Hauptnavigation:

You are here: Homepage > DOMAINS > DNSSEC > Status > Resolver Configuration

Resolver Configuration

Since 5 January 2010, DENIC has made available the signed version of the .de zone in the DNSSEC testbed. Here are the addresses (IPv4 and IPv6) of the authoritative servers:


auth-fra.dnssec.denic.de. 81.91.161.228  2A02:568:0:1::53

auth-ams.dnssec.denic.de. 87.233.175.25

will answer DNS queries including DNSSEC data as authoritative and non-recursive name servers.

At the following links, you will find configuration examples for the DNSSEC-capable resolvers we know:

ISC BIND (ab 9.7)

https://www.isc.org/software/bind

Configuration Example

NLnet Labs Unbound (1.4.0 oder neuer)

http://unbound.net/

Configuration Example

Nominum Vantio

http://www.nominum.com/products/vantio_base_server.php

Configuration Example

The diagram below illustrates how the configuration of a resolver participating in the DNSSEC testbed will affect the name resolution under the top level domain DE.

 

Instead of the official name servers communicated to the resolver by the root zone (published on the root name servers), the resolver will consult the dedicated testbed systems. For all other targets, the delegation path will be followed.