Repository files navigation Support for CDS/CDNSKEY/CSYNC updates
RFC 7344 : Automating DNSSEC Delegation Trust Maintenance
RFC 8078 : Managing DS Records from the Parent via CDS/CDNSKEY
RFC 9615 : Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's Operator
Support in domain registries
Support in domain registrars
Registrar
CDS
CDNSKEY
Delete
Bootstrap from insecure
Bootstrap via _dsboot
CSYNC
Notes
Glauca
Yes
Yes
Yes
All name servers must respond the same, TCP-only
Yes
?
Docs
Domainnameshop
Yes
Yes
Yes
All name servers must respond the same, TCP-only
Possible future
No
part of BIND 9
can use both CDS and CDNSKEY
can produce DSset file or script for nsupdate
no support for bootstrapping from insecure
no support for DNSSEC delete
part of FRED
only CDNSKEY records
supports bootstrapping from insecure
almost zero documentation :(
rcdss (RIPE NCC CDS Scanner)
written in Python using dnspython
reads RIPE Database objects
produces RPSL-like diff objects
multithreaded scanning
no support for bootstrapping from insecure
publishes both CDS and CDNSKEY records
automated KSK rollover based on feedback from the parent
controlled by cds-cdnskey-publish config option
can also submit DS change directly using DDNS
publishes both CDS and CDNSKEY records
automated KSK rollover with checkds option
publishes both CDS and CDNSKEY records
controlled by pdnsutil set-publish-cds
requires manual KSK rollover
synthesis of _dsboot record via LUA records: Setup LUA records ; LUA module ; pdns config
About
Info about CDS update support
Resources
License
Stars
Watchers
Forks
You can’t perform that action at this time.