training & consulting |  about the author |  forums |  Mail Me 

If you are comfortable thats OK but your browser may be giving you less than optimum performance on our site. We recommend using a version 5 browser including Mozilla

DNS Security Training

Duration: 2 days.

La formation est aussi disponible en français.

Other courses: Basic DNS, Advanced DNS, DNS and IPv6, DNS and Telephony (VoIP), DNS on Windows Servers, LDAP Courses, Telecommunications/SS7 courses.

The primary focus of the course is BIND which is available on Linux, UNIX and Windows platforms. The course is offered with Linux (Fedora Core), FreeBSD or Windows 2003 as the platform for all excercises.

Summary

Reliable, robust and secure operation of the DNS hierarchy - from the root servers to an individual domain name server - is critical to all Internet operations. The course concentrates on the use of DNSSEC for the control of Zone Transfers, DDNS and zone Integrity and especially the automation of key-rollver using established tools. While the primary focus of the course is BIND other DNS software will be discussed.

Description

Students will review the theory behind the DNS hierarchy, the DNS protocol, forward and reverse mapping zone files. DNS (DNSSEC) security is based on modern cryptographic techniques and processes. The student will learn the underlying principles without requiring mathematical knowledge. Specific implementation of shared-secret (symmetric) and public-key (asymmetric) implementations will be detailed covering Zone Transfer, Dynamic DNS (DDNS) and Zone Integrity. Secure DDNS integration with DHCP is covered and procedurea nd requirements for key management and key-rollover are illustrated. The course includes a number of hands on configuration exercises.

Audience:

The course is designed for DNS administrators, Network and System Administrators, Security specialists and those who need a thorough understanding of DNS security. Students should have taken the Basic DNS Course or have over 2 years exposure to DNS operations.

About the Instructor

Ron Aitchison is the author of Pro DNS and BIND (Apress ISBN 1-59059-494-0) which was the first book to cover the new DNS security protocols (DNSSEC). Ron has been involved in communications and networking for more years than he cares to admit and is president and founder of Zytrax, Inc. a company specializing in IP communications (wired and wireless), systems development and consulting in Montreal, Canada. He has been involved with Open Source systems for over 10 years.

Outline:

Module 1: DNS Refresher

Module 2: DNS Security Basics

Module 3: Cryptographic Introduction

Module 4: Securing Zone Transfers

Module 5: Securing DDNS

Module 6: Zone Integrity

Module 7: Zone signing

Module 6: Keyrollover and Maintenance

Module 9: Summary

Other courses: Basic DNS, Advanced DNS, DNS and IPv6, DNS and Telephony (VoIP).

Copyright © 2003 - 2009 NetWidget, Inc.
All rights reserved. Legal and Privacy
 
site by zytrax
Questions to web-master at netwidget
Page modified: July 26 2007.

Stuff

training courses

book stuff

home
short contents
full contents
notes & errata
files (1.1) zip
files (1.1) tarball

where to buy

Apress
amazon.com
barnes & noble
bookpool.com

book links

governance
dns software
libraries
security
dnssec
ipv6
dns telephony

articles

index
death of hope
Open DNS
DNSBLs
DLV
commercial DNSSEC
why DNSSEC?
short TTLs

Failover Strategies
TTLs revisited
DNSSEC Adds Value?

useful stuff

zytrax dns info
dnssec.net
bind9.net