DNSSEC deployment guide (Beta) for Windows Server 2008 R2

Published 13 February 09 03:07 PM

Check out the Windows Server 2008 R2 DNSSEC Deployment Guide here:

http://www.microsoft.com/downloads/details.aspx?FamilyID=7a005a14-f740-4689-8c43-9952b5c3d36f&DisplayLang=en

Please note that this is a Beta guide.  Your feedback is most welcome!

DNSSEC also features in the "What's New in DNS in Windows 2008 R2 page": http://technet.microsoft.com/en-us/library/dd378952.aspx

by sseshad
Filed under:

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

# jgurtz said on February 20, 2009 12:01 PM:

It's great that windows dns will, at long last, finally support dnssec!  As everyone involved in dns surely knows, it is the real way to fix the Kaminsky bug.

Unfortunately, I see in this deployment guide:

"Dynamic updates are automatically disabled on a DNSSEC-signed zone.  Windows Server 2008 R2 DNS server supports the signing of static zones only.  You must use Dnscmd.exe or DNS Manager to add more resource records to a zone and the zone must be re-signed."

Well, at least DNSSEC will be available for Internet facing zones which are normally static.  What about all these windows clients on the network which send dynamic updates?  I can't see moving all dhcp client PCs to static addressing or 100% dhcp reservations.  Pretty unmanageable for more than a handful of hosts.  One workaround I see would be clients doing dynamic updates to a DNSSEC zone on a server running BIND using the nsupdate client tool.  the Windows AD/DNS would then be a secondary to the BIND infrastructure.

Looking forward, does Microsoft intend for DNSSEC to be an "Internet only" feature and intend for clients to continue using a proprietary secure dynamic update protocol for internal windows hosts?

Will secure dynamic updates ( tsig(0) ) to DNSSEC signed zone be added in the future?

Also, command-line stuff is great, wonderful for those times when things need to be scripted in a scalable way.  Still, this is Windows after all, and a useful gui is one of the reasons why one would use Windows instead of Linux, etc...  Will there be future integration of DNSSEC key generation and zone  signing into the DNS manager snap-in?  A stop gap measure might be a simple .Net tool that automates dnscmd.exe

Thanks though, good to see progress on this front!

Leave a Comment

(required) 
(optional)
(required) 

  
Enter Code Here: Required

About sseshad

Shyam Seshadri is the Program Manager in Microsoft responsible for the Windows Domain Name System (DNS) server and client products.

This Blog

Syndication

Page view tracker