CertaDNS

DNS Security Practitioner

Operating a signed zone: key roles and algorithms, the rollover that breaks delegations, authenticated denial and zone walking, CAA against ACME, registrar locks, resilience, and the dangling records that outlive the services behind them.

lessons
19
total
3 h
level
Intermediate

Assumes Domain Security Fundamentals.

You will be able to

  • Read a zone’s key set and say whether it uses separate keys or one
  • Choose a signing algorithm, and say what to migrate off
  • Perform a KSK rollover without breaking the delegation
  • Say what an attacker learns from your authenticated denial
  • Write a CAA set that constrains issuance without blocking your own ACME client
  • Distinguish a transfer lock from a registry lock in RDAP output
  • Find dangling CNAME, NS and MX records and retire services safely

Syllabus

  1. 1. How a Zone Is Signed

    Key roles, the algorithms worth using, and the signature window that expires.

    1. One key or two11 min
    2. Which algorithm11 min
    3. Signatures expire11 min
  2. 2. Authenticated Denial

    Why NSEC enumerates your zone, what NSEC3 fixed, and what replaced both.

    1. NSEC enumerates your zone11 min
    2. What NSEC3 fixed, and did not11 min
    3. Answering on the fly10 min
  3. 3. Key Rollovers

    The two rollovers, the DS update that breaks delegations, and automating it.

    1. The rollover that breaks delegations12 min
    2. Rolling the signing key11 min
    3. Letting the parent update itself10 min
  4. 4. Constraining Issuance

    Reading a CAA set, and writing one that does not block your own ACME client.

    1. Reading a CAA set11 min
    2. CAA against your own ACME client11 min
  5. 5. The Registrar Layer

    Reading lock state from RDAP, and the account that outranks every DNS control.

    1. Reading lock state11 min
    2. The account outranks every record11 min
  6. 6. Authoritative Resilience

    Single-provider risk, running two, and what has to stay in sync between them.

    1. One provider is one outage11 min
    2. Running two12 min
  7. 7. Zone Transfer

    AXFR, TSIG and NOTIFY, and what an open transfer hands to anyone who asks.

    1. How a secondary stays current11 min
    2. An open transfer10 min
  8. 8. Records That Outlive Their Services

    Dangling CNAME, NS and MX, and the retirement discipline that prevents all three.

    1. Three kinds of dangling11 min
    2. Retiring a service safely11 min
  9. 9. Final assessment

    15 scenario questions · 80% to pass · unlimited retakes

    What the assessment covers

DNS Security Practitioner

  • Complete every lesson in DNS Security Practitioner
  • Pass the DNS Security Practitioner assessment with at least 80%
About the certificates

CertaDNS Engineering · last reviewed