[dns-operations] Help with DNSSEC config

Mohamed Lrhazi ml623 at georgetown.edu
Fri Aug 3 06:32:55 UTC 2012


I am trying to verify my DNSSEC setup... Can anyone help me out by
explaining why would this first dig work, while the next would not:


jazz:~ [5764]# dig +dnssec @ns1.gu.edu gu.edu

; <<>> DiG 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 <<>> +dnssec @ns1.gu.edu
gu.edu
; (1 server found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44596
;; flags: qr aa rd ad; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1

...

jazz:~ [5765]# dig +dnssec @bind.odvr.dns-oarc.net gu.edu

; <<>> DiG 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 <<>> +dnssec @
bind.odvr.dns-oarc.net gu.edu
; (2 servers found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 18338
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

...
jazz:~ [5766]#

Thanks a lot,
Mohamed.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.dns-oarc.net/pipermail/dns-operations/attachments/20120803/1cd6bd36/attachment.html>


More information about the dns-operations mailing list