Plenary Presentations

Monday | Tuesday | Wednesday | Thursday | Friday

FRIDAY

11:00 – 12:30

25. DNSSEC Deployment PDF
Olaf Kolkman. (30 min)

The DNSSEC specifications have been finalised about half a year ago.
RIPE NCC and other organizations are publishing signed zones and experiences are gathered. We present how DNSSEC is deployed at the RIPE NCC.

The presentation will cover three topics:

  • The Key Management procedures and the software used to implement these. RIPE NCC will maintain the private keys for several tens of zone files. All these zones will have their own key pairs and key-rollover frequencies. We'll present a birds-eye view on the problem and a our solutions to these

  • Nameserver performance measurements. We assessed the memory, CPU and network load increases for ns- pri.ripe.net and k.root-servers.net when DNSSEC is being deployed.

  • Parent-Child key exchange and the interfaces available for that. In order to build a DNSSEC infrastructure signing authority will need to be delegated from parent to child. The RIPE NCC provides the WHOIS DB as the interface for key-exchanges. We explain some of the procedural details and demonstrate a web based tool intended to ease Whois object construction.

 

26. History of RIPE. (30 min)
Olivier Martin, CERN

Back to top


This page has been updated: