AW: AW: Disable DNSSEC Validation for selected Domains

2015-01-15 Thread Stefan.Lasche
> >If the zone isn't signed, it shouldn't be trying to validate it as there's >nothing to validate. Unless this fictional TLD now has a real delegated >counter-part? > >Stuart Just for clarification: If a TLD does not exist, it can neither be signed nor unsigned. And, officially, the mentioned

Re: AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Warren Kumari
NSEC. W On Wed, Jan 14, 2015 at 5:12 PM, Stuart Browne wrote: >> Unfortunately we can't sign the fictional TLD, since we are neither master >> nor slave of the zone. >> We are just forwarding our queries to a foreign authorative Server. >> >> Grüße, >> Stefan > > If the zone isn't signed, it shou

RE: AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Stuart Browne
> Unfortunately we can't sign the fictional TLD, since we are neither master > nor slave of the zone. > We are just forwarding our queries to a foreign authorative Server. > > Grüße, > Stefan If the zone isn't signed, it shouldn't be trying to validate it as there's nothing to validate. Unless

AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Stefan.Lasche
Hi Daniel, > You may also try to disable all DNSSEC algorithms for a zone: > https://lists.dns-oarc.net/pipermail/dns-operations/2014-October/012282.html > > Regards, > Daniel Also a nice idea for a workaround :) But it did not work for me. This is what I tried: Options {

AW: AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Stefan.Lasche
>> Our customer uses a fictional Toplevel Domain[...] > > Can you flip the problem on its head, by signing the fictional TLD and > deploying managed-keys (or trusted-keys) on the validating resolvers? > > Graham Unfortunately we can't sign the fictional TLD, since we are neither master nor slave

Re: AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Graham Clinch
On 14/01/2015 09:34, stefan.las...@t-systems.com wrote: > Our customer uses a fictional Toplevel Domain[...] Can you flip the problem on its head, by signing the fictional TLD and deploying managed-keys (or trusted-keys) on the validating resolvers? Graham ___

AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Stefan.Lasche
Hi Chris, > While you wait for this to become generally available, you can do what I like > to do for my customers: Use two layers of recursive DNS servers. The first > layer takes queries from clients, knows about your insecure domains > (through stub zones, slave zones, or conditional forwardi

AW: Disable DNSSEC Validation for selected Domains

2015-01-14 Thread Stefan.Lasche
Hm... In our case a short lifespan won't be enough. Our customer uses a fictional Toplevel Domain and migrating the whole Infrastructure to a new, proper Domain will take him months if not years. They'll have to adjust every DNS Config of every Server, every Webservice they have running interna