We are working on a stablished network with a BIND9 server running (as well as many other services). I'm learning and trying to reorganize the old configuration files to comply with the present day (Many dead machines, unused names, reverse mapping and so on).
In the meantime, I'd love to follow best practices and secure the DNS with DNSSEC. While checking the configuration I stumbled across the fact that the TLD we use is not secured with DNSSEC.
My question: Is there any point (I bet it is) in securing our DNS with DNSSEC if upstairs (at super-domains) no one is doing so?
Our zone/domain space is under our university domain, directly under ve.
space (Venezuela TLD). That is, something like example.university.ve.
Neither ve
or our university's DNS are secured.
If we should secure our subdomain anyway, I'd still like to know what problems would the insecure TLDs cause if any attacker comes by.
PS: I used tools like http://dnsviz.net/ and https://dnssec-debugger.verisignlabs.com/ to check on DNSSEC confs.