DNSSEC deployment


hello,

i deploy dnssec on dns server. not sure if possible. have 1 server domain controller , recursive dns server. our server runs windows server 2008 r2. want secure dns replies only, not want sign active directory domain.

 

is possible it? how can deploy it?

hi,

please review the dnssec deployment guide (word document) learn deploying dnssec windows server 2008 r2. there web version of document here:  http://technet.microsoft.com/en-us/library/ee649268(ws.10).aspx

the deployment guidance discusses setting separate, secure zone signed. zone should contain hosts have static addresses because dnssec in server 2008 r2 not support dynamic updates.

dns queries hosts in zone can secured dnssec. queries resource records in other zones (that not signed) still work, these not secured.

i hope helps,

-greg



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2