
This is the Title of the Book, eMatter Edition
Copyright © 2007 O’Reilly & Associates, Inc. All rights reserved.
172
|
Chapter 6: Securing Domain Name Services (DNS)
software, and, similarly, know and use security services provided by your DNS-regis-
tration provider. Network Solutions and other top-level domain registrars all offer
several change-request security options, including PGP. Make sure that your pro-
vider requires at least email verification of all change requests for your name
domains!
Selecting a DNS Software Package
The most popular and venerable DNS software package is BIND. Originally a gradu-
ate-student project at UC Berkeley, BIND is now relied on by thousands of sites
worldwide. The latest version of BIND, v9, was developed by Nominum Corporation
under contract to the Internet Software Consortium (ISC), its official maintainers.
BIND has historically been and continues to be the reference implementation of the
Internet Engineering Task Force’s (IETF’s) DNS standards. BIND Version 9, for
example, provides the most complete implementation thus far of the IETF’s new
DNSSEC standards for DNS security. Due to BIND’s importance and popularity, the
better part of this chapter will be about securing BIND.
But BIND has its detractors. Like Sendmail, BIND has had a number of well-known
security vulnerabilities over the years, some of which have resulted in considerable
mayhem. Also like ...