ARIN Deploys DNSSEC Zone Signing [Archived]

OUT OF DATE?

Here in the Vault, information is published in its final form and then not changed or updated. As a result, some content, specifically links to other pages and other references, may be out-of-date or no longer available.

Posted: Wednesday, 01 July 2009

On 1 July 2009 ARIN will begin phase two of its DNSSEC project by publishing the zones that it is authoritative for under in-addr.arpa.

Because the parent zone (in-addr.arpa) is not signed, you will need to place the advertised keys as part of your DNS server configuration as defined on ARIN’s trust anchor list. The list is available for download in BIND-style and zone-file format at:

https://www.arin.net/about_us/dnssec/trust_anchors.html

The DNSSEC project will be completed in three phases. The third and final phase is allowing DS records from ARIN-issued delegations that have secured zones. View the detailed deployment plan at:

https://www.arin.net/about_us/dnssec/

To learn more about DNSSEC, please look at http://www.dnssec.net/.

Regards,

Mark Kosters
Chief Technology Officer
American Registry for Internet Numbers (ARIN)

OUT OF DATE?

Here in the Vault, information is published in its final form and then not changed or updated. As a result, some content, specifically links to other pages and other references, may be out-of-date or no longer available.