The DNSSEC-Tools package is a collection of tools, scripts, Perl modules, C libraries, and application patches that are useful for DNS zone administrators and end users to deploy DNS Security (DNSSEC).
| Tags | Networking Software Development Libraries Perl Modules Internet DNS |
|---|---|
| Licenses | BSD Revised |
| Operating Systems | Unix |
| Implementation | Perl C |
Recent releases


Changes: This release contains many new features, including support for nsec3, enhanced rollerd deployment modes, and new tools such as lsdnssec and getds. Additionally, it contains some bugfixes over the 1.4 series of code.


Changes: Many improvements were made to the documentation, trust anchor management, key rollover, and zone signing. The validating library has received a number of improvements. There is a new shim library that can be used to bring any application into DNSSEC compliance without recompiling it. Many other changes were made


Changes: This release included patches for validation in a number of applications: Firefox, Postfix, Sendmail, libspf2, wget, jabber-2, ssh, and ncftp. The included validator library contains an expanded set of validator policy definitions and provides initial support for Dynamic Lookaside Validation (DLV). A new Perl module that binds to the validation library was added along with the trustman utility, an IETF "Timers" implementation for automated monitoring of DNSSEC key rollovers. The key-rollover utility handles KSK rollover operations in addition to ZSK rollover operations within a zone. Many other changes were made.


Changes: Minor patches to the build system for DESTDIR support. Zonesigner publishes both zsks when signing with the published zsk. There is a minor bugfix in the Net::DNS::ZoneFile::Fast module.


Changes: Signing with multiple key sets is possible. trustman supports managing trust keys in both named.conf and dnsval.conf. libval can be created either threaded or not.
A graphical user interface for encryption of USB flash drives or external hard drives.