Jump to content

Recommended Posts

Posted (edited)

Hi

 

I recently moved our DNS management to Cloudflare for our Domain.

 

The registrar for our domain is Capita who manage it on Nominet.

 

I'm trying to enable DNSSEC for our domain name servers - Cloudflare provided me with this info:

 

Step 1 - Activate DNSSEC in Cloudflare

 

- Log in to the Cloudflare dashboard and select your account and domain.

- Go to DNS > Settings.

- For DNSSEC, click Enable DNSSEC.

 

In the dialog, you have access to several necessary values to help you create a DS record at your registrar. Once you close the dialog, you can access this information by clicking DS record on the DNSSEC card.

 

​​

Step 2 - Add DS record to your registrar

 

Add the DS record to your registrar. If Algorithm 13 - Cloudflare’s preferred cipher choice - is not listed by your registrar, it may also be called ECDSA Curve P-256 with SHA-256.

 

 

I've done Step 1 and have provided Capita with the DS record that was generated, but Capita keep insisting that I need to add it at Cloudflare.

 

Cloudflare pretty clearly states that the DS record can only be added by the Registrar.

 

Am I going mad - or are they? I'm essentially stuck in a loop with their support and I don't know how else to explain it to them.

 

Any advice appreciated.

 

Thanks

Edited by giblet
Posted

Just tested it on one of our spare domains and checking against this guide: https://developers.cloudflare.com/dns/dnssec/

 

you appear to be correct and Capita need to pull their finger out.

 

Alternatively swap your registrar for someone competent. I like Krystal (there's a few threads on them around here) but others are available.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...