Re: DNSSEC validation on 9.7.4 not working

2015-06-24 Thread Alan Clegg
Andrews [mailto:ma...@isc.org] > Sent: Tuesday, June 23, 2015 11:03 PM > To: Frank Bulk > Cc: bind-us...@isc.org > Subject: Re: DNSSEC validation on 9.7.4 not working > > > I suspect that the DNSKEY record for the root will be marked as a > 'answer' rather tha

RE: DNSSEC validation on 9.7.4 not working

2015-06-24 Thread frnkblk
iginal Message- From: Mark Andrews [mailto:ma...@isc.org] Sent: Tuesday, June 23, 2015 11:03 PM To: Frank Bulk Cc: bind-us...@isc.org Subject: Re: DNSSEC validation on 9.7.4 not working I suspect that the DNSKEY record for the root will be marked as a 'answer' rather than 'secu

Re: DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Mark Andrews
ER: 127.0.0.1#53(127.0.0.1) > ;; WHEN: Tue Jun 23 22:41:31 2015 > ;; MSG SIZE rcvd: 883 > > root@nagios:/etc/bind# date -u > Wed Jun 24 03:41:52 UTC 2015 > root@nagios:/etc/bind# > > Frank > > -Original Message- > From: Mark Andrews [mailto:ma...@isc.org]

RE: DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Frank Bulk
@nagios:/etc/bind# Frank -Original Message- From: Mark Andrews [mailto:ma...@isc.org] Sent: Tuesday, June 23, 2015 10:31 PM To: Frank Bulk Cc: bind-us...@isc.org Subject: Re: DNSSEC validation on 9.7.4 not working Should have asked for +dnssec on those queries. Also "date -u&qu

Re: DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Mark Andrews
> wBRfmAi9wvR/Qc6IV4MFMXjmkclXns+atIQZ9uQV3YAvKv/cVuO7Mneu > MssIQixaMw+jp73R7zIUNMbLBgJRQXI57Rl+pvXBAkgHndVwv+aJkf7y GEuE9Dtj > > ;; Query time: 0 msec > ;; SERVER: 127.0.0.1#53(127.0.0.1) > ;; WHEN: Tue Jun 23 22:17:59 2015 > ;; MSG SIZE rcvd: 586 > > > Frank >

RE: DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Frank Bulk
7.0.0.1) ;; WHEN: Tue Jun 23 22:17:59 2015 ;; MSG SIZE rcvd: 586 Frank -Original Message- From: Mark Andrews [mailto:ma...@isc.org] Sent: Tuesday, June 23, 2015 10:11 PM To: Frank Bulk Cc: bind-us...@isc.org Subject: Re: DNSSEC validation on 9.7.4 not working In message <003d01d0

Re: DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Mark Andrews
In message <003d01d0ae24$682fc080$388f4180$@iname.com>, "Frank Bulk" writes: > I'm running BIND 9.7.3 on Debian and having trouble configuring DNSSEC > validation. > > I'm using the excellent guides at > http://users.isc.org/~jreed/dnssec-guide/dnssec-guide.html#easy-start-guide- > for-recursiv

DNSSEC validation on 9.7.4 not working

2015-06-23 Thread Frank Bulk
I'm running BIND 9.7.3 on Debian and having trouble configuring DNSSEC validation. I'm using the excellent guides at http://users.isc.org/~jreed/dnssec-guide/dnssec-guide.html#easy-start-guide- for-recursive-servers and https://www.surf.nl/binaries/content/assets/surf/en/knowledgebase/2012/rappo