Alteon Application Switch Operating System Application Guide
Global Server Load Balancing
752
Document
ID:
RDWR-ALOS-V2900_AG1302
Deleting Keys
1. Access the DNSSEC Key menu.
2. Delete the selected key.
NSEC and NSEC3 Records
DNSSEC authenticates denial of existence by using NSEC and NSEC3 records. An NSEC is used to
prove that a name does not exist. When a record does not exist, the DNS server (Alteon) answers
with an NSEC DNS signature using the closest lexicographic name of the request.
Example
The DNS server holds the example.com domain and has records for a.example.com and
c.example.com. When someone asks for b.example.com, the DNS server responds with an NSEC for
a.example.com and c.example.com.
Automatic NSEC and NSEC3 Record Creation
The following procedure occurs:
1. Alteon receives a DNS query.
2. One of the following occurs:
—
If the domain name and a matching record exists, the regular GSLB DNSSEC procedure is
followed.
—
If the domain name exists but no matching record exists, Alteon returns the NSEC or NSEC3
record of the requested name.
—
If neither the domain name nor a matching record exists, Alteon drops the DNS request.
Note:
When issuing an NSEC RRSIG answer, the DNS server uses only one record (NSEC or
NSEC3).
>> /cfg/slb/gslb/dnssec/key
Enter key id:
Enter key id: 123
------------------------------------------------------------
[Key 123 Menu]
generate - Create new key
expire - Set key expiration period
rollover - Set key rollover period
sigvalid - Set key signature validity period
sigpub - Set key signature publication period
del - Delete key
ena - Enable entry
dis - Disable entry
cur - Display current key configuration
>> Key 123# del
Confirm deletion of this key? (y/n) [n]: