Internet Resilience in France 2015 Document produced by the ANSSI with the participation of the Afnic. Researched and written by: François Contat, Pierre Lorinquer, Florian Maury, Julie Rossi, Maxence Tury, Guillaume Valadon and Nicolas Vivet. The editorial team would like to thank the observatory members and the reviewers for enriching this report with their comments and remarks. Document formatted using LATEX. Figures produced with TikZ and PGFPlots. Please send any comments or remarks to the following address:
[email protected] Table of contents Executive Summary 5 Presentation of the Observatory 7 Introduction 9 1 Resilience in Terms of the BGP Protocol 11 1.1 Introduction 11 1.2 Prefixes Hijacks 15 1.3 The Use of Route Objects 19 1.4 Declarations in the RPKI 22 2 Resilience in terms of the DNS protocol 25 2.1 Introduction 25 2.2 Dispersion of authoritative DNS servers 30 2.3 Implementing DNSSEC 34 2.4 Dispersion of inbound e-mail relays 36 3 Resilience in terms of the TLS protocol 43 3.1 Introduction 43 3.2 Session Negotiation 46 3.3 Robustness of Certificate Signatures 50 General Conclusion 53 Bibliography 55 Acronyms 59 Internet Resilience in France - 2015 3 Executive Summary Since 2011, the Internet Resilience Observatory in France has studied the technologies that are critical for the proper operation of the Internet in France. In order to understand the dependence of the French economy and society on those of other countries, the Observatory focuses on the French Internet, a subset of the Internet in France that does not take into account foreign players.