Tutorials • Plesk
Activating DNSSEC and generating DS records in the Plesk administration panel
In this article, we will present the necessary steps to activate DNSSEC and to generate the required DS DNS records for configuring the domain at the registrar.
Views 437Updated 20 zilePublished on 07/02/2020by Alexandru Jurca
Introduction
- DNSSEC (Domain Name System Security Extensions) is an extension of the Domain Name System (DNS) on the Internet, aimed at securing this protocol through the use of encryption algorithms.
- The Plesk control panel gives us the ability to generate the keys needed for DNSSEC configuration.
Requirements
- Access to the Plesk administration panel, username, and password.
- Access to the domain's administration panel at the registrar, username, and password.
Steps
- First, we will log in to the administration panel
- Activating DNSSEC can be done by accessing the DNSSEC Plugin from the configuration panel related to the respective domain/subscription.
- Then the option Sign the DNS Zone will be selected
- Explanatory notes:
-The recommended generation algorithm and currently the most widely supported is RSASHA256.
-The key sizes will be: 2048 bits for KSK, and 1024 bits for ZSK.
-The displayed recommendations can be used for the validity period.
-Key expiration will block access to the domain until the new keys are confirmed at the registrar.
- After the keys are generated, they will be automatically used to sign the DNS Zone.
Public Keys can be viewed by clicking on View DNSKEY Records
DS Records are displayed at the bottom. - Depending on the registrar's preferences, either DS records or public keys will need to be added in the domain control panel.