Professional Documents
Culture Documents
FRXUV#XUHFFQUVIU
DNS
❍ &UpDWLRQ%HUQDUG7X\
❍ 0RGLILFDWLRQV
%HUQDUG7X\
3/HFD
Page 1
Plan
❍ *pQpUDOLWpV
❍ 'RPDLQ1DPH6\VWHPODWKpRULH
❍ HWODSUDWLTXH
❍ /HVpTXLSHPHQWVFRPPXQLTXHQWJUkFHjOHXUDGUHVVH,3
❍ 6HXOHVOHVDSSOLFDWLRQVXWLOLVHQWOHVQRPVGHVpTXLSHPHQWV
² SRXUFHUWDLQHVRQSHXWXWLOLVHUOHVDGUHVVHVIWSWHOQHW
² SRXUG
DXWUHVOHVQRPVVRQWLQGLVSHQVDEOHVZZZ
❍ $XQHDGUHVVH,3SHXWFRUUHVSRQGUHXQRXSOXVLHXUVQRPVDOLDV
❍ 8QQRPGRLWrWUHXQLTXHDXPRQGH
Page 2
Les Correspondances Nom - Adresse IP
❍ )LFKLHUHWFKRVWV
ILFKLHU$6&,,
PLVHjMRXUPDQXHOOH
JHVWLRQPDQXHOOHGHVUHVVRXUFHVQRQORFDOHV
❍ 1,6<HOORZ3DJHV
ILFKLHUQGEP
FUppjSDUWLUGXILFKLHUHWFKRVWVGXPDvWUH
JHVWLRQPDQXHOOHGHVUHVVRXUFHVQRQORFDOHV
❍ 'RPDLQ1DPH6\VWHP'16
HQVHPEOHGHILFKLHUV$6&,,
RUJDQLVDWLRQKLpUDUFKLTXHHWPRQGLDOHGHVUHVVRXUFHV
PpPRULVDWLRQGHVLQIRUPDWLRQVUHFXHLOOLHVFDFKH
❍ 5)&HW
❍ /HV2EMHFWLIV
(VSDFHGH1RPVPRQGLDOFRKpUHQWLQGpSHQGDQWGHV
SURWRFROHVHWGXV\VWqPHGHFRPPXQLFDWLRQVRXVMDFHQWV
*HVWLRQGpFHQWUDOLVpHGHVLQIRUPDWLRQVGHODEDVHGHGRQQpHV
JOREDOH
8VDJHJpQpUDOLQGpSHQGDQWGHVW\SHVG
DSSOLFDWLRQV
HWGXW\SHGHPDFKLQHVGXPLFURDXPDLQIUDPH
Page 3
DNS : généralités (2)
❍ $YDQWDJHV
*HVWLRQGpFHQWUDOLVpH
² DGPLQLVWUDWLRQGHVVHXOHVUHVVRXUFHVORFDOHV
² PDLVDFFqVjWRXWHVOHVUHVVRXUFHVGHO
,QWHUQHW
6\VWqPHGHFDFKH
PpPRULVHUOHVUpVROXWLRQVSUpFpGHQWHV
JDLQGHWHPSV
SDVGHVXUFKDUJHLQXWLOHGXUpVHDX
'16V\VWqPHODUJHPHQWUpSDQGXELHQU{GpHWVWDQGDUG
❍ ,QFRQYpQLHQWV
3UREOqPHGHFHUWLILFDWLRQGHO
LQIRUPDWLRQ
² OHVGRQQpHVFKDQJHQWOHQWHPHQW
OHVFRXSOHVQRPV#,3
² SULRULWpjO
DFFqVjO
LQIRUPDWLRQVXUOHVPLVHVjMRXUHWOD
JDUDQWLHGHFRKpUHQFH
Page 4
DNS : la théorie (1)
❍ &RQVWLWXDQWVGX'16
/
(VSDFHGHV1RPVGHGRPDLQHVHWOHVLQIRUPDWLRQV
DIIpUHQWHV5HVRXUFH5HFRUGVRX55
/HV6HUYHXUVGH1RPV
/HV5HVROYHUV
OHVQRPVGHGRPDLQHGHFHWWHVXLWHVRQWVpSDUpVSDUXQ
² ([HGX -XVVLHXIU IU FQUVIU
Page 5
DNS : la théorie (3)
❍ /HQRPPDJHSHXWDXVVLrWUHUHODWLI
FHODVXSSRVHTXHO
25,*,1(VRLWFRQQXH
([VKLYDMXVVLHX HVWXQQRPUHODWLIDXGXGRPDLQH)5
² RQGLWTXH)5HVWO
RULJLQHFRXUDQWH
❍ XQQRPGHGRPDLQHUHODWLIRXDEVROXHVWOLPLWpjFDUDFWqUHV
❍ XQGRPDLQHHVWLGHQWLILpSDUXQ1RPGHGRPDLQH
F
HVWODVRXVDUERUHVFHQFHTXLDSRXURULJLQHFHQRPGHGRPDLQH
❍ 8QGRPDLQHLQFOXVGDQVXQDXWUHHVWXQVRXVGRPDLQH
([SUHSDLPLWHGXHVWVRXVGRPDLQHGH
² DLPLWHGX
² PLWHGX
² HGX
²
❍ 4XHO1RPGH'RPDLQHFKRLVLU"
5)&
FDUDFWqUHVPD[ FRQVHLOOpFDUDFWqUHVPD[
$=D]
GRLWFRPPHQFHUSDUXQHOHWWUH
❍ OHJpUDQWGXGRPDLQHHQJOREDQWOHY{WUHGRLWDVVXUHUO
XQLFLWpGHV
QRPVGHGRPDLQH
O
85(&SRXUXQVRXVGRPDLQHGH&156)5
OH$)1,&SRXUXQVRXVGRPDLQHGH)5
Page 6
L’Espace des Noms
(Root)
""
.com .edu .mil .gov .arpa .org .net .fr .uk .de .nl .au .jp •••
isis compta
❍ /
DGPLQLVWUDWLRQGHVQRPVGHGRPDLQHHVWKLpUDUFKLVpH
/H1,&1HWZRUN,QIRUPDWLRQ&HQWHUDX[(WDWV8QLVHVW
UHVSRQVDEOHGHODFFRUGLQDWLRQPRQGLDOH$8725,7(
❍ HWGpFHQWUDOLVpH
/H1,&DGRQQpGpOpJDWLRQj5,3(1&&SRXUODJHVWLRQGHV
1RPVGH'RPDLQHHQ(XURSH
² 5,3(1&&DDXWRULWpSRXUO
(XURSH
5,3(1&&DGRQQpGpOpJDWLRQDO¬·$)1,&SRXUODJHVWLRQGHV
QRPVGHGRPDLQHHQ)UDQFH
² OH$)1,&$VVRFLDWLRQ)UDQoDLVHSRXUOHQRPPDJH
LQWHUQHWHQFRRSpUDWLRQKWWSZZZQLFIUDDXWRULWpHQ
)UDQFH
Page 7
DNS : administration (2)
❍ /¬·$)1,&HQUHJLVWUHWRXVOHVQRPVGHVRXVGRPDLQHGXGRPDLQH
)5
DYHFXQJpUDQWSRXUFKDTXHGRPDLQHGpOpJDWLRQG
DXWRULWp
² HGIIUHVWJpUpSDUOD'LUHFWLRQGHO
(')
² XUHFIUHWFQUVIUVRQWJpUpVSDUO
85(&
²
❍ /HJpUDQWGXGRPDLQH;IUHVWUHVSRQVDEOH
GHODGpOpJDWLRQGHVQRPVGHGRPDLQHVGHODIRUPH<;IU
GHODGpVLJQDWLRQG
XQDGPLQLVWUDWHXUGXGRPDLQH<;IU
❍ ,OIDXWFRQWDFWHUO¬·$)1,&KWWSZZZQLFIU
3RXUIDLUHHQUHJLVWUHUXQQRPGHGRPDLQHVRXVIU
3RXUIDLUHRXYULUOD]RQHFRUUHVSRQGDQWH
❍ &RQWDFWHUOH*,35HQDWHUGQVVYS#UHQDWHUIURXZZZUHQDWHUIU
SRXUOHVHQWLWpVUHOHYDQWGHODFRPPXQDXWp(QVHLJQHPHQW
5HFKHUFKH
❍ ,OIDXWFRQWDFWHUO
85(&GQVPDVWHU#XUHFFQUVIURX
ZZZXUHFFQUVIU
3RXUIDLUHHQUHJLVWUHUXQQRPGHGRPDLQHVRXVFQUVIU
3RXUIDLUHRXYULUOD]RQH;FQUVIU
Page 8
DNS : la théorie (6)
❍ ,OQ
\DSDVGHFRUUHVSRQGDQFHV\VWpPDWLTXHHQWUHXQQRPGH
GRPDLQHHWXQHDGUHVVHGHUpVHDX,3
/HQRPHVWXQHQRWLRQDGPLQLVWUDWLYH
/HGRPDLQHFQUVGLUIUUHJURXSHVLWHVj3DULVHWVLWHj
7RXORXVH
❍ ,O\DXQHKLpUDUFKLHGHVQRPVGHGRPDLQHV
❍ FRQWUDLUHPHQWDX[DGUHVVHVGHUpVHDX[
/
HVSDFHGHV1RPVHWOHVUHTXrWHVLQYHUVHV
❍ UpDOLVHUODFRUUHVSRQGDQFH#,3!QRP
QRPGHPDFKLQHRXGHUpVHDX
❍ OHSVHXGRGRPDLQHLQDGGUDUSDHWGHVSRLQWHXUV
UHSUpVHQWDWLRQGHO
HVSDFHGHVDGUHVVHVVRXVIRUPHGH
GRPDLQHV
H[HW
Page 9
Le pseudo domaine in-addr.arpa.
$USD )U
PTR
/HV5HVRXUFH5HFRUGV55V
❍ 8QQRPGH'RPDLQHLGHQWLILHXQQRHXGGHO
DUEUHGHV1RPV
❍ QRHXG !XQHQVHPEOHG
LQIRUPDWLRQV5HVVRXUFHV
❍ &HWHQVHPEOHHVWGpFULWSDUGHV55V
❍ ,OSHXW\DYRLUSOXVLHXUV55V
OHXURUGUHHVWLQGLIIpUHQW
Page 10
Sructure d’un RR
❍ ([HPSOHVGH5HVRXUFH5HFRUGV
Page 11
Alias et noms canoniques
$OLDVHWQRPVFDQRQLTXHV
❍ 8QQRPGH'RPDLQHQHGRLWMDPDLVSRLQWHUVXUXQDOLDVPDLVVXUXQ
1RPFDQRQLTXH
❍ ([
LQDGGUDUSD,1375 /DIRULDLESIU
Page 12
DNS : la théorie (13)
❍ 3DUDPqWUHVGX62$5)&¬
■ Serial No de version
■ Refresh Intervalle entre 2 polling des serveurs 2daires
■ Retry Intervalle si polling infructueux
■ Expire Durée de l'autorité sur la zone
■ Minimum Durée de vie (TTL) des RR dans un cache
❍ ([HPSOH
9HUVLRQ
5HIUHVKK
5HWU\K
([SLUHM
0LQLPXPM
❍ (VSDFHGHV1RPVGH'RPDLQHHVWGpFRXSpHQ=21(6
DGPLQLVWUDWLYHV
❍ 8QH=RQHHVWVRXVO
DXWRULWpG
XQ1DPH6HUYHU16
❍ 8Q1DPH6HUYHUSHXWDYRLUDXWRULWpVXUSOXVLHXUV=RQHV
Page 13
DNS : les ZONES (2)
'pILQLWLRQV
❍ XQH=21(HVWGpOLPLWpHSDUOHVSDUWLHVFRQWLJHVGHO
DUEUHGHV
QRPVGHGRPDLQHVXUOHVTXHOOHVXQ16SRVVqGHXQHLQIRUPDWLRQ
FRPSOqWH
❍ F
HVWOHVRXVDUEUHJpUpSDUXQHHQWLWpDGPLQLVWUDWLYHSDUWLFXOLqUH
/
DXWRULWpVXUFHVRXVDUEUHFHWWH=RQHOXLDpWpGpOpJXpH
❍ ODGpOpJDWLRQHVWWRWDOH
SHXWFKDQJHUO
RUJDQLVDWLRQGXVRXVDUEUHGRQWLODODFKDUJH
VDQVSUpDYLV
SHXWGpOpJXHUXQHSDUWLHGHOD=RQHjXQHDXWUHHQWLWpVRXV
]RQH
❍ /HQRPGHOD=RQH 1RPGXQRHXGVRPPLWDO
QRHXGVRPPLWDO QRHXGOHSOXVpOHYpGHODVRXVDUERUHVFHQFH
❍ FRXSXUHHQWUH]RQHV
Q
LPSRUWHRHQWUHQRHXGVDGMDFHQWVGHO
DUEUH
WRXVOHVQRHXGVG
XQH]RQHGRLYHQWrWUHUHOLpVHQWUHHX[
!IUDJPHQWDWLRQGHODEDVHGHGRQQpHJpQpUDOH
!SOXVJUDQGHIDFLOLWpG
DGPLQLVWUDWLRQ
!PDLV
Page 14
DNS : les ZONES (4)
=RQH5RRW
=RQH)5
)5
-XSLWHU +HUPHV.OHLR
&UpDWLRQG
XQHQRXYHOOH=RQH5)&
❍ REWHQLUODGpOpJDWLRQGHFHWWHQRXYHOOH]RQH
DXSUqVGXJpUDQWGHOD]RQHPqUH
]RQHPqUH]RQHTXLLQFOXWODQRXYHOOH]RQHHUQLYHDX
❍ 2IIULUXQVHUYLFHGHQRPVUHGRQGDQW
EDFNXSpORLJQp
❍ $MRXWHUOHVLQIRUPDWLRQVDGKRFGDQVOD]RQHPqUH
JOXHGDWD
Page 15
DNS : Les Serveurs de Noms (1)
❍ 1DPH6HUYHUV16
❍ 2ULJLQH%,1'%HUNOH\,QWHUQHW1DPH'DHPRQ
❍ %DVpVXUOHPRGHFOLHQWVHUYHXU
8WLOLVHXQHFRQQH[LRQ7&3SRUWSRXUOHVHUYHXU
8QL[LQ1DPHG:LQGRZV1706QDPHVHUYHU
² UpSRQGDX[UHTXrWHVGHVFOLHQWV
² UpVRXGOHVFRUUHVSRQGDQFHV
1RP!#,3
#,3!1RP
❍ )RQFWLRQV
5pSRQGUHDX[UHTXrWHVUHoXHVFRQFHUQDQWGHVUHVVRXUFHVGH
VDVHV]RQHV
(YHQWXHOOHPHQWUpSRQGUHjGHVUHTXrWHVFRQFHUQDQWG
DXWUHV
]RQHVFDFKHGGDWD
❍ ,OFRQQDLW
OHV#,3HWOHVQRPVGHVUHVVRXUFHVGHVD]RQH
OHV#,3GHV16GHV]RQHVLQFOXVHVVRXV]RQHV
OHV#,3GHV16GHOD]RQH5RRW
TXLFRQQDLVVHQWO
#,3GHV16GHVVRXV]RQHVDGMDFHQWHV
('81(7&20)58.1/
Page 16
DNS : Les Serveurs de Noms (3)
5pVROXWLRQVGHVUHTXrWHV
❍ PRGHLWpUDWLIPLQLPDOHWREOLJDWRLUH
!5pSRQVH ^'DWD_(UUHXU_3RLQWHXU`
❍ PRGHUpFXUVLIIDFXOWDWLISUpFLVpSDUOHIODJ5$5'
!5pSRQVH ^'DWD_(UUHXU`
❍ /RUVTX
XQVHUYHXUUHoRLWXQHUHTXrWH
LOUpSRQGDXFOLHQWVL
² LODO
LQIRUPDWLRQGDQVVHVWDEOHV
² RXGDQVVRQFDFKH
VLQRQLOFRQVWUXLWXQHGHVUHTXrWHVSRXUOHV16VXFFHVVLIVHQ
FRPPHQFDQWSDUFHX[GHOD]RQH5RRWHW
² VRLWWUDQVPHWODUpSRQVHjO
DXWHXUGHODUHTXrWHPRGH
UpFXUVLI
² VRLWWUDQVPHWO
#,3GX16jLQWHUURJHU
² O
DXWHXUGHODUHTXrWHGHYUDLQWHUURJHUFHQRXYHDXVHUYHXU
PRGHLWpUDWLI
❍ 6XUFKDTXHPDFKLQHXQFDFKHPpPRULVHWRXWHVOHVUpVROXWLRQV
SUpFpGHQWHV
Page 17
DNS : les serveurs de noms (5)
❍ 5HGRQGDQFHGHVVHUYHXUV
8QVHUYHXUDSSHOpSULPDLUH
² %DVHG
LQIRUPDWLRQVG
XQGRPDLQH
² &HWWHEDVHHVWPLVHjMRXUPDQXHOOHPHQW
² VHXOHDXWRULWpVXUOHVLQIRUPDWLRQVGXGRPDLQH
'HVVHUYHXUVVHFRQGDLUHV
² FRSLHDYHFPLVHjMRXUDXWRPDWLTXHGHODEDVH
G
LQIRUPDWLRQVGXVHUYHXUSULPDLUH
² VROOLFLWDWLRQjLQWHUYDOOHUpJXOLHUGXVHUYHXUSULPDLUH
² VWRFNHQWGDQVOHXUFDFKH
❍ 5HPDUTXHV
² ,OIDXWELHQFKRLVLUVRQVHUYHXUSULPDLUHHWVHVVHUYHXUV
VHFRQGDLUHV
² 3HQVHUDXHQILQGHVQRPVTXLGpVLJQHQWXQGRPDLQH
DEVROX
² $WWHQWLRQjPRGLILHUOHQXPpURGHYHUVLRQGDQVOHVWDEOHVj
FKDTXHPLVHjMRXU
Page 18
Les Requêtes et les réponses (1)
❍ OHVIRUPDWVVRQWVWDQGDUGLVpV
8'33RUW
RFWHWVPD[LPXP
(17(7( 6 6 6 6
RFWHWV
(QWrWH !2SFRGHW\SHGHUHTXrWH
4QDPH 1RPFDQRQLTXH
64QDPH4W\SH4FODVV 4W\SH $3750;62$
4FODVV ,1&+
655VUpSRQGDQWjODUHTXrWHUHoXH
655VSRLQWDQWYHUVG
DXWUHV16
655VHQSULPH
([HPSOH
5HTXrWH ,%3)50;"
❍ 6
4QDPH ,%3)5
4W\SH 0;
4FODVV ,1
❍ 66HW6 YLGHV
Page 19
DNS : Les Requêtes (3)
5pSRQVH
❍ 6 GUHTXrWH
❍ 6
,%3)5 0; 3DVFDOLESIU
❍ 6 YLGH
❍ 6
3DVFDOLESIU $
5HPDUTXH
3RXUODUpVROXWLRQ#,3!1RPGH0DFKLQHRQQ
XWLOLVHSDVXQ
IRUPDWGHUHTXrWHLQYHUVH
PDLVOHSVHXGRGRPDLQH,1$''5$53$5)&
Page 20
DNS : Les "Resolvers" (1)
❍ )RQFWLRQV
&RUUHVSRQGDQFH1RP!#,3
!55VGHW\SH$
&RUUHVSRQGDQFH#,3!1RP
!55VGHW\SH375
#,3 [\]W !UHTXrWHW]\[,1$''5$53$
5HFKHUFKHGHWRXWHLQIRUPDWLRQGDQVODEDVHGHGRQQpHV
GHO
HVSDFHGHV1RPV
² XWLOLVDWLRQGXFDFKH
❍ 2EMHFWLIV
UpGXLUHOHVGpODLVHWODFKDUJHGXUpVHDX
UpGXLUHOHWUDYDLOGHV16
❍ /H5HVROYHUHVWXQHLQWHUIDFH
16
3DUWLH/2&$/( 3DUWLH',67$17(
Page 21
DNS : Mise en Oeuvre (1)
/HVW\SHVGH6HUYHXUVGH1RPV
❍ 3DVGHVHUYHXUGXWRXWPDLVXQ5HVROYHU
SDVGHUpVROXWLRQGHVQRPVGHVUHVVRXUFHVORFDOHV
UpVROXWLRQGHVQRPVGHVUHVVRXUFHVGLVWDQWHV
❍ 6HUYHXUVHFRQGDLUH
O
DGPLQLVWUDWLRQGHVUHVVRXUFHVORFDOHVHVWDVVXUpHSDUXQWLHUV
❍ 6HUYHXUSULPDLUH
DGPLQLVWUDWLRQGHVUHVVRXUFHVORFDOHV
DXWRULWpVXUFHVLQIRUPDWLRQV
❍ 6HUYHXUFDFKH
PpPRULVHOHVUHTXrWHVSUpFpGHQWHV
DXFXQHWDEOHORFDOH
❍ 6HUYHXUIRUZDUGLQJ
HQULFKLOHFDFKHG
XQRXSOXVLHXUVDXWUHV16
/HV)LFKLHUVjFRQILJXUHU
❍ HWFUHVROYFRQI
❍ 5pSHUWRLUHURRWQV
❍ 5pSHUWRLUHUHVRXUFHV 5pSHUWRLUHGpILQL
GDQVHWFQDPHGERRW
❍ 5pSHUWRLUHUHYHUVH
❍ 5pSHUWRLUHORFDOKRVW
Page 22
DNS : Mise en Oeuvre (3)
3RXUWHVWHUXQ16
QVORRNXS
² QVORRNXSUHVVRXUFH
² QVORRNXS
!"
² QVORRNXSW\SH P[UHVVRXUFH
KRVWV
Page 23