Projects / DNSSEC Walker

DNSSEC Walker

DNSSEC Walker is a tool to recover DNS zonefiles using the DNS protocol. The server does not have to support zonetransfer, but the zone must contain DNSSEC "NXT" or "NSEC" records. Optionally, it can also verify DNSSEC signatures on the RRsets within the zone.

Tags Internet DNS Security Utilities Systems Administration
Licenses Freeware GPL
Operating Systems POSIX
Implementation Perl

Tweet this project Short link

Rss Recent releases

  • Rrelease-mid
  •  20 Sep 2005 11:08
  • Rrelease-after

Changes: Able to verify more then one signature per owner name, and also print which key tag was used for verification. The parameter -x has been added to enable EDNS.0 DNSSEC when retrieving SIG/RRSIG types, because some servers don't return those records otherwise.

  • Rrelease-mid
  •  19 Sep 2005 10:04
  • Rrelease-after

Changes: Support for an optional "startname" parameter was added; it is used to specify which owner name to start walking on, which is useful when interrupted half way through a big zone.

  • Rrelease-mid
  •  14 Sep 2005 04:28
  • Rrelease-after

Changes: Verifying signatures (the -y parameter) in zones that have multiple online keys now works. This make it possible to verify signatures in ".se", the world's first ccTLD that uses DNSSEC in the real zone.

  • Rrelease-mid
  •  04 Jun 2004 05:51
  • Rrelease-after

Changes: This release adds bugfixes and improved output.

  • Rrelease-mid
  •  02 Jun 2004 08:02
  • Rrelease-after

Changes: Support was added for RRSIG/DNSKEY (as well as old-style SIG/KEY). The -n parameter now enables non-recursiveness for everything. Output was improved.

E190b4c49e0534225bbabc9eac0556f1_thumb

Project Spotlight

Tiny Calculator

A simple command line calculator that resolves mixed expressions.

D8ca4842fd212b1dc01e924958694fbd_thumb

Project Spotlight

Tric-Tac-Toe

A new twist (or perhaps "tilt") on the classic Tic-Tac-Toe game.