Hurricane Electric's IPv6 Tunnel Broker Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

Welcome to Hurricane Electric's Tunnelbroker.net forums!

Author Topic: DNSSEC for slaves?  (Read 346 times)

sporkv6

  • Newbie
  • *
  • Posts: 7
    • View Profile
DNSSEC for slaves?
« on: March 09, 2017, 05:55:32 PM »

I'm new to DNSSEC with PowerDNS, so I'm possibly fighting two things at once - my ignorance of how PowerDNS compares to BIND in setting things up on my master, and then the possibility that HE.net DNS does not support/transfer all the necessary records.

Can anyone give a solid yes/no on whether *slaving* DNSSEC should work here or not?

I suspect not - when I query my own master for DS records, I get them, and when I query HE, no errors, but also no DS records.  Validated my domain, made sure serials match between master/slave, etc.
Logged

sporkv6

  • Newbie
  • *
  • Posts: 7
    • View Profile
Re: DNSSEC for slaves?
« Reply #1 on: March 10, 2017, 09:39:21 AM »

Bump: Anyone?

To simplify, does HE.net's DNS service, when used as a slave/secondary, support DNSSEC?
Logged

broquea

  • Sr. Network Engineer, HE.NET AS6939
  • Administrator
  • Hero Member
  • *****
  • Posts: 1671
    • View Profile
    • Another IPv6 Blog...
Re: DNSSEC for slaves?
« Reply #2 on: March 10, 2017, 10:29:43 AM »

DNSSEC support is not available as of yet.
Logged

primordial

  • Newbie
  • *
  • Posts: 3
    • View Profile
Re: DNSSEC for slaves?
« Reply #3 on: May 14, 2017, 01:47:27 PM »

Any chance of getting a status update on this feature?

It's been years that many of us have been waiting patiently. Last discussion in the forum was almost 2 years ago, and the home page still just says "We're looking into this now" which also hasn't changed in years.

Should we give up hope? HE is _awesome_ at being a proponent of IPv6 everywhere, but doesn't seem to have the same fondness for making sure it stays secure and trustworthy.
Logged

snarked

  • Hero Member
  • *****
  • Posts: 688
    • View Profile
Re: DNSSEC for slaves?
« Reply #4 on: May 14, 2017, 01:59:13 PM »

It will transfer the DNSSEC records as part of the zone data and store it, but it doesn't serve the data so no signatures go out in response to queries.  Also, there is currently no way to give HE the DS record content (for reverse zones only -- obviously).
Logged