Review Cloud DNS DNSSEC settings

Configure DNSSEC and the parent trust chain so public DNS responses can be validated.

Description

A public DNS zone without DNSSEC cannot provide signature-based verification of the origin and integrity of its DNS data. Where an attacker can forge DNS responses, users may be directed to an unintended address.

DNSSEC does not encrypt DNS data. Zone signing, a correct DS record in the parent zone and a DNSSEC-validating resolver are all needed.

Potential impact

  • Trusting a forged DNS response can direct users to an impersonated service.
  • A mismatch between DS records and signing state can interrupt legitimate name resolution.

Remediation

Enable DNSSEC for the public zone and register the correct DS record with the domain registrar or parent zone. Select a supported signing algorithm and test resolution through a validating resolver. Follow the Cloud DNS transition procedure for key changes or disabling DNSSEC, accounting for DS records and TTLs.

Examples

Replace the zone name, domain and project with actual values and provide the path to a service account JSON file. Parent delegation and DS record configuration are omitted.

Before

yaml
- name: DNS 관리 영역 생성
  google.cloud.gcp_dns_managed_zone:
    name: test-zone
    dns_name: test.somewild2.example.com.
    description: test zone
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

This task does not specify DNSSEC settings. Check the existing zone’s signing state and parent DS records separately.

After

yaml
- name: DNS 관리 영역 생성
  google.cloud.gcp_dns_managed_zone:
    name: test-zone
    dns_name: test.somewild2.example.com.
    description: test zone
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    dnssec_config:
      kind: dns#managedZoneDnsSecConfig
      state: "on"

This sets dnssec_config.state to the string "on". Complete the trust chain by configuring the parent DS record and verifying successful validation.

References