://secure.nic.cz/files/knot-dns/knot-1.99.1.tar.gz

Please note, that Knot DNS 1.99.1 is not ready to replace Knot DNS 1.6.x.

We are looking forward to hear some feedback from you. And we are happy to 
answer all your questions and concerns.

Best regards,

Jan

--
 Jan Včelák, Knot DNS
 CZ.NIC Labs https://www.knot-dns.cz
 --------------------------------------------
 Milešovská 5, 130 00 Praha 3, Czech Republic
 WWW: https://labs.nic.cz https://www.nic.cz

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
knot-dns-users mailing list
[email protected]
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

Reply via email to