Dig +topdown

Tony Finch dot at dotat.at
Fri Jul 1 16:56:29 UTC 2011

Daniel McDonald <dan.mcdonald at austinenergy.com> wrote:

> I set up a zone with dnssec, and wanted to verify that it was working
> properly.  But I appear to have trouble with the root KSK.
> $ dig +dnssec danmcdonald.us +topdown
> ;; No trusted key, +sigchase option is disabled
> Any advise as to what I might be doing wrong?

The manual says:

           Specifies a file containing trusted keys to be used with +sigchase.
           Each DNSKEY record must be on its own line.

           If not specified, dig will look for /etc/trusted-key.key then
           trusted-key.key in the current directory.

f.anthony.n.finch  <dot at dotat.at>  http://dotat.at/
Cromarty, Forth, Tyne: Variable 3 or 4. Smooth or slight, occasionally
moderate in east Cromarty later. Occasional showers. Good.

More information about the bind-users mailing list