non-working DNSSEC after network outage

Mark Andrews marka at isc.org
Thu Aug 20 21:02:25 UTC 2026


DNSSEC validation requires that validator can establish a chain of trust back to a trust anchor or cryptographically prove that the chain does not exist.  When named started it was unable to do this for some / perhaps all of the names being looked up. 

Named will also treat primary and secondary zone it is serving as trusted.  If all your recursive servers are primaries or secondaries for the apexes of the internal namespace you are using they won’t need to query the root servers to establish the chain of trust mentioned above. 

Note named would have recovered on its own when the external link came back up. There is very short cache of validation failures that needs to time out before this is completed. 
-- 
Mark Andrews

> On 21 Aug 2026, at 04:25, Marco Moock <mm at dorfdsl.de> wrote:
> 
> Hello!
> 
> Yesterday I had a power outage and the server running named was online before the internet connection was, so it tried to resolve queries, but failed.
> 
> This led to messages like
> 
> [794]: no valid RRSIG resolving './DNSKEY/IN': 2001:500:a8::e#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 2001:500:1::53#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 202.12.27.33#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 192.58.128.30#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 192.33.4.12#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 192.5.5.241#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 192.203.230.10#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 198.41.0.4#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 192.36.148.17#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 170.247.170.2#53
> [794]: no valid RRSIG resolving './DNSKEY/IN': 199.7.91.13#53
> 
> And they were cached until I restarted named, as no queries were answered anymore.
> 
> Is that intended behavior and how can I change this?
> 
> --
> kind regards
> Marco
> 
> Junk-Mail bitte an trashcan at stinkedores.dorfdsl.de
> 
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.
> <OpenPGP_signature.asc>



More information about the bind-users mailing list