PING

Measuring DNSSEC keying "drift" between parent and child


Listen Later

This time on PING, Peter Thomassen from SSE and DEsec.io discusses his analysis of the failure modes of CDS and CDNSKEY records between parent and child in the DNS. These records are used to provide in-band signalling of the DS record, fundamental to the maintenance of a secure path from the trust anchor to the delegation through all the intermediate parent and grandparent domains. Many people use out-of-band methods to update this DS information, but the CDS and the CDNSKEY records are designed to signal this critical information inside the DNS, avoiding many of the pitfalls of passing through a registry-registrar web service.


The problem is, as Peter has discovered, the information across the various nameservers (denoted by the NS record in the DNS) of the child domain can get out of alignment, and the tests a parent zone need to do checking CDS and CDNSKEY information aren't sufficiently specified to wire down this risk.


Peter performed a "meta analysis" inside a far larger cohort of DNS data captured by Florian Steurer and Tobias Fiebig at the Max Planck Institute and discovered a low but persisting error rate, a drift in the critical keying information between a zones NS and the parent. Some of these related to transitional states in the DNS (such as when you move registry or DNS provider) but by no means all, and this has motivated Peter and his co-authors to look at improved recommendations for managing CDS/CDNSKEY data, to minimise the risk of inconsistency, and the consequent loss of secure entry path to a domain name.


Read more about DNSSEC delegation at the APNIC Blog, and the IETF:

  • Authenticated bootstrapping of DNSSEC delegations (NIls Wisiol, APNIC Blog March 2022)
  • Measurement of CDS/CDNSKEY inconsistencies (IETF119 Presentation, March 2024)
  • Generalised DNS NOTIFY (IETF Draft)
...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,976 Listeners

Radiolab by WNYC Studios

Radiolab

43,946 Listeners

Risky Business by Patrick Gray

Risky Business

365 Listeners

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,260 Listeners

Talk Python To Me by Michael Kennedy

Talk Python To Me

590 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

215 Listeners

Click Here by Recorded Future News

Click Here

412 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,879 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

34 Listeners

The Hedge by Russ White

The Hedge

15 Listeners

Signals and Threads by Jane Street

Signals and Threads

72 Listeners

The RIPE Labs Podcast by RIPE Labs Editor

The RIPE Labs Podcast

1 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

47 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

315 Listeners