Forum Discussion

JustCooLpOOLe's avatar
JustCooLpOOLe
Icon for Cirrocumulus rankCirrocumulus
Aug 08, 2017

DNSSEC - Parent Domain

I'm a little fuzzy on the chain of trust as it relates to how our current environment is setup.

 

Current Environment:

 

We have two GTMs configured in an Active/Active configuration with one sitting in our primary datacenter and the other sitting in our co-location site. We are only using them in a gloabal availability loadbalancing scenario. Our WideIPs are subdomains, such as hello.test.com and . The test.com or would be hosted in something like DNS Made Easy or GoDaddy.

 

Question:

 

I'd like to set up DNSSEC for our WideIPs and as I understand it, the DS record needs to be submitted to the parent domain to establish the chain of trust. Since the F5 is the authoritative resolover of the hello.test.com, would the parent domain be test.com? Or would .com be the parent?

 

The reason why I ask is that DNS Made Easy doesn't seem to support DNSSEC for it's Primary DNS but does for Secondary DNS and that would really suck.