Speaker
Tamas Csillag
(PCH.net)
Description
PCH is providing DNSSEC service for those who ask for it.
Up until recently the zone operator needed to choose if they sign their zones themselves or ask us to do it for them.
By utilizing RFC 8901 the operator of a zone can do the signing themselves and serve the signed zone on their authoritatives and have an external party do it for their systems as well to increase resiliency and autonomy.
This is a talk about how we implemented "Model 1" of RFC 8901 using knot dns offline-ksk functionality.
Talk duration | 10 Minutes (+5 for Q&A) |
---|---|
Other conferences? | ICANN83 at Prague |
Primary author
Tamas Csillag
(PCH.net)