Re: DNSSEC Status...

2010-06-01 Thread Mark Andrews
In message <573607.58516...@web114302.mail.gq1.yahoo.com>, Heavy Man writes: > A few questions about DNSSEC... > > I understand the root zones are currently getting signed. Just for sanit= > y sake, should I be able to DIG +dnssec a.gtld-servers.net and be able to s= > ee a RRSIG record (assume

Re: DNSSEC Status...

2010-06-01 Thread Casey Deccio
On Tue, Jun 1, 2010 at 6:55 AM, Heavy Man wrote: > A few questions about DNSSEC... > > I understand the root zones are currently getting signed. The root zone is currently signed with a DURZ (deliberately unvalidatable root zone) as part of its deployment. See the following site for more infor

Re: DNSSEC Status...

2010-06-01 Thread Stephane Bortzmeyer
On Tue, Jun 01, 2010 at 06:55:14AM -0700, Heavy Man wrote a message of 61 lines which said: > I understand the root zones are currently getting signed There is only one root zone... > Just for sanity sake, should I be able to DIG +dnssec > a.gtld-servers.net and be able to see a RRSIG record

DNSSEC Status...

2010-06-01 Thread Heavy Man
A few questions about DNSSEC... I understand the root zones are currently getting signed.  Just for sanity sake, should I be able to DIG +dnssec a.gtld-servers.net and be able to see a RRSIG record (assume I have a valid dnssec recursive name server with a valid trust anchor configured).  Check