DirectAccess breaks DNSSEC
Summary
In the lab, Lutz Donnerhacke shows how DirectAccess, DNS64 and policy-based name resolution can prevent valid DNSSEC checks. DNSSEC initially recognised the answer altered by DNS64 as insecure. The test distributed trust anchors and validation policies via group policy.
Ideas
- DNS64 changes answers and therefore predictably collides with DNSSEC signatures.
- Enforced validation makes manipulated answers visible instead of silently usable.
- Native IPv6 destinations avoid the need to synthesise IPv6 addresses.
- DirectAccess can still pass on signed native answers incompletely.
- Successful connectivity does not prove successful cryptographic name validation.
- Lab setups make interactions between transition technologies reproducible.
Insights
- Compatibility mediation and end-to-end authenticity often pursue opposite goals.
- Security functions often fail because of intermediate layers rather than the protocol itself.
- Negative tests reveal resolver errors more reliably than successful name resolution.
Quotes
Nein, der DirectAccess-Resolver macht DNSSEC kaputt.
(“No, the DirectAccess resolver breaks DNSSEC.”) – Lutz Donnerhacke
Habits
- Donnerhacke checks positive and negative DNS answers separately for signatures.
Facts
- A native AAAA answer did not reach the DirectAccess client correctly either.
References
- Lutz Donnerhacke: DirectAccess breaks DNSSEC (German)
- DNS64: synthesis of AAAA answers for NAT64.
- Microsoft DirectAccess: the remote access technology examined.
Critique
- The specific finding applies to the DirectAccess setup and software version of the time.
- The article does not fully separate resolver, client and policy errors from each other.
Remarks
- DirectAccess is historical, but DNS rewriting remains relevant in transition networks.
- The experiment shows the value of cryptographically verifiable error messages.
Recommendations
- Test DNSSEC with positive, negative and deliberately altered answers.
- Document every resolver and every rewrite in the query path.
- Prefer native IPv6 when DNS64 creates avoidable complexity.
Links to the original source and the Web Archive open in a new tab.