Route53 DNSSEC Configuration
Overview
DNSSEC stands for DNS Security Extensions and was developed by the IETF.
DNSSEC adds digital signatures to DNS records to ensure that response records are generated by legitimate administrators and that they have not been tampered with.
It is an effective countermeasure against DNS spoofing, as typified by DNS cache poisoning.
AWS Route 53 supports DNSSEC. The following is a step-by-step guide to setting up DNSSEC.
Before DNSSEC signing
Check the status of DNSSEC signing in the DNSSEC Analyzer.If there is no digital signature, a red symbols is displayed.
DNSSEC settings
-
Open the Route 53 Console.
-
Choose
Hosted Zones
in the left pane. -
Choose the target Domain name.
-
Choose
DNSSEC signing
tab.
-
Choose
Enable DNSSEC signing
on the right side of the screen.
-
Create
KSK
.- Enter
KSK name
. - Choose
Create customer managed CMK
. - Enter
CMK name
. - Choose
Create KSK and enable signing
.
- Enter
-
After a few moments,
DNSSEC signing was successfully enabled.
message appears at the top of the screen.
-
Choose
View information to create DS record
on the right side of the screen.
-
Establish a chain of trust
is displayed.Note the following items.- Flags
- Signing algorithm
- Public key
-
Choose
Registered domains
in the left pane. -
Choose the target Domain name.
-
Choose
Manage Keys
on the right side of the screen.
-
Enter
Key type
Algorithm
Public key
and chooseAdd
.
-
A message is displayed that the request was successfully submitted, and an email is also sent.
-
After a few moments,
Disabled
disappears fromDNSSEC status
.
After DNSSEC signing
Check the status of DNSSEC signing again in the DNSSEC Analyzer.After setting DNSSEC, all symbols are now green.