{"id":18787233,"url":"https://github.com/michaelforney/dnssec-rr","last_synced_at":"2025-04-13T13:11:53.502Z","repository":{"id":66675320,"uuid":"252889457","full_name":"michaelforney/dnssec-rr","owner":"michaelforney","description":"Tools for working with DNSSEC (mirror)","archived":false,"fork":false,"pushed_at":"2024-03-10T21:33:45.000Z","size":149,"stargazers_count":8,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-03-27T04:12:26.446Z","etag":null,"topics":["bearssl","dns","dnssec"],"latest_commit_sha":null,"homepage":"https://sr.ht/~mcf/dnssec-rr","language":"C","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"isc","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/michaelforney.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-04-04T02:23:18.000Z","updated_at":"2025-01-13T11:46:28.000Z","dependencies_parsed_at":"2024-03-10T22:37:30.850Z","dependency_job_id":"15141837-3dc7-47b8-96ab-f2db3c000b88","html_url":"https://github.com/michaelforney/dnssec-rr","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelforney%2Fdnssec-rr","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelforney%2Fdnssec-rr/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelforney%2Fdnssec-rr/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelforney%2Fdnssec-rr/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/michaelforney","download_url":"https://codeload.github.com/michaelforney/dnssec-rr/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248717238,"owners_count":21150389,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bearssl","dns","dnssec"],"created_at":"2024-11-07T20:53:55.686Z","updated_at":"2025-04-13T13:11:53.479Z","avatar_url":"https://github.com/michaelforney.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# dnssec-rr\n\n[![builds.sr.ht status](https://builds.sr.ht/~mcf/dnssec-rr.svg)](https://builds.sr.ht/~mcf/dnssec-rr)\n\nThis repository contains a few tools for working with DNSSEC. The\ntools are implemented using [BearSSL].\n\nFor a detailed description of DNSSEC and how these tools fit together,\nsee this [blog post].\n\n## Generating keys\n\nYou can generate your ZSK (zone-signing key) and KSK (key-signing\nkey) using the `brssl` tool:\n\n```\n$ brssl skey -gen ec:secp256r1 -rawpem zsk.pem\n$ brssl skey -gen ec:secp256r1 -rawpem ksk.pem\n```\n\nYou can also use `-gen rsa[:size]` to generate RSA keys.\n\n## Complete example\n\nLet's say we have a complete zone file `example.com.zone`:\n\n```\n$ORIGIN example.com.\n$TTL\t86400\n@\tIN\tSOA\tns1.example.com. root.example.com. 2020040900 7200 900 1209600 1200\n\t\tNS\tns1.example.com.\n\t\tA\t1.2.3.4\nns1\t\tA\t1.2.3.4\n```\n\nYou can sign it with two keys, `ksk-example.com.pem` and\n`zsk-example.com.pem` with the following commands:\n\n```\n$ cp example.com.zone example.com.zone.signed\n$ { dnskey -k example.com. ksk-example.com.pem\n    dnskey example.com. zsk-example.com.pem\n    nsec example.com.zone.signed\n    rrsig -k ksk-example.com.pem example.com.zone.signed\n    rrsig -z zsk-example.com.pem example.com.zone.signed\n  } \u003e\u003e example.com.zone.signed\n```\n\nAlternatively, you can sign it with a single key, `csk-example.com.pem`:\n\n```\n$ cp example.com.zone example.com.zone.signed\n$ { dnskey -k example.com. csk-example.com.pem\n    nsec example.com.zone.signed\n    rrsig csk-example.com.pem example.com.zone.signed\n  } \u003e\u003e example.com.zone.signed\n```\n\nThis may be wrapped up into a shell script at some point.\n\n## ds\n\nThis tool generates a `DS` record for the parent zone (usually used\nfor registrar configuration).\n\n```\n$ ds example.com. ksk.pem\nexample.com.    IN      DS      5207 13 2 10a30f9f11818844a7df830b85e125c9868bd2917fb21907f7f3569bdf8934d7\n```\n\n## dnskey\n\nThis tool generates a `DNSKEY` record from a private key.\n\n```\n$ dnskey -k example.com. ksk.pem\nexample.com.    IN      DNSKEY  257 3 13 0KcqMTP78j9XbR4FoglT9t03IIMtsRO321K01QlNAXuYmI/YlLU9elwEwYfAtPJ1GMCpXiJWrCd2Di1nATypCA==\n$ dnskey example.com. zsk.pem\nexample.com.    IN      DNSKEY  256 3 13 FH+S2VOGBc7NAZU/1yL271VjUDzYEh3Ehv4Ii2GoFVTFwcHA/o3kdZS5N+l2CVK4N+6bqsiHwcqtmydSMVcziQ==\n```\n\n## nsec\n\nThis tool generates `NSEC` records for a zone, linking the domain\nnames together.\n\n```\n$ { cat \u003c\u003c'EOF'; dnskey -k example.com. ksk.pem; dnskey example.com. zsk.pem; } | nsec\n$TTL 86400\nexample.com.\t\tIN\tSOA\tns1.example.com. root.example.com. 2020040900 7200 900 1209600 1200\nabc.example.com.\tIN\tA\t1.2.3.4\ndef.example.com.\tIN\tA\t5.6.7.8\nEOF\nexample.com.    1200    IN      NSEC    abc.example.com. SOA RRSIG NSEC DNSKEY\nabc.example.com.        1200    IN      NSEC    def.example.com. A RRSIG NSEC\ndef.example.com.        1200    IN      NSEC    example.com. A RRSIG NSEC\n```\n\n## rrsig\n\nThis tool signs the records in a zone, generating `RRSIG` records.\n\n```\n$ { cat \u003c\u003c'EOF'; dnskey -k example.com. ksk.pem; dnskey example.com. zsk.pem; } \u003e example.com.zone\n$TTL 86400\nexample.com.\t\tIN\tSOA\tns1.example.com. root.example.com. 2020040900 7200 900 1209600 1200\nabc.example.com.\tIN\tA\t1.2.3.4\ndef.example.com.\tIN\tA\t5.6.7.8\nEOF\n$ rrsig -k ksk.pem example.com.zone\nexample.com.    86400   IN      RRSIG   DNSKEY 13 2 86400 20200510061125 20200410061125 5207 example.com. aM2PVY7JIgyVZIzE8J2c427ju3VRCPjdIeDwkCqa9ITI4n9WrCL50dLL5NC7E1vSERA6FUNybV0skjXoX6mLbA==\n$ rrsig -z zsk.pem example.com.zone\nexample.com.    86400   IN      RRSIG   SOA 13 2 86400 20200510061143 20200410061143 28335 example.com. QR8IwdtcyApF13FP7dOpoQDOpcXasa2zBdlvLWl8X6j5d3COv13B/mV2/T5uPMIEFJEBvapIHsk0XUuHPzbe3g==\nabc.example.com.        86400   IN      RRSIG   A 13 3 86400 20200510061143 20200410061143 28335 example.com. MaSqG7b1NBDDfNWWXHQ6mVdamT50jzIF8YZpbWZ38w4PfIvSBLrx1zW7NgxiUcTv/2DhGrhFfuZENF8Y07eNPw==\ndef.example.com.        86400   IN      RRSIG   A 13 3 86400 20200510061143 20200410061143 28335 example.com. Izl/hwxnmwtmYTDVXMJIhsCLQGM2Icdz54Ap5akxHrhooAsxG8rHz4HikAureBSTVm+gO3hZ2+Cx2w7sIBr4Og==\n```\n\n## tlsa\n\nThis tool generates a DANE `TLSA` record for a certificate.\n\n```\n$ tlsa example.com. cert.pem\nexample.com.    IN      TLSA    3 1 1 6584317c0720726df738582b2f5d440b8162baecd001e07fdf3d148d3f521fad\n```\n\n[BearSSL]: https://bearssl.org\n[blog post]: https://mforney.org/blog/2020-05-21-securing-your-zone-with-dnssec-and-dane.html\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmichaelforney%2Fdnssec-rr","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmichaelforney%2Fdnssec-rr","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmichaelforney%2Fdnssec-rr/lists"}