Split-View DNSSEC Operational Practices
暂无分享,去创建一个
The security extensions to the Domain Name System (DNSSEC) allow for
integrity protection, whereby it is possible to make a determination
of the verity of data returned from the Domain Name System in response
to a query. Current operation of the Domain Name System also allows
for the creation of multiple views of data, where the answer returned
in response to a query is dependent on the origin of the query. Data
integrity and the ability to return possibly conflicting values as in
split-views may be construed to be mutually conflicting goals; but
this apparent dichotomy is resolvable in practice through careful
configuration. This document provides recommendations for configuring
a manageable split-view DNSSEC environment in a representative
enterprise network.