
DNS Training Description:
Reliable, robust and secure operation of the DNS hierarchy - from the root servers to an individual domain name server - is critical to all Internet operations. The course concentrates on the use of DNSSEC for the control of Zone Transfers, DDNS and zone Integrity and especially the automation of key-rollover using established tools. While the primary focus of the course is BIND other DNS software will be discussed.
Students will review the theory behind the DNS hierarchy, the DNS protocol, forward and reverse mapping zone files. DNS (DNSSEC) security is based on modern cryptographic techniques and processes. The student will learn the underlying principles without requiring mathematical knowledge. Specific implementation of shared-secret (symmetric) and public-key (asymmetric) implementations will be detailed covering Zone Transfer, Dynamic DNS (DDNS) and Zone Integrity. Secure DDNS integration with DHCP is covered and procedures and requirements for key management and key-rollover are illustrated. The course includes a number of hands on configuration exercises.
The primary focus of the course is BIND which is available on Linux, UNIX and Windows platforms. The course is offered with Linux (Fedora Core), FreeBSD or Windows 2003 as the platform for all exercises.
DNS Training Audience:
The course is designed for DNS administrators, Network and System Administrators, Security specialists and those who need a thorough understanding of DNS security. Students should have taken the Basic DNS Course or have over 2 years exposure to DNS operations.
DNS Training Course duration:
2 days
DNS Training Course outline:
Module 1: DNS Refresher
Module 2: DNS Security Basics
Module 3: Cryptographic Introduction
Module 4: Securing Zone Transfers
Module 5: Securing DDNS
Module 6: Zone Integrity
Module 7: Zone signing
Module 8: Keyrollover and Maintenance
Module 9: Summary