Migrating a high-value domain while maintaining inner peace Roland - - PowerPoint PPT Presentation

migrating a high value domain while maintaining inner
SMART_READER_LITE
LIVE PREVIEW

Migrating a high-value domain while maintaining inner peace Roland - - PowerPoint PPT Presentation

Migrating a high-value domain while maintaining inner peace Roland van Rijswijk - Deij roland.vanrijswijk@surfnet.nl Why migrate? We had a fairly complex set-up with shared keys We were using an old version of OpenDNSSEC that did


slide-1
SLIDE 1

Migrating a high-value domain while maintaining inner peace

Roland van Rijswijk - Deij roland.vanrijswijk@surfnet.nl

slide-2
SLIDE 2 SURFnet: we make innovation work

Why migrate?

  • We had a fairly

complex set-up with shared keys

  • We were using an
  • ld version of

OpenDNSSEC that did not really support this

2
slide-3
SLIDE 3 SURFnet: we make innovation work

Guiding principles

3
slide-4
SLIDE 4 SURFnet: we make innovation work

Guiding principles

4
slide-5
SLIDE 5 SURFnet: we make innovation work

Guiding principles

  • Manual zone editing shall be kept to a minimum

– Less room to make (stupid) mistakes in a high stress environment

  • The migration must take place as quickly as

possible

– Preferable within a day

5
slide-6
SLIDE 6 SURFnet: we make innovation work

Preparing

6
slide-7
SLIDE 7 SURFnet: we make innovation work

Preparing

7

Situation on source signer Situation on destination signer

KSKsrc,act ZSKsrc,act ZSKdst,act RR KSKdst,act DSdst,act KSKdst,act ZSKdst,act ZSKsrc,act RR KSKsrc,act

slide-8
SLIDE 8 SURFnet: we make innovation work

Testing with a live domain

8

➊ ➋ ➌

slide-9
SLIDE 9 SURFnet: we make innovation work

Actual migration

  • We performed the actual migration on the

4th of July

  • Migration took about one day
  • Nobody noticed anything, and that is exactly

what we had hoped for

9
slide-10
SLIDE 10 SURFnet: we make innovation work

Lessons learned

  • Providing input based on our experience to

draft-koch-dnsop-dnssec-operator-change http:/ /bit.ly/draft-koch

  • Published detailed document

about our process and blogged about it on our DNSSEC blog https:/ /dnssec.surfnet.nl/

10
slide-11
SLIDE 11

nl.linkedin.com/in/rolandvanrijswijk @reseauxsansfil roland.vanrijswijk@surfnet.nl

Questions? Remarks? Read our blog: https:/ /dnssec.surfnet.nl/