DNSSEC protocol has started working in the .JP domain.
The administrators of Japan's national domain, JP (JPRS), announced that work on implementing the secure DNSSEC protocol in the zone has been completed. This protocol will close fundamental vulnerabilities in the domain name system through the use of digital signatures and will improve the security of servers supporting the domain, mitigating associated risks such as phishing, cache poisoning, and traffic redirection.
Some cryptographic algorithms for DNSSEC were borrowed from Russian GOST standards. The GOST encryption principles in DNSSEC have been tested using the ORG domain and the GoDaddy registrar, and are also supported by the latest versions of DNS server software—BIND and Unbound.
Before implementing DNSSEC, JPRS conducted various tests and demo runs of the protocol before committing to its use. Zone signing began on October 17, 2010. Three months later, DNSSEC implementation was successfully completed.
Today, the protocol is deployed in only 13% of all existing domain zones, or 40 out of more than 280 domains. These domains include .BIZ, .GOV, .INFO, .ORG, .BE, .EU, .FR, .NL, .UK, and others. A statistical analysis reveals that DNSSEC is not yet popular among domain name owners or end users. To popularize DNSSEC, experts are proposing several solutions, ranging from mandated implementation decisions to educational outreach.