DNSSEC/TLSA Validator add-on for Web Browsers

Status
Not open for further replies.

Terry Ganzi

Level 26
Thread author
Verified
Top Poster
Well-known
Feb 7, 2014
1,540
https://www.dnssec-validator.cz/index.html
DNSSEC/TLSA Validator is a web browser add-on which allows you to check the existence and validity of DNS Security Extensions (DNSSEC) records and Transport Layer Security Association (TLSA) records related to domain names. Results of these checks are displayed by using icons and information texts in the page’s address-bar or browser tool-bar. Currently,Internet Explorer (IE), Mozilla Firefox (MF), Google Chrome/Chromium(GC), Opera (OP), Apple Safari (AS) are supported.

Description
DNSSEC/TLSA Validator allows you to check the existence and validity of DNSSEC signed DNS records. DNSSEC Validator shows whether the domain name is DNSSEC-signed. It also checks whether the browser is connecting to the correct IP address assigned for this domain name. If a valid DNSSEC chain related to the domain is found the plug-in will also check for the existence of TLSA records. TLSA records store hashes of remote server TLS/SSL certificates. The authenticity of a TLS/SSL certificate for a domain name is verified by DANE protocol (RFC 6698). DNSSEC and TLSA validation results are displayer by using several icons. Additional explanatory texts are shown in the page’s address bar (MF, GC and OP), in a separate tool bar (IE) or toolbar buttons (AS). Clicking on a given icon symbol reveals more detailed information.

Key features
  • DNSSEC Validator checks the existence and validity of DNSSEC-signed DNS records for domain names and it also checks whether the browser is connecting to the correct IP addresses assigned for these domain names.
  • TLSA Validator attempts to perform a validation of TLSA/PKI pair according to the DANE protocol.
  • TLSA Validator can interrupt HTTPS request when the server certificate doesn't correspond with obtained TLSA records (MF only in synchronous mode, AS).
  • DNSSEC/TLSA Validator is not dependent on an external validating resolver for its function.
  • Both validator cores (DNSSEC and TLSA) are based on libunbound.
  • Encompasses a shared DNS cache accessible from all browser windows and tabs to improve performance.
  • Coloured icons display the status of DNSSEC/TLSA validation.
  • English, German, Czech and Polish localization (AS only Engilsh).
  • Open source project released under the GNU GPL.
GUI and interface
  • Coloured key icons and information texts present DNSSEC validation states.
  • Coloured padlock icons and information texts display TLSA validation states.
  • Screen-shots are available here.
Supported platforms
  • all major UNIX-like systems (Linux, Mac OS X, BSD, ...)
  • MS Windows
  • 32-bit and 64-bit architectures are supported.
Known limitations
  • IE and GC/OP versions may not work correctly in cooperation with proxies (DNSSEC Validator only).
  • Plug-in cores can lose DNSSEC information when packets are fragmented (typically on WiFi).
  • Usage of DNSSEC unaware or non-compliant resolvers or exotic resolver configurations cause validation problems.
 

Terry Ganzi

Level 26
Thread author
Verified
Top Poster
Well-known
Feb 7, 2014
1,540
Capture.PNG

https://www.grc.com/fingerprints.htm
https://www.ssllabs.com
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top