Description
DNSSEC for a public Cloud DNS zone helps validate the origin and integrity of DNS responses. It requires zone signing, correct DS records in the parent zone and a validating resolver. It does not encrypt DNS data.
Cloud DNS DNSSEC settings apply to public zones. The same configuration should not be applied indiscriminately to private zones.
Potential impact
- Trusting forged responses can direct users to unintended addresses.
- Inconsistent signing state and DS records can interrupt legitimate name resolution.
Remediation
- Set
dnssecConfig.state: "on"for the public zone and register the correct DS records with the registrar or parent zone. - Follow the documented DS-record and TTL procedures for key changes or disabling DNSSEC, and test resolution with a validating resolver.
Examples
These excerpts show public-zone settings in the retired Deployment Manager format. Supply the actual domain and omitted required settings through a supported tool, and configure delegation and DS records separately.
Before
yaml
resources:
- name: dns
type: dns.v1.managedZone
properties:
name: my-zone
After
yaml
resources:
- name: dns
type: dns.v1.managedZone
properties:
name: my-zone
dnssecConfig:
state: "on"
Explanation:
- Before: The zone's DNSSEC settings are omitted. Check its effective signing state and parent delegation.
- After: Zone signing is enabled. The parent chain of trust and client validation are also needed for protection.