General Discussion
  >> General Broadband Chatter


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | (show all)   Print Thread
Standard User Oliver341
(eat-sleep-adslguide) Fri 04-Oct-24 19:06:17
Print Post

Re: DoH, DNSSEC, Unbound and Pi-hole


[re: Thaumaturge] [link to this post]
 
In reply to a post by Thaumaturge:
I can see that implementing DNSSEC could be a significant overhead for net admins

For most people, enabling DNSSEC is as easy as ticking "enable" in their domain registrar's control panel.

But even for someone like myself who operates their own authoritative nameservers, it's really easy: https://bind9.readthedocs.io/en/v9.18.14/dnssec-guid...

Basically add two lines to the Bind 9 zone config and upload the dnskey to the parent nameservers (via the registrar). Bind 9 handles the rest automatically, including the zone signing key rollovers.

Oliver.
Standard User Thaumaturge
(member) Fri 04-Oct-24 21:04:39
Print Post

Re: DoH, DNSSEC, Unbound and Pi-hole


[re: Oliver341] [link to this post]
 
If it's a no-brainer like you say these days - it's been a long time since I did any serious domain admin, so I take your word for it - why doesn't everybody just do it?
Standard User Oliver341
(eat-sleep-adslguide) Fri 04-Oct-24 21:31:11
Print Post

Re: DoH, DNSSEC, Unbound and Pi-hole


[re: Thaumaturge] [link to this post]
 
It's a good question, and I wonder the same myself.

Oliver.


Register (or login) on our website and you will not see this ad.

Pages in this thread: 1 | [2] | (show all)   Print Thread

Jump to