Re: Handling of expired RRSIG records - ise.gov

2014-05-21 Thread Simon Waters
On 21 May 2014, at 13:01, Stephane Bortzmeyer wrote: > Probably because there is no DS record for ise.gov, which prevents the > validator to try. Thanks, and indeed no DS in .gov, knew I was missing something basic. ___ Please visit https://lists.isc

Handling of expired RRSIG records - ise.gov

2014-05-21 Thread Simon Waters
Dear Bind Users, BIND 9 logs report: RRSIG has expired for "www.ise.gov" And "no valid signature found" for "ise.gov A". Yet I can still resolve and visit the website http://ise.gov/ DNS recursive server has: dnssec-validation yes; dnssec-enable yes; dnssec-accept-expired