sec:dnssec
Unterschiede
Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
Beide Seiten der vorigen RevisionVorhergehende ÜberarbeitungNächste Überarbeitung | Vorhergehende Überarbeitung | ||
sec:dnssec [2023/10/30 13:56] – [DNSSEC] admin | sec:dnssec [2024/04/08 07:11] (aktuell) – [Betrieb:] admin | ||
---|---|---|---|
Zeile 1: | Zeile 1: | ||
====== DNSSEC ====== | ====== DNSSEC ====== | ||
+ | * https:// | ||
* https:// | * https:// | ||
* [[https:// | * [[https:// | ||
* https:// | * https:// | ||
* https:// | * https:// | ||
+ | * <code bash> | ||
+ | dig example.com. +multiline +dnssec # get A and RESIG Record for domain | ||
+ | dig @1.1.1.1 example.com. +multiline +dnssec +trace # trace funktioniert nicht mehr mit 8.8.8.8 | ||
+ | </ | ||
===== Testing ===== | ===== Testing ===== | ||
+ | ==== Domain: ==== | ||
+ | |||
+ | * https:// | ||
+ | * https:// | ||
+ | * https:// | ||
+ | * Überprüfung von DS und DNSKEY einer Domain:< | ||
+ | dig @8.8.8.8 example.com. DS # KSK key-id must match between DS and DNSKEY | ||
+ | dig @8.8.8.8 example.com. DNSKEY +dnssec +cd +multiline | ||
+ | </ | ||
+ | |||
+ | ==== Resolver: ==== | ||
+ | * https:// | ||
+ | * https:// | ||
+ | * <code bash>dig sigok.ippacket.stream #should return an A-Record | ||
+ | dig sigfail.ippacket.stream # should return a SERVFAIL | ||
+ | dig sigfail.ippacket.stream +cd #(check disabled - should return an A-Record)</ | ||
+ | |||
+ | Infos zum Testen: | ||
+ | |||
+ | * https:// | ||
* [[https:// | * [[https:// | ||
* https:// | * https:// | ||
Zeile 13: | Zeile 38: | ||
* https:// | * https:// | ||
+ | ===== Betrieb: ===== | ||
+ | * https:// | ||
+ | * [[https:// | ||
+ | * https:// | ||
+ | * https:// | ||
===== Troubleshooting ===== | ===== Troubleshooting ===== |
sec/dnssec.1698674194.txt.gz · Zuletzt geändert: 2023/10/30 13:56 von admin