Hauptnavigation:

You are here: Homepage > DOMAINS > DNSSEC > DNSSEC Testbed > Resolver Configuration

Resolver Configuration

Since 5 January 2010, DENIC has made available the signed version of the .de zone in the DNSSEC testbed. Here are the addresses (IPv4 and IPv6) of the authoritative servers:


auth-fra.dnssec.denic.de. 81.91.161.228  2A02:568:0:1::53

auth-ams.dnssec.denic.de. 87.233.175.25

will answer DNS queries including DNSSEC data as authoritative and non-recursive name servers.

At the following links, you will find configuration examples for the DNSSEC-capable resolvers we know:

ISC BIND

https://www.isc.org/software/bind

Configuration Example (9.7 or newer)

Configuration Example (9.8.0 or newer)

NLnet Labs Unbound (1.4.0 or newer)

http://unbound.net/

Configuration Example

Nominum Vantio

http://www.nominum.com/products/vantio_base_server.php

Configuration Example

The diagram below illustrates how the configuration of a resolver participating in the DNSSEC testbed will affect the name resolution under the top level domain DE.

 

Instead of the official name servers communicated to the resolver by the root zone (published on the root name servers), the resolver will consult the dedicated testbed systems. For all other targets, the delegation path will be followed.