- 17-12-21Wij werken gewoon thuis door
- 05-11-21Mond- en neusmasker vanaf 6 november bij BIT verplicht
- 14-10-21Nationale Datacenter Dag 9 november 2021
- 12-10-21Plaatsing nieuwe drycooler voor BIT-2A
- 03-08-21Wegwerkzaamheden BIT-2 van 16 aug tot en met 25 sep
- 23-07-21DDoS aanvallen naar BIT infra
- 25-06-21Mond- en neusmasker niet meer verplicht bij BIT
- 14-04-21Untangle haalt de complexiteit uit netwerkbeveiliging
- 03-03-21Vacature Netwerk Engineer
- 02-03-21Update RFO netwerk incident 17 februari 2021
BIT now has reverse DNS zones signed with DNSSEC
Internet operates with domain names and IP addresses. An IP address is connected to a domain name and that connection has been protected at BIT for the last few years by the implementation of DNSSEC signatures on the DNS traffic.
Clients who wish to do so can enable DNSSEC for their domain names in the BIT-Portal. Simply put, this means that answer of the DNS cannot be altered ‘on route’, which creates more security that when you access httsp://example.nl, you are truly accessing the servers of example.nl.
Since the start of august, BIT also has all its ‘reverse DSN zones’ signed with DNSSEC. Both for IPv4 as for IPv6 addresses! Because domain names come with IP addresses, but you could (roughly) say that IP addresses are always connected to a name. This is called the ‘reverse’ of an IP address and is also in the DNS, like domain names. Since august, BIT has also secured this ‘reverse DNS’ with DNSSEC!
Why now? While we have been implementing ‘forward’ DNSSEC for years? The step from IP to domain name is much less important for the safe operation of the internet than the step from domain name to IP. The chance of someone causing problems by ‘changing’ the name connected to an IP address into something that is not correct, is very small. The biggest risk is in ‘changing’ the IP address connected to a domain name to redirect internet traffic to an incorrect site. We have mostly activated this DNSSEC protection ‘because we can’ and we like to do things thoroughly.
Did you, in consultation with BIT, get the reverses for IP addresses delegated to you and did you arrange their signing yourself? Give us a call, so we can ensure that the delegation to you is also secure!
By: Sander Smeenk