Linux / DNSSEC / long-term operationsLong-term administration

DNS/DNSSEC Infrastructure Migration and Operations

Long-term authoritative DNS administration for a media environment and gradual modernisation of DNSSEC signing. The work included migrating more than 1,000 zones from OpenDNSSEC to BIND while preserving existing keys and uninterrupted DNS service.

Role
Initially an internal Linux administrator, later an external provider of server administration and DNS/DNSSEC modernisation.
Active DNS zones
Approximately 1,000
Public secondary servers
3
Signing
BIND 9.18 / DNSSEC
Keys
SoftHSM / PKCS#11
Migration platform
Ubuntu 22.04 LTS

Long-term DNS infrastructure

The authoritative DNS infrastructure consists of one hidden primary and three public secondary DNS servers. The hidden primary prepares and signs the zones with DNSSEC; the public secondary servers receive those zones and answer DNS queries.

The environment currently manages approximately 1,000 active DNS zones and historically handled more. Ongoing work covers Linux server administration, configuration changes, automation, monitoring and gradual modernisation. The specific signing migration from OpenDNSSEC to BIND covered more than 1,000 zones.

Migration objectives and DNSSEC continuity

Signing was originally handled by OpenDNSSEC with SoftHSM. The modernisation aimed to remove the dependency on a separate OpenDNSSEC layer and bring DNSSEC management directly into BIND.

The essential requirements were to preserve a valid chain of trust, retain the existing KSK/ZSK stored in SoftHSM and correctly map the keys to each zone. The migration procedure needed to support ongoing checks, rollback to the previous state and continued authoritative DNS service.

Moving signing into BIND

The target solution uses BIND 9.18, inline-signing and dnssec-policy on Ubuntu 22.04 LTS. Retaining the distribution version of BIND was a deliberate choice: the signing system changed on the existing platform, without simultaneously moving to another BIND version.

Existing KSK/ZSK were mapped for use through SoftHSM and the PKCS#11 interface. This preserved the keys while moving to native DNSSEC management in BIND, also preparing for their subsequent lifecycle and future rollover.

Cutover proceeded in controlled batches with verification steps. Before switching, a bulk check covered every migrated zone: each newly signed version had a serial equal to or newer than the original production state.

Automation and change verification

Bash scripts generated configurations, prepared key directory structures and mapped DNSSEC keys. Bulk changes therefore shared a consistent preparation process and verification output.

Validation scripts compared zone serials and produced reports for each batch cutover. Monitoring and a prepared rollback plan were part of the procedure, allowing changes to be assessed and reversed in a controlled way if necessary.

Ongoing infrastructure operations

The migration is one stage of long-term Linux infrastructure administration. Work continues on authoritative DNS servers, DNSSEC configuration, Zabbix monitoring and automation of operational tasks.

Over the years, the broader environment encompassed dozens to approximately 100 Linux servers running Ubuntu, Debian, RHEL and SLES. Supporting services included web and databases (Apache/nginx, PHP/MySQL), mail (Postfix/Exim), HAProxy/Keepalived, FreeRADIUS/LDAP/OTP and Samba, alongside virtualisation, storage/SAN and backups.

Result

DNSSEC signing was transferred from OpenDNSSEC to native BIND management, preserving the existing keys and chain of trust without interrupting authoritative DNS service.

Removing the separate OpenDNSSEC layer unified and simplified configuration. Further key lifecycle management and rollover are prepared directly in BIND; the infrastructure remains verifiable and amenable to automation as part of ongoing operations.

Related services

Connectivity and visibility

Networks and MikroTik

Networks for offices, industrial sites and ISP infrastructure: design, RouterOS configuration, secure connectivity and monitoring.

Service details

Discuss a project

Long-term Linux administration for a media environment. DNSSEC migration from OpenDNSSEC to BIND, preserving keys and continuity across more than 1,000 zones.

Discuss a project