Hurricane Electric's IPv6 Tunnel Broker Forums

Tunnelbroker.net Specific Topics => Questions & Answers => Topic started by: snarked on April 21, 2010, 11:21:56 PM

Title: DNSSEC on Reverse IPv6 zones via HE?
Post by: snarked on April 21, 2010, 11:21:56 PM
With the DNS root data being signed as of July 1, 2010, this got me thinking.  Will HE offer DNSSEC for our tunnels' reverse zones?  We already have may have 3 DNS servers for the reverse zones, but there's no place to add DS information....

Is this on the list of things to add?  Will it be ready in July?  Will HE secure its main reverse zone ("0.7.4.0.1.0.0.2.ip6.arpa")?  (And, will ns1.he.net ever get an IPv6 address?)


PS:  Demanding, aren't I?  ;-)
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: broquea on April 22, 2010, 12:03:03 AM
Maybe in the future, no changes to production equipment at this time.
NS1 gets one when you can promise that someone dual-stacked with broken IPv6 connectivity won't have issues when all authoritative NS are on both stacks. :D
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: snarked on April 22, 2010, 11:17:49 AM
Aside - regardin NS1 and IPv6:  Isn't that "their" problem, not yours?

DNSSEC:  :-(

(Not to say that I've implemented it either.  Even with BIND, it's not easy.)
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: broquea on April 22, 2010, 12:12:35 PM
And Google white-lists why? ;)

Similar principal, we provide web hosting (and now DNS hosting) where our ns1-5 are the authoritative NS, so this configuration keeps the first/primary/etc NS available even to broken IPv6 configured machines, and thus our customers websites don't get a "slow" feel with waiting 30-60s for broken IPv6 connectivity to time out and perform lookups against our NS over IPv4.
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: jimb on April 22, 2010, 03:40:12 PM
Ironic how Teredo and 6to4, meant to speed IPv6 adoption, actually results in slowing it down because of the need to do things like this.
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: HLFH on September 03, 2019, 03:34:53 AM
Hello  :)


Any updates for DNSSEC support on Reverse IPv6 zones via HE?

Thanks,
HLFH
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: snarked on September 04, 2019, 12:50:45 AM
Although HE hasn't updated this topic, I can say that all my zones, including reverse zones, are DNSSEC signed and seemed to be served properly, but there isn't a delegation chain.  ISC shouldn't have shut down its DLV function because of this, but it closed in 2017.

Providing signatures where the chain is lacking may be a bandwidth waste, but at least it doesn't break the DNS.
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: rbgidcouk on February 10, 2021, 12:06:07 AM
I have this concern too. I have a tunnel-connected site (no other viable option) that hosts an authoritative DNS server and I'd really like to secure rDNS for those addresses.
Title: Re: DNSSEC on Reverse IPv6 zones via HE?
Post by: tlhackque on February 17, 2022, 05:14:48 AM
In the 12 years since this issue was raised, DNSSEC adoption has (slowly) increased - as have attacks on the DNS.

The work-around of ISC's DLV, which could provide an alternate trust path for orphaned signed reverse zones has been discontinued.

The technology for supporting DNSSEC has matured - including RFCs 7344 and 8078, which largely automate the process of updating parent zones via CDS/CDNSKEY records.

It would be helpful if DNSSEC support could be provided for reverse zones.