problem for validate the script dnssec to isc dlv

fakessh @ fakessh at fakessh.eu
Mon Mar 28 13:18:43 UTC 2011


it is, I'm coming I do not understand the need to recreate and validate
the file keyset-en ....... I then recreate a good record with the key in
this file and my past signatures are good. I did not understand
correctly the operation of dlv


keyset files and I recreated downgrade bind to the stable version 9.3 of
CentOS 5.5 and using webmin. can you give me the command to use to
create files Keyset

I did not find any documentation regarding the creation of this type of
file 
I will update my blog more precisely with the new guidelines


thanks for your good support
thanks mark andrews
thanks Torinthiel
thanks eivind olsen
thanks evan hunt
thanks dan mahoney
thanks michel graff


Le lundi 28 mars 2011 à 10:04 +0200, Eivind Olsen a écrit :
> > dns appear as my syncro.
> > yet I'm still at the same point
> > missing keys
> 
> Your delegation for the domain fakessh.eu doesn't seem to be 100% correct
> yet though.
> 
> If I ask the nameservers for .eu (like p.nic.eu) it tells me your domain
> belongs to 4 nameservers:
> 
> ns0.xname.org
> ns1.xname.org
> ns1.novacrea.fr
> r13151.ovh.net
> 
> If I ask the first one on that list, ns0.xname.org, it tells me you only
> have 3 nameservers:
> 
> ns1.xname.org
> ns1.novacrea.fra
> r13151.ovh.net
> 
> If I try to get a reply from ns1.xname.org it just goes into timeout here:
> 
> [eivind at vimes ~]$ dig +dnssec ns fakessh.eu @ns1.xname.org
> 
> ; <<>> DiG 9.6.-ESV-R3 <<>> +dnssec ns fakessh.eu @ns1.xname.org
> ;; global options: +cmd
> ;; connection timed out; no servers could be reached
> [eivind at vimes ~]$
> 
> If I try to get a reply from r13151.ovh.net I just get a servfail:
> 
> [eivind at vimes ~]$ dig +dnssec ns fakessh.eu @r13151.ovh.net
> 
> ; <<>> DiG 9.6.-ESV-R3 <<>> +dnssec ns fakessh.eu @r13151.ovh.net
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 53023
> ;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
> ;; WARNING: recursion requested but not available
> 
> ;; OPT PSEUDOSECTION:
> ; EDNS: version: 0, flags: do; udp: 4096
> ;; QUESTION SECTION:
> ;fakessh.eu.                    IN      NS
> 
> ;; Query time: 55 msec
> ;; SERVER: 87.98.186.232#53(87.98.186.232)
> ;; WHEN: Mon Mar 28 10:02:33 2011
> ;; MSG SIZE  rcvd: 39
> 
> Regards
> Eivind Olsen
> eivind at aminor.no
> 
> 
-- 
gpg --keyserver pgp.mit.edu --recv-key 092164A7
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x092164A7
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Ceci est une partie de message num?riquement sign?e
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20110328/f2a4cba9/attachment.bin>


More information about the bind-users mailing list