problem for validate the script dnssec to isc dlv

Mark Andrews marka at isc.org
Thu Mar 24 22:24:23 UTC 2011


In message <1301004136.12273.106.camel at localhost.localdomain>, "fakessh @" writes:
> Le vendredi 25 mars 2011 =C3=A0 08:24 +1100, Mark Andrews a =C3=A9crit :
> > In message <1300993213.12273.96.camel at localhost.localdomain>, "fakessh @"=
>  write
> > s:
> > > hi bind //guru/
> > > hi isc guru
> > > hi mark andrews
> > > hi michel graff
> >  
> > There are no DLV records for fakessh.eu.  See below.
> > 
> > There are no DS records for fakessh.eu.  See below.
> > 
> 
> necessarily because I can not validate the key through via isc dlv

One of these is necessary.  You have neither.  Additionally the DS for
fakessh.eu is the best long term solution as it will be used by more
people.

Mark
 
> > Two of the nameservers for your zone are not DNSSEC enabled.   They
> > do NOT return RRSIG records when asked for the DNSKEY records with
> > DO=1.  See below.
> > 
> > You need to address these issues.
> > 
> > Mark
> > 
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org



More information about the bind-users mailing list