Checklist: Deploy DNSSEC

 

Applies To: Windows Server 2012 R2, Windows Server 2012

This parent checklist includes cross-reference links to topics that provide important conceptual information about DNSSEC. It also contains links to subordinate checklists that help you complete the required tasks.

Before you complete the tasks in this checklist, make sure that you have performed the prerequisite tasks in the parent checklist, such as reviewing conceptual information about DNSSEC and deciding on a deployment method and DNSSEC parameter values to use.

The DNS server that you use to perform procedures in this checklist is intended to be the Key Master. For more information, see The Key Master. You can also use a different DNS server than the Key Master but you might have to adjust some steps in these procedures accordingly.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a conceptual topic or to a subordinate checklist, return to this topic after you review the conceptual topic or after you complete the tasks in the subordinate checklist so that you can proceed with the remaining tasks in this checklist.

  Checklist: Deploy DNSSEC

Task

Reference

Review DNSSEC concepts, terminology, components, requirements, and specifications.

Overview of DNSSEC

DNSSEC in Windows

Appendix A: DNSSEC Terminology

Decide on a deployment method; identify pilot servers and zones.

DNSSEC Deployment Planning

Sign a zone.

Checklist: Sign a Zone

Deploy trust anchors.

Checklist: Distribute Trust Anchors

Configure and deploy DNS client policies.

Checklist: Deploy DNSSEC Policies to DNS Clients

Review zone signing parameters and manage the signed zone.

Checklist: Review and Manage a Signed Zone

Deploy IPsec policy to protect zone transfers

Checklist: Secure Zone Transfers

Review DNS client requirements for DNSSEC validation.

Procedure: Review Name Resolution Policy Settings

See also

Overview of DNSSEC

DNSSEC in Windows

DNSSEC Deployment Planning

Appendix A: DNSSEC Terminology

Appendix B: Windows PowerShell for DNS Server