Secure DNS infrastructure with DNSSEC


The Domain Name System (DNS) is an old and “unsecure by default” protocol, yet at the core of Internet communications and carrying more and more security-related information.


Domain Name System Security Extensions (DNSSEC) adds origin authentication and integrity protection to the protocol by signing DNS data. However the ratio of signed domain names remains low, mostly because, as any security feature, DNSSEC brings some risks when implemented without a proper understanding.


This course targets IT students, professionals or enthusiasts currently managing domain names and willing to start signing their DNS zones, improve or gain confidence in their signing procedures with hands-on experience and best-practices.

Out of stock

Sorry, the course is fully booked. If you are interested in getting notifications for available spots in case other participants cancel, please leave your name and email address below

SKU: 9262 Categories: ,

Start date

October 27, 2023

End date

October 27, 2023

Language(s) of the training


Languages spoken by the coach(es)

English, French


Dr. Guillaume-Jean Herbiet


This course covers the following :

  • theoretical background on DNSSEC
  • protecting a DNS domain with DNSSEC in practice
  • actual implementation of DNSSEC-signing (manually then automatically)
  • DNSSEC-signing validation and monitoring


During this course, after a more theoretical introduction to understand the basic concepts of DNSSEC, learners will be invited to actually install, configure and operate DNSSEC-signing utilities, from most simple (manual) to complex (automated) solution.


By the end of the course and thanks to hands-on labs, students will have acquired the required knowledge and experience to confidently implement DNSSEC themselves onto their own DNS infrastructure.

Learning Outcomes

On completion of this course, learners will be able to:

  • fully understand DNSSEC principles, purpose and advantages
  • anticipate and mitigate DNSSEC risks
  • Confidently implement simple to more advanced DNSSEC-signing infrastructure using open-source software
  • analyze, troubleshoot and correct most common DNSSEC-related issues
  • acquire DNSSEC confidence best practices


This course has a total duration of 7 hours and takes place over the course of 1 day

  • 27-10-2023: 09:00 – 12:00
  • 27-10-2023: 13:00 – 17:00

Format and Location

This course takes place ON-SITE
Terres Rouges building
14, porte de France
L-4360 Esch/Alzette




Prior knowledge of the DNS (Domain Name System) basics is required. Participants without prior DNS background are invited to attend the “Domain Name System (DNS) administration” course.

Basic knowledge of GNU/Linux system administration (installing packages, editing configuration files, restarting services, monitoring logs, …) is expected for the hands-on labs.

Additional Info


This training does not have any assessment or exams; a certificate of participation will be issued to participants.

Esco Skills

perform ICT troubleshooting, ICT security standards

Esco Occupations

ICT system architect, ICT system developer, ICT security manager, ICT security technician