Description
A public DNS zone without DNSSEC cannot provide signature-based verification of the origin and integrity of its DNS data. Where an attacker can forge DNS responses, users may be directed to an unintended address.
DNSSEC does not encrypt DNS data. Zone signing, a correct DS record in the parent zone and a DNSSEC-validating resolver are all needed.
Potential impact
- Trusting a forged DNS response can direct users to an impersonated service.
- A mismatch between DS records and signing state can interrupt legitimate name resolution.
Remediation
Enable DNSSEC for the public zone and register the correct DS record with the domain registrar or parent zone. Select a supported signing algorithm and test resolution through a validating resolver. Follow the Cloud DNS transition procedure for key changes or disabling DNSSEC, accounting for DS records and TTLs.
Examples
Replace the zone name, domain and project with actual values and provide the path to a service account JSON file. Parent delegation and DS record configuration are omitted.
Before
- name: DNS 관리 영역 생성
google.cloud.gcp_dns_managed_zone:
name: test-zone
dns_name: test.somewild2.example.com.
description: test zone
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
This task does not specify DNSSEC settings. Check the existing zone’s signing state and parent DS records separately.
After
- name: DNS 관리 영역 생성
google.cloud.gcp_dns_managed_zone:
name: test-zone
dns_name: test.somewild2.example.com.
description: test zone
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
dnssec_config:
kind: dns#managedZoneDnsSecConfig
state: "on"
This sets dnssec_config.state to the string "on". Complete the trust chain by configuring the parent DS record and verifying successful validation.