This document provides introductory information on how DNSSEC works, how to configure BIND 9 to support some commonDNSSEC features, as well as some basic troubleshooting tips. The chapters are organized as such:
Chapter 1 covers the intended audience for this document, assumed background knowledge, and a basic introduction to
the topicof DNSSEC.
Chapter 2 covers various requirements that are needed before implementing DNSSEC, such as software
versions, hardwarecapacity, network requirements, and security changes.
Chapter 3 walks through setting up a validating resolver, more information on the validation process, as well as
examples ofusing tools to verify that the resolver is validating answers.
Chapter 4 walks through setting up a basic signed authoritative zone, explains the relationship with the parent zone,
and on-goingmaintenance tasks.
Chapter 5 provides some tips on how to analyze and diagnose DNSSEC-related problems.
Chapter 6 covers several topics, from key generation, key storage, key management, NSEC and NSEC3, to
disadvantages ofDNSSEC.
Chapter 7 provides several working examples of common solutions, with step-by-step details