Migrating a high-value domain while maintaining inner peace
Roland van Rijswijk - Deij roland.vanrijswijk@surfnet.nl
Migrating a high-value domain while maintaining inner peace Roland - - PowerPoint PPT Presentation
Migrating a high-value domain while maintaining inner peace Roland van Rijswijk - Deij roland.vanrijswijk@surfnet.nl Why migrate? We had a fairly complex set-up with shared keys We were using an old version of OpenDNSSEC that did
Migrating a high-value domain while maintaining inner peace
Roland van Rijswijk - Deij roland.vanrijswijk@surfnet.nl
Why migrate?
complex set-up with shared keys
OpenDNSSEC that did not really support this
2Guiding principles
3Guiding principles
4Guiding principles
– Less room to make (stupid) mistakes in a high stress environment
possible
– Preferable within a day
5Preparing
6Preparing
7Situation on source signer Situation on destination signer
KSKsrc,act ZSKsrc,act ZSKdst,act RR KSKdst,act DSdst,act KSKdst,act ZSKdst,act ZSKsrc,act RR KSKsrc,act
Testing with a live domain
8Actual migration
4th of July
what we had hoped for
9Lessons learned
draft-koch-dnsop-dnssec-operator-change http:/ /bit.ly/draft-koch
about our process and blogged about it on our DNSSEC blog https:/ /dnssec.surfnet.nl/
10nl.linkedin.com/in/rolandvanrijswijk @reseauxsansfil roland.vanrijswijk@surfnet.nl
Questions? Remarks? Read our blog: https:/ /dnssec.surfnet.nl/