★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/host_security_article-2341.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Host Security 1/20/2001 0:17

Securing DNS with Transaction Signatures

Linux.ie
Posted By: Benjamin D. Thomas
1/20/2001

The DNS works on a question-answer model. If a client needs information from the DNS it sends a question to a DNS server and the server returns an answer. Until recently it was only possible for a server to examine a question and determine whether or not to answer it based on the IP address the question originated from. This is not ideal. Authentication using source IP address alone is considered insecure. Transaction Signatures, or TSIG for short, add cryptographic signatures as a method of authenticating a DNS conversation. It uses a shared secret to establish trust between the communicating parties.

TSIG is used to ensure that DNS information purporting to be from a certain server is actually from that server. I have mostly put it to use to authenticate zone transfers between master and slave nameservers. I want to be sure that my slave nameserver is never fooled into accepting a copy of my zone from an imposter who spoofs my master nameserver's IP address.


Click here to go to this article.

Microsoft outsources some DNS servers to Linux
Jan 29

Linux Security Week - January 29th 2001
Jan 29

Call For Testers: New Secure ftpd
Jan 29

Web war rages over DVD-cracking site
Jan 28

Preview of Steal this Computer Book 2
Jan 28

Top Ten Secure Shell FAQs
Jan 28

SSL is not a magic bullet
Jan 28

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000