| Today | 606 |
|---|---|
| Total | 936158 |
(Stephen Morris, manager of the team for advanced projects, Nominet.)
In 2008, researcher Dan Kaminsky put secure DNS on the Internet world’s agenda, and .SE thus achieved a significant international breakthrough in its efforts to ensure more secure DNS lookups. However, as early as autumn 2005, .se was the first country top-level domain in the world to sign its zone with DNSSEC, and was the first to offer a commercial DNSSEC service.
DNSSEC is a security add-on for the Internet’s domain name system (DNS) through which responses to DNS lookups are secured with cryptographic signatures. The purpose is to safeguard DNS from abuse known as cache poisoning. For several years, .SE has been a driving force to implement and spread DNSSEC. In addition, .se was the world’s first country top-level domain name to sign its zone and world’s first top domain to offer a commercial DNSSEC service in February 2007.
In 2008, interest in the technology gained real momentum. .SE attracted the attention of the entire Internet world by being at the leading edge in DNSSEC and for being eager to share its experiences. This was evident in the major interest shown in the international DNSSEC seminar held in October 2008. The seminar attracted 150 participants,
including from 20 top domains around the world. .SE also held international training sessions for DNSSEC. One of the speakers at the seminar was Steve Crocker, co-chair of the DNSSEC Deployment Working Group.
- .SE’s pioneer initiatives in the area of DNSSEC must be praised. A successful implementation of DNSSEC requires the involvement of all top domains, registrars and Internet operators, says Steve Crocker.
Stephen Morris, manager of the team for advanced projects at the United Kingdom’s country top-level domain .uk, which is operated by Nominet, participated in the workshop. He commented:
-As the representative for a top-level domain, the workshop was a chance for me to learn, from an organization with practical experience, about the issues one is forced to deal with when starting to use DNSSEC. What was most useful
to me was the chance to hear about registrars’ and customers’ experiences. .SE is a pioneer when it comes to implementing DNSSEC and has many experiences to share with the rest of the DNS community.
Robert Martin-Legène, CIO of DK Hostmaster A/S, participated to gain an understanding of the tasks and processes that are in store before the Danish registry begins using DNSSEC.
- .SE’s efforts in the area are absolutely ground-breaking, and its efforts to share the information it has acquired are incredibly valuable for participants. I greatly admire the .SE’s policy of sharing this information, he says.
A contributing reason for the increased interest was the possibility of exploiting a weakness in DNS which was made public by researcher Dan Kaminsky in July and is often called the Kaminsky bug. He demonstrated a new, very simple way of carrying out cache poisoning, which further emphasized the importance of implementing DNSSEC.
In the autumn, .SE launched the website Kaminskybuggen.se to provide information about the insecurities in DNS and to spread knowledge of DNSSEC. On the site, users can test the security of their computers and domains free of charge.
Another result of the increased attention paid to DNSSEC was that an increasing number of registrants, including many municipalities and Swedish government authorities, decided to sign their .se domains. .SE’s goal was for 1,000
domains to be signed in 2008, and this was achieved early, in November. To further support the development, as of 1 January 2009 .SE stopped charging a fee for the DNSSEC service.
In 2009, many top domains will follow in .SE’s footsteps and begin signing domains. .SE plans to hold additional international workshops and training during the year. A large project focusing on OpenDNSSEC has also been launched, involving the development of tools for automatic key management. Further information on the project is available at www.opendnssec.se.
Read more about DNSSEC at http://www.iis.se/en/domaner/dnssec/.