Deploy360 5 January 2012

DNSSEC-Trigger

DNSSEC-Trigger from NLnet Labs is a fascinating experimental tool that solves a fundamental problem that many end-users do not have access to a local DNS resolver that supports DNSSEC.  DNSSEC-Trigger configures a local copy of the Unbound DNS server (supplied for both Windows and Mac OS X) on your laptop or desktop so that you can use DNSSEC validation even if your local DNS servers may not directly support it.  As the project page explains:

Dnssec trigger enables the end-host (laptop or desktop computer) to use DNSSEC protection for the DNS traffic.  It probes for DNSSEC capable servers and instructs a validator on localhost to use that. If it fails, the user can opt to go insecure.

This means a browser can (often) get DNSSEC capable results. It may trust results from 127.0.0.1 with the ADflag. Or it can do DNSSEC validation itself.

As this is a very useful component for testing DNSSEC, we intend to link to (or create) some tutorials relating to installing and using DNSSEC-Trigger. (If you are aware of existing tutorials, HOWTOs or blog posts, please let us know.)

Related Resources

Deploy360 1 March 2019

DNS Privacy Frequently Asked Questions (FAQ)

Almost every time we use an Internet application, it starts with a Domain Name System (DNS) transaction to map...

Deploy360 1 March 2019

IPv6 Security for IPv4 Engineers

This document provides an overview of IPv6 security that is specifically aimed at IPv4 engineers and operators. Rather than...

Deploy360 27 February 2019

Introduction to DNS Privacy

Abstract Almost every time we use an Internet application, it starts with a Domain Name System (DNS) transaction to...