Description
Without DNSSEC, a public DNS zone cannot provide signature-based verification of DNS data origin and integrity. Trusting a forged response can direct users to an unintended address.
DNSSEC does not encrypt DNS data. Zone signing, correct DS records in the parent zone and a validating resolver are all required.
Potential impact
- Forged DNS responses can direct users to impersonated services.
- A mismatch between signing state and DS records can interrupt legitimate name resolution.
Remediation
- Set
dnssec_config.state = "on"for the public zone and register the correct DS records with its registrar or parent zone. - Follow official DS-record and TTL transition procedures for key changes or disabling DNSSEC, and test resolution with a validating resolver.
Examples
These examples compare public managed zones. Replace the name and domain with actual values, and configure parent delegation and DS records separately. Do not apply these settings unchanged to private zones.
Before
hcl
resource "google_dns_managed_zone" "example" {
name = "foobar"
dns_name = "foo.bar."
dnssec_config {
state = "off"
non_existence = "nsec3"
}
}
After
hcl
resource "google_dns_managed_zone" "example" {
name = "foobar"
dns_name = "foo.bar."
dnssec_config {
state = "on"
non_existence = "nsec3"
}
}
Explanation:
- Before: DNSSEC signing is disabled for the zone.
- After: DNSSEC signing is enabled. The parent trust chain and a validating resolver are also needed for protection.