From Microsoft

Oct 29, 2009 16:10 GMT  ·  By

Customers that need to boost the security of Domain Name System responses, in an infrastructure leveraging the latest versions of the Windows client and server operating systems, can turn to guidance from Microsoft that will streamline the deployment of DNS Security Extensions. Via the Microsoft Download Center, the software giant is offering for download a guide designed to simplify Domain Name System (DNS) Security Extensions (DNSSEC) deployment on Windows 7 and Windows Server 2008 R2. Companies in need of an additional layer of protection for Windows 7 and Windows Server 2008 R2 networks can make sure that all DNS responses are validated with the additional security extensions.

“DNSSEC is a suite of extensions that add security to the DNS protocol. The core DNSSEC extensions are specified by the Internet Engineering Task Force (IETF) in RFCs 4033, 4034, and 4035, with additional RFCs providing supporting information. This guide offers detailed procedures and conceptual information to help you deploy Domain Name System Security Extensions (DNSSEC) in your organization, using Windows Server® 2008 R2. DNSSEC is an important new feature that provides the ability for DNS servers and clients to trust DNS responses. This adds an additional layer of protection to your network by guaranteeing that the information received from a DNS server has not been modified or tampered with in any way,” Microsoft explained.

This deployment guide is currently up for grabs from Microsoft, free of charge. According to the software giant, the resource is focused exclusively on the successors of Windows Vista and Windows Server 2008. Windows 7 is available for purchase since October 22, with customers being able to buy Windows Server 2008 R2 a tad earlier, starting with September.

“The guide also provides information about using the Name Resolution Policy Table (NRPT). The NRPT is a new feature available in Windows Server 2008 R2 that allows you to configure DNS client settings and special behavior for specified names or namespaces. The NRPT is a key component used to configure client settings for DNSSEC-protected zones,” Microsoft added.