Re: 3 new servers couldn't download the key for '.' and there really wasn't any indication

2024-10-30 Thread Mark Andrews
So you didn’t the log message produced by this? dnssec_log(zone, ISC_LOG_WARNING, "Unable to fetch DNSKEY set '%s': %s", namebuf, isc_result_totext(eresult)); And if the forwarder is stripping RRSIGs. Forwarders need to suppor

Re: dnnsec ipv6 reverse zone configuration

2024-10-30 Thread Mark Andrews
Create the zone 0.0.6.d.7.0.6.2.ip6.arpa and delegate 3.0.0.0.0.9.0.0.6.d.7.0.6.2.ip6.arpa from it. The ARIN servers delegate 0.0.6.d.7.0.6.2.ip6.arpa to ns1.itctel.com and ns2.itctel.com which are not configured to serve it or they have an overly restrictive ACL (it should be open to the world)

dnnsec ipv6 reverse zone configuration

2024-10-30 Thread Michael Martinell via bind-users
Hello, hoping somebody might have some insight into the errors I am seeing on ipv6 dnssec records. I am just starting to roll out dnssec on my reverse zones and have started with IPv6 on the record that contains just our ns2.itctel.com and dns2.itctel.com records. Our IPv4 forward zones are wor

3 new servers couldn't download the key for '.' and there really wasn't any indication

2024-10-30 Thread Drew Weaver
Hello, We recently replaced 3 BIND 9 servers with newer ones. For whatever reason during the initial setup process the 3 servers all failed to download the dnssec key for '.' And there was no indication whatsoever that this failed. I would propose that if the server is configured as a caching