Configure DNSSEC
-
Enable DNSSEC on the NetScaler appliance.
-
Create a zone signing key and a key signing key for the zone.
-
Add the two keys to the zone.
-
Sign the zone with the keys.
-
ADNS—NetScaler is the ADNS and generates the signatures itself.
-
Proxy—NetScaler acts as a DNSSEC proxy. It is assumed that the NetScaler is placed in front of the ADNS/LDNS servers in a trusted mode. The ADC acts only as a proxy caching entity and does not validate any signatures.
Enable and disable DNSSEC
Enable or disable DNSSEC by using the CLI
- set dns parameter -dnssec ( ENABLED | DISABLED )
- show dns parameter
> set dns parameter -dnssec ENABLED
Done
> show dns parameter
DNS parameters:
DNS retries: 5
.
.
.
DNSEC Extension: ENABLED
Max DNS Pipeline Requests: 255
Done
Enable or disable DNSSEC by using the GUI
-
Navigate to Traffic Management > DNS.
-
In the details pane, click Change DNS settings.
-
In the Configure DNS Parameters dialog box, select or clear the Enable DNSSEC Extension check box.
Create DNS keys for a zone
suffix.key is appended to the names of the public components of the keys. The suffix.private is appended to the names of their private components. The appending happens automatically.
/nsconfig/dns/ directory, but it is not automatically published in the zone. After you create a key by using the create dns key command, you must explicitly publish the key in the zone by using the add dns key command. The process of generating a key is separate from the process of publishing the key in a zone to enable you to use alternative means to generate keys. For example, you can import keys generated by other key-generation programs (such as bind-keygen) by using the Secure FTP (SFTP) and then publish the keys in the zone. For more information about publishing a key in a zone, see Publish a DNS key in a zone.
Create a DNS key by using the CLI
create dns key -zoneName <string> -keyType <keyType> -algorithm <algorithm> -keySize <positive_integer> -fileNamePrefix <string>
> create dns key -zoneName example.com -keyType zsk -algorithm RSASHA256 -keySize 1024 -fileNamePrefix example.com.zsk.rsasha1.1024
File Name: /nsconfig/dns/example.com.zsk.rsasha1.1024.key (public); /nsconfig/dns/example.com.zsk.rsasha1.1024.private (private); /nsconfig/dns/example.com.zsk.rsasha1.1024.ds (ds)
This operation may take some time, Please wait...
Done
> create dns key -zoneName example.com -keyType ksk -algorithm RSASHA512 -keySize 4096 -fileNamePrefix example.com.ksk.rsasha1.4096
File Name: /nsconfig/dns/example.com.ksk.rsasha1.4096.key (public); /nsconfig/dns/example.com.ksk.rsasha1.4096.private (private); /nsconfig/dns/example.com.ksk.rsasha1.4096.ds (ds)
This operation may take some time, Please wait...
Done
Create a DNS key by using the GUI
-
Navigate to Traffic Management > DNS.
-
In the details area, click Create DNS Key.
-
Enter values for the different parameters and click Create.Create a DNS keyNote: To modify the file name prefix of an existing key:
-
Click the arrow next to the Browse button.
-
Click either Local or Appliance (depending on whether the existing key is stored on your local computer or in the
/nsconfig/dns/directory on the appliance) -
Browse to the location of the key, and then double-click the key. The File Name Prefix box is populated with only the prefix of the existing key. Modify the prefix accordingly.
-
Publish a DNS key in a zone
bind-keygen program), ensure that the key is added to the /nsconfig/dns/ directory. Then publish the key in the zone. Use the ADC GUI to add the key to the /nsconfig/dns/ directory. Or, use some other program to import the key to the directory, such as the Secure FTP (SFTP).
add dns key command for each public-private key pair that you want to publish in a given zone. If you created a ZSK pair and a KSK pair for a zone, use the add dns key command to first publish one of the key pairs in the zone. Repeat the command to publish the other key pair. For each key that you publish in a zone, a DNSKEY resource record is created in the zone.
Publish a key in a zone by using the CLI
- add dns key <keyName> <publickey> <privatekey> [-expires <positive_integer> [<units>]] [-notificationPeriod <positive_integer> [<units>]] [-TTL <secs>]
- show dns zone [<zoneName> | -type <type>]
> add dns key example.com.zsk example.com.zsk.rsasha1.1024.key example.com.zsk.rsasha1.1024.private
Done
> add dns key example.com.ksk example.com.ksk.rsasha1.4096.key example.com.ksk.rsasha1.4096.private
Done
> show dns zone example.com
Zone Name : example.com
Proxy Mode : NO
Domain Name : example.com
Record Types : NS SOA DNSKEY
Domain Name : ns1.example.com
Record Types : A
Domain Name : ns2.example.com
Record Types : A
Done
Publish a key in a DNS zone by using the GUI
Configure a DNS key
Configure a key by using the CLI
- set dns key <keyName> [-expires <positive_integer> [<units>]] [-notificationPeriod <positive_integer> [<units>]] [-TTL <secs>]
- show dns key [<keyName>]
> set dns key example.com.ksk -expires 30 DAYS -notificationPeriod 3 DAYS -TTL 3600
Done
> show dns key example.com.ksk
1) Key Name: example.com.ksk
Expires: 30 DAYS Notification: 3 DAYS TTL: 3600
Public Key File: example.com.ksk.rsasha1.4096.key
Private Key File: example.com.ksk.rsasha1.4096.private
Done
Configure a key by using the GUI
-
Navigate to Traffic Management > DNS > Keys.
-
In the details pane, click the key that you want to configure, and then click Open.
-
In the Configure DNS Key dialog box, modify the values of the following parameters as shown:
-
Expires—expires
-
Notification Period—notificationPeriod
-
TTL—TTL
-
-
Click OK.
Sign and unsign a DNS zone
Sign a zone by using the CLI
- sign dns zone <zoneName> [-keyName <string> ...]
- show dns zone [<zoneName> | -type (ADNS | PROXY | ALL)]
- save config
> sign dns zone example.com -keyName example.com.zsk example.com.ksk
Done
> show dns zone example.com
Zone Name : example.com
Proxy Mode : NO
Domain Name : example.com
Record Types : NS SOA DNSKEY RRSIG NSEC
Domain Name : ns1.example.com
Record Types : A RRSIG NSEC
Domain Name : ns2.example.com
Record Types : A RRSIG
Domain Name : ns2.example.com
Record Types : RRSIG NSEC
Done
> save config
Done
Unsign a zone by using the CLI
- unsign dns zone <zoneName> [-keyName <string> ...]
- show dns zone [<zoneName> | -type (ADNS | PROXY | ALL)]
> unsign dns zone example.com -keyName example.com.zsk example.com.ksk
Done
> show dns zone example.com
Zone Name : example.com
Proxy Mode : NO
Domain Name : example.com
Record Types : NS SOA DNSKEY
Domain Name : ns1.example.com
Record Types : A
Domain Name : ns2.example.com
Record Types : A
Done
Sign or unsign a zone by using the GUI
-
Navigate to Traffic Management > DNS > Zones.
-
In the details pane, click the zone that you want to sign, and then click Sign/Unsign.
-
In the Sign/Unsign DNS Zone dialog box, do one of the following:
-
To sign the zone, select the check boxes for the keys (zone signing key and key signing key) with which you want to sign the zone.You can sign the zone with more than one zone signing key or key signing key pair.
-
To unsign the zone, clear the check boxes for the keys (zone signing key and key signing key) with which you want to unsign the zone.You can unsign the zone with more than one zone signing key or key signing key pair.
-
-
Click OK.
View the NSEC records for a given record in a zone
View the NSEC record for a given record in a zone by using the CLI
show dns nsecRec [<hostName> | -type (ADNS | PROXY | ALL)]
> show dns nsecRec example.com
1) Domain Name : example.com
Next Nsec Name: ns1.example.com
Record Types : NS SOA DNSKEY RRSIG NSEC
Done
View the NSEC record for a given record in a zone by using the GUI
-
Navigate to Traffic Management > DNS > Records > Next Secure Records.
-
In the details pane, click the name of the record for which you want to view the NSEC record. The NSEC record for the record you select is displayed in the Details area.
Remove a DNS key
Remove a key from the NetScaler by using the CLI
- rm dns key <keyName>
- show dns key <keyName>
> rm dns key example.com.zsk
Done
> show dns key example.com.zsk
ERROR: No such resource [keyName, example.com.zsk]
Remove a key from the NetScaler by using the GUI
-
Navigate to Traffic Management > DNS > Keys.
-
In the details pane, click the name of the key that you want to remove from the ADC, and then click Remove.