DNSSEC deployment
hello,
i deploy dnssec on dns server. not sure if possible. have 1 server domain controller , recursive dns server. our server runs windows server 2008 r2. want secure dns replies only, not want sign active directory domain.
is possible it? how can deploy it?
hi,
please review the dnssec deployment guide (word document) learn deploying dnssec windows server 2008 r2. there web version of document here: http://technet.microsoft.com/en-us/library/ee649268(ws.10).aspx
the deployment guidance discusses setting separate, secure zone signed. zone should contain hosts have static addresses because dnssec in server 2008 r2 not support dynamic updates.
dns queries hosts in zone can secured dnssec. queries resource records in other zones (that not signed) still work, these not secured.
i hope helps,
-greg
Windows Server > Network Infrastructure Servers
Comments
Post a Comment