Skip to main content

Cascade

Cascade is a modern DNSSEC signer. Cascade is the replacement for OpenDNSSEC, which is reaching its end-of-life in October 2027.

Cascade takes DNS zone files, validates them, signs them, and outputs the signed zone files. The signed zone files can then be transferred to an online DNS server. This means that Cascade is just one component of a larger pipeline. This distinguishes Cascade from Knot DNS, which is a complete authoritative DNS server.

For key management, Cascade integrates with HSMs via the PKCS#11 and KMIP standards. Through this integration, Cascade can delegate key generation and signing to an HSM. This allows you to keep DNSSEC signing keys securely inside tamper-proof, high-performance hardware, such as Primus HSM. This also enables professional key management throughout the entire key lifecycle, including key generation, backup, and rollover.

Cascade integration diagram via PKCS#11

Benefits

  • Secure your DNS: Sign your DNS zone with DNSSEC for integrity and authentication of DNS records.
  • Secure your keys: Keep your DNSSEC signing keys securely inside a Primus HSM.
  • High availability: Deploy your Primus HSMs as an auto-syncing, geo-redundant cluster.
  • High performance:
    • A single Primus HSM can deliver thousands of EC key generations per second and tens of thousands of EC signatures per second. Performance scales linearly with the number of devices in a cluster.
    • Key generation is required during ZSK and KSK rollovers. Signing is required whenever the zone changes, such as when records are added or updated.

Getting Started

Follow the installation guide to learn how to set up Cascade together with a Primus HSM.

References

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?