RE: DNSSEC authentication and ad parameter

2012-01-11 Thread Gaurav kansal
kansal Cc: bind-users@lists.isc.org Subject: Re: DNSSEC authentication and ad parameter On 11/01/2012 11:13, Gaurav kansal wrote: Hi Gaurav, > Now, I understand why I was not getting my "AD" flag set in query response. > > I tried from google dns (8.8.8.8) also but didn't

RE: DNSSEC authentication and ad parameter

2012-01-11 Thread Gaurav kansal
Ya. It also appears the same to me. -Original Message- From: Jan-Piet Mens [mailto:jpm...@gmail.com] On Behalf Of Jan-Piet Mens Sent: Wednesday, January 11, 2012 5:00 PM To: bind-users@lists.isc.org Cc: Gaurav kansal Subject: Re: DNSSEC authentication and ad parameter > DNS O

Re: DNSSEC authentication and ad parameter

2012-01-11 Thread Jan-Piet Mens
> DNS OARC runs a pair of validating servers, open to the public. It appears their BIND server has DLV anchor configured, but their Unbound instance doesn't. -JP ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: DNSSEC authentication and ad parameter

2012-01-11 Thread Jan-Piet Mens
> I tried from google dns (8.8.8.8) also but didn’t get “AD” bit set. This may > be because 8.8.8.8 might not be configured for DLV validation. Google's DNS servers don't do proper DNSSEC validation. > Is there any open dns available from which I can check my domain for “AD” > flag set??

Re: DNSSEC authentication and ad parameter

2012-01-11 Thread Anand Buddhdev
On 11/01/2012 11:13, Gaurav kansal wrote: Hi Gaurav, > Now, I understand why I was not getting my “AD” flag set in query response. > > I tried from google dns (8.8.8.8) also but didn’t get “AD” bit set. This may > be because 8.8.8.8 might not be configured for DLV validation. > > Is there any o

RE: DNSSEC authentication and ad parameter

2012-01-11 Thread Gaurav kansal
IP - 6259 Operation And Routing Unit NIC , NEW DELHI From: Marc Lampo [mailto:marc.la...@eurid.eu] Sent: Wednesday, January 11, 2012 12:52 PM To: 'Gaurav kansal'; bind-users@lists.isc.org Subject: RE: DNSSEC authentication and ad parameter Hello, The authoritative NS for nkn

RE: DNSSEC authentication and ad parameter

2012-01-10 Thread Marc Lampo
(for .eu) From: Gaurav kansal [mailto:gaurav.kan...@nic.in] Sent: 11 January 2012 06:16 AM To: bind-users@lists.isc.org Subject: DNSSEC authentication and ad parameter Dear All, I had purchased a new domain especially for DNSSEC testing. But when I ask my registry to insert my DS keys in

Re: DNSSEC authentication and ad parameter

2012-01-10 Thread Mark Elkins
It is working. -- $ dig test.nknsec.in +dnssec ; <<>> DiG 9.8.1 <<>> test.nknsec.in +dnssec ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4578 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL:

DNSSEC authentication and ad parameter

2012-01-10 Thread Gaurav kansal
Dear All, I had purchased a new domain especially for DNSSEC testing. But when I ask my registry to insert my DS keys in .in zone file, I got the answer that .in is still not ready for this although .in is signed. I tried to authenticate my domain through ISC dlv. I upload my DS key there