25 Nov 2025
Biztonsági szemle
DNSSEC signed zones - best practice guidance relating to NSEC3 signing and validation
Overview DNSSEC-signed zones offer protection against response spoofing to both DNSSEC-validating resolvers and authoritative DNS zone operators who choose to sign their published zones. NSEC and NSEC3 are the mechanisms within DNSSEC used to provide proof of non-existence of names. This is achieved by a DNSSEC-signed assurance that between two signed names, no other names exist. NSEC3 uses hash mechanisms to avoid disclosure of the bounding names themselves, otherwise it is possible to establis ...
Read more