Contents Menu Expand Light mode Dark mode Auto light/dark mode
Nitrokey Documentation
Light Logo Dark Logo
Nitrokey Documentation
  • Nitrokey 3
    • Frequently Asked Questions
    • Windows
      • Two-Factor Authentication For ERP Software Odoo
      • Firmware Update
      • Passwordless Authentication With Microsoft
      • Nitrokey Reset
      • Troubleshooting
    • macOS
      • Two-Factor Authentication For ERP Software Odoo
      • Firmware Update
      • Using The Nitrokey 3 With nitropy
      • Nitrokey Reset
      • Troubleshooting
    • Linux
      • Two-Factor Authentication For ERP Software Odoo
      • Desktop Login And Linux User Authentication
      • Firmware Update
      • Using The Nitrokey 3 With nitropy
      • Nitrokey Reset
      • Troubleshooting
  • Nitrokey FIDO2
    • Frequently Asked Questions
    • Windows
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Firmware Update
      • Passwordless Authentication With Microsoft
      • Nitrokey Reset
    • macOS
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Firmware Update
      • Nitrokey Reset
    • Linux
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Desktop Login And Linux User Authentication
      • Firmware Update
      • Nitrokey Reset
  • Nitrokey FIDO U2F
    • Windows
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
    • macOS
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
    • Linux
      • Two-Factor Authentication And Passwordless Login For Nextcloud Accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Desktop Login And Linux User Authentication
  • Nitrokey HSM 2
    • Frequently Asked Questions
    • Windows
      • TLS Setup With Apache2
      • Creating a Certificate Authority
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Importing Keys And Certificates
      • PKCS#11 URL Generation
      • Login to Windows Domain Computers With MS Active Directory
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • macOS
      • TLS Setup With Apache2
      • Creating a Certificate Authority
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Importing Keys And Certificates
      • PKCS#11 URL Generation
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • Linux
      • TLS Setup With Apache2
      • Automatic Screen Lock at Removal
      • Creating a Certificate Authority
      • DNSSEC
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Importing Keys And Certificates
      • IPsec
      • N-of-m Schemes
      • PKCS#11 URL Generation
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
      • Stunnel
  • Nitrokey Pro 2
    • Frequently Asked Questions
    • Windows
      • Two-factor Authentication for Google
      • Two-factor Authentication for Microsoft Account
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Change User and Admin PIN
      • Elliptic Curves (ECC) Support
      • Login With EIDAuthenticate on Stand Alone Windows Computers
      • Factory Reset
      • Firmware Update
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • OpenPGP Email Encryption
      • Windows Login and S/MIME Email Encryption with Active Directory
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • OpenVPN Configuration with Easy-RSA
      • Viscosity Client Configuration with OpenVPN
      • Two-factor Authentication with One-Time Passwords (OTP)
      • PuTTY
      • Login to Windows Domain Computers With MS Active Directory
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • macOS
      • Two-factor Authentication for Google
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Change User and Admin PIN
      • Elliptic Curves (ECC) Support
      • Factory Reset
      • Firmware Update
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • Two-factor Authentication with One-Time Passwords (OTP)
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • Linux
      • Two-factor Authentication for Google
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Automatic Screen Lock at Removal
      • Creating a Certificate Authority
      • Change User and Admin PIN
      • Full-Disk Encryption With cryptsetup/LUKS
      • Elliptic Curves (ECC) Support
      • Factory Reset
      • Firmware Update
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • IPsec
      • Login With PAM
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • OpenVPN Configuration with Easy-RSA
      • Two-factor Authentication with One-Time Passwords (OTP)
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
      • SSH For Server Administration
      • Stunnel
  • Nitrokey Start
    • Frequently Asked Questions
    • Windows
      • Factory Reset
      • Setup With Gnu Privacy Assistant (GPA)
      • Multiple Identities
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • PuTTY
      • Setting KDF-DO
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • macOS
      • Factory Reset
      • Setup With Gnu Privacy Assistant (GPA)
      • Multiple Identities
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • Setting KDF-DO
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • Linux
      • Factory Reset
      • Firmware Update
      • Setup With Gnu Privacy Assistant (GPA)
      • IPsec
      • Login With PAM
      • Multiple Identities
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • Setting KDF-DO
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
      • SSH For Server Administration
      • Stunnel
  • Nitrokey Storage 2
    • Frequently Asked Questions
    • Windows
      • Two-factor Authentication for Google
      • Two-factor Authentication for Microsoft Account
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Change User and Admin PIN
      • Elliptic Curves (ECC) Support
      • Login With EIDAuthenticate on Stand Alone Windows Computers
      • Encrypted Mobile Storage
      • Factory Reset
      • Firmware Update
      • Activate Update Mode Manually
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Hidden Volumes
      • OpenPGP Email Encryption
      • Windows Login and S/MIME Email Encryption with Active Directory
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • Two-factor Authentication with One-Time Passwords (OTP)
      • PuTTY
      • Login to Windows Domain Computers With MS Active Directory
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • macOS
      • Two-factor Authentication for Google
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Change User and Admin PIN
      • Elliptic Curves (ECC) Support
      • Login With EIDAuthenticate on Stand Alone Windows Computers
      • Encrypted Mobile Storage
      • Factory Reset
      • Firmware Update
      • Activate Update Mode Manually
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Hidden Volumes
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • Two-factor Authentication with One-Time Passwords (OTP)
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
    • Linux
      • Two-factor Authentication for Google
      • Two-factor Authentication for Nextcloud accounts
      • Two-Factor Authentication For ERP Software Odoo
      • Automatic Screen Lock at Removal
      • Change User and Admin PIN
      • Full-Disk Encryption With cryptsetup/LUKS
      • Elliptic Curves (ECC) Support
      • Encrypted Mobile Storage
      • Factory Reset
      • Firmware Update
      • Activate Update Mode Manually
      • Setup With Gnu Privacy Assistant (GPA)
      • Hard Disk Encryption
      • Hidden Volumes
      • IPsec
      • Login With PAM
      • OpenPGP Email Encryption
      • OpenPGP Key Generation With Backup
      • OpenPGP Key Generation Using GPA
      • OpenPGP Key Generation On-Device
      • OpenPGP Email Encryption with Outlook
      • OpenPGP Email Encryption With Thunderbird
      • OpenVPN Configuration with Easy-RSA
      • Two-factor Authentication with One-Time Passwords (OTP)
      • S/MIME Email Encryption
      • S/MIME Email Encryption with Outlook
      • S/MIME Email Encryption with Thunderbird
      • SSH For Server Administration
      • Stunnel
  • NitroPad
    • Frequently Asked Questions
    • Qubes
      • Change User and Admin PIN
      • Default Boot
      • Factory Reset
      • Firmware Update
      • Firmware Update v1.4+
      • Enable Network Settings, e.g. Wifi
      • Nitrokey App Installation
      • Operating System Reinstallation
      • Verify Sealed Hardware
      • System update
      • Troubleshooting
      • User Password Reset
    • Ubuntu
      • Change Disk Encryption Passphrase
      • Change User and Admin PIN
      • Default Boot
      • Factory Reset
      • Firmware Update
      • Firmware Update v1.4+
      • Nitrokey App Installation
      • Operating System Reinstallation
      • Verify Sealed Hardware
      • System update
      • Troubleshooting
  • NitroPC
    • Frequently Asked Questions
    • Debian
      • Operating System Reinstallation
      • Verify Sealed Hardware
    • Qubes
      • Nitrokey App Installation
      • Operating System Reinstallation
      • Verify Sealed Hardware
    • Ubuntu
      • Nitrokey App Installation
      • Operating System Reinstallation
      • Verify Sealed Hardware
  • NitroPhone
    • Apps
    • Background Images
    • Frequently Asked Questions
  • NextBox
    • Getting Started
    • Hardware Overview
    • Connect External Storage
    • Desktop And Mobile Synchronization
      • Android/iOS
      • Windows
      • Mac OS X
      • Linux
    • Backup and Restore
    • Managing Remote Access
      • Walkthrough
      • Method comparison
      • Backwards Proxy
      • Dynamic DNS
      • Static Domain
      • DNS Rebind
      • Port Forwarding
      • IPv6 Settings
    • Technical Documentation
      • LED Colors and Patterns
      • Factory Reset
      • Replace Internal Hard-Drive
    • NextBox FAQ
      • Generic
      • Hardware
      • Software
      • Nextcloud
      • Remote Access
  • NetHSM
    • Getting Started
    • Administration
    • Operation
    • Integration
    • Guides
      • PKCS#11 with pkcs11-tool
  • NitroWall
    • Verify Sealed Hardware
    • Backup & Restore
    • Using NitroWall as combined DHCP-Client/DHCP-Server
    • How to set up a LAN Bridge
    • How to Fix NTP
    • How to set up IDS/IPS with Suricata
    • Hardware Compatibility
  • Software
    • nitropy
      • All Platforms
        • Installing nitropy With pipx
      • Windows
        • Installing nitropy on Windows
      • Linux
        • Setting up The udev Rules For nitropy
Back to top

DNSSEC#

(Nitrokey HSM 2 - Linux)

Protect your domain name resolution using DNSSEC and a Nitrokey HSM as secure key store. It’s based on Smartcard-HSM which is why the following resources apply:

  • Luis D Espinoza Sanchez & Eberhard W Lisse held a session on using the SmartCard-HSM for DNSSEC at the 2015 ICAAN Meeting in Singapore.

  • Jan-Piet Mens wrote a nice article about integrating the SmartCard-HSM with PowerDNS.

  • Integration with OpenDNSSEC has been successfully tested.

Diese Seite ist auf Deutsch verfügbar.
Cette page est disponible en français
Esta página está disponible en español.
Deze pagina is beschikbaar in het Nederlands.
Questa pagina è disponibile in italiano.
このページは日本語でご覧いただけます。
Эта страница доступна на русском языке.
本页有中文版本。
Αυτή η σελίδα είναι διαθέσιμη στα ελληνικά.
Denne side er tilgængelig på dansk.
Тази страница е достъпна на български език.
See lehekülg on saadaval eesti keeles.
Tämä sivu on saatavilla suomeksi.
Šī lapa ir pieejama latviešu valodā.
Šis puslapis pateikiamas lietuvių kalba.
Ta strona jest dostępna w języku polskim.
Esta página está disponível em português.
Această pagină este disponibilă în limba română.
Den här sidan finns på svenska.
Táto stránka je k dispozícii v slovenčine.
Ta stran je na voljo v slovenščini.
Tato stránka je k dispozici v češtině.
Ez az oldal magyar nyelven érhető el.
Auf Deutsch ansehen
Ausblenden
Passer au français
Cacher
Cambia al español.
Ocultar
Schakel over op Nederlands.
Verberg
Passa all`italiano.
Nascondi
日本語に切り替えます。
隠す
Переключитесь на русский язык.
Скрыть
换成中文。
隐藏
Αλλαγή σε ελληνικά.
Απόκρυψη
Skift til dansk.
Skjul
Преминете на български език.
Скрий
Vahetage eesti keelele.
Peida
Vaihda suomeksi.
Piilota
Pārslēgties uz latviešu valodu.
Paslēpt
Perjunkite į lietuvių kalbą.
Paslėpti
Przełącz się na język polski.
Ukryj
Mudar para português.
Esconder
Treceți la limba română.
Ascundeți
Växla till svenska.
Dölj
Prepnite na slovenčinu.
Skryť
Preklopite na slovenščino.
Skrij
Přepněte na češtinu.
Skrýt
Váltson magyarra.
Rejtsd el
Next
Setup With Gnu Privacy Assistant (GPA)
Previous
Creating a Certificate Authority
Copyright © Nitrokey
Edit this Page | Request docs change