Sign in to follow this  
Followers 0

DNSSEC et Bind9 sur serveur Squeeze

2 posts in this topic

Posted · Report post

Bonjour à tous,

Je tente d'implémenter un resolver DNSSEC sur mon serveur afin de valider les clés DKIM des mails que je reçois.

J'ai configuré mon resolv.conf pour aller demander à bind9 de résoudre les requêtes.

/etc/resolv.conf


nameserver 127.0.0.1

/etc/bind/named.conf.options

options {

	 directory "/var/cache/bind";

	 forwarders {

			 213.186.33.99;

	 };

	 auth-nxdomain no; # conform to RFC1035

	 listen-on-v6 { ::1; };

	 listen-on { 127.0.0.1; };

	 dnssec-enable yes;

	 dnssec-validation yes;

	 dnssec-lookaside auto;

	 allow-recursion { 127.0.0.1; };

};


managed-keys {

[.....]

}

Les requêtes avec dig utilisent bien DNSSEC et me donnent un SERVFAIL quand il faut :

dig www.dnssec-failed.org +dnssec

; <<>> DiG 9.7.3 <<>> www.dnssec-failed.org +dnssec

;; global options: +cmd

;; Got answer:

;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 37976

;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:

; EDNS: version: 0, flags: do; udp: 4096

;; QUESTION SECTION:

;www.dnssec-failed.org.		 IN	 A

;; Query time: 3 msec

;; SERVER: 127.0.0.1#53(127.0.0.1)

;; WHEN: Sat Jan 19 15:40:46 2013

;; MSG SIZE rcvd: 50

Seulement voilà, j'ai l'impression que le système en lui-même n'utilise pas DNSSEC car je peux toujours pinger ce domaine :

ping www.dnssec-failed.org

PING www.dnssec-failed.org.fr (94.23.128.152) 56(84) bytes of data.

64 bytes from 94.23.128.152: icmp_req=1 ttl=123 time=4.71 ms

...

Est-ce un comportement normal ?

Share this post


Link to post
Share on other sites

Posted · Report post

Et bien, j'ai l'impression que DNSSEC ne passionne pas les foules :)

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0