lpic-303-v3

LPIC-303 V3 study materials

View on GitHub

331.4 - DNS and Cryptography

Key Knowledge Areas:

Partial list of the used files, terms and utilities:

Terms

CAA, DS, DNSKEY, NSEC, NSEC3, NSEC3PARAM, RRSIG, and TLSA records

list of DNS record types

CAA

DNS certification authority authorization

DANE

DNS-based authentication of named entities

DNS over HTTPS

DNS over HTTPS

DNS over TLS

DNS over TLS

DNSSEC

domain name system security extensions

Multicast DNS

multicast DNS

TSIG

transaction signature

Files

named.conf

(Fedora: bind.x86_64)
/etc/named.conf

Utilities

dnssec-keygen

(Fedora: bind-dnssec-utils.x86_64)
man 8 dnssec-keygen

dnssec-keymgr (wrapper for dnssec-keygen, dnssec-settime)

(Fedora: bind-dnssec-utils.x86_64)
man 8 dnssec-keymgr

dnssec-signzone

(Fedora: bind-dnssec-utils.x86_64)
man 8 dnssec-signzone

dnssec-settime

(Fedora: bind-dnssec-utils.x86_64)
man 8 dnssec-settime

dnssec-dsfromkey

(Fedora: bind-dnssec-utils.x86_64)
man 8 dnssec-dsfromkey

rndc

(Fedora: bind.x86_64)
man 8 rndc

dig

(Fedora: bind-utils.x86_64)
man 1 dig

delv

(Fedora: bind-utils.x86_64)
man 1 delv

openssl

(Fedora: openssl.x86_64)
man 1 openssl

Notes

BIND versions

BIND DNSSEC authoritative configuration

DNSSEC key management and zone signing

Reloading zones after signing

CAA configuration

DANE configuration

TSIG configuration

BIND 9 and later: TSIG example

BIND DNSSEC recursive configuration

BIND DNSSEC troubleshooting