[dns-operations] DNSSEC validation failures for reverse delegations?

Sebastian Wiesinger dns-operations at ml.karotte.org
Sat Dec 8 14:26:43 UTC 2012


Hello,

since last night around 0:30 CET I'm getting sporadic validation
failures for a hand full of reverse delegation. Not many but a few
each hour, from seemingly unrelated delegations:


validation failure <220.113.219.219.in-addr.arpa. PTR IN>: signatures from unknown keys from 199.212.0.53 for DS 219.219.in-addr.arpa. while building chain of trust
validation failure <203.241.192.117.in-addr.arpa. PTR IN>: signatures from unknown keys for <117.in-addr.arpa. SOA IN> from 2001:13c7:7002:3000::11
validation failure <111.123.15.116.in-addr.arpa. PTR IN>: signatures from unknown keys from 193.0.9.3 for DS 15.116.in-addr.arpa. while building chain of trust
validation failure <195.14.47.114.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:67c:1010:27::53 for DS 47.114.in-addr.arpa. while building chain of trust
validation failure <220.113.219.219.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.28.131 for DS 219.219.in-addr.arpa. while building chain of trust
validation failure <197.47.93.119.in-addr.arpa. PTR IN>: signatures from unknown keys from 194.146.106.106 for DS 93.119.in-addr.arpa. while building chain of trust
validation failure <32.37.206.117.in-addr.arpa. PTR IN>: signatures from unknown keys for <117.in-addr.arpa. SOA IN> from 193.0.9.3
validation failure <66.21.101.183.in-addr.arpa. PTR IN>: signatures from unknown keys from 194.146.106.106 for DS 101.183.in-addr.arpa. while building chain of trust
validation failure <66.21.101.183.in-addr.arpa. PTR IN>: key for validation 101.183.in-addr.arpa. is marked as invalid because of a previous validation failure <66.21.101.183.in-addr.arpa. PTR IN>: signatures from unknown keys from 194.146.106.106 for DS 101.183.in-addr.arpa. while building chain of trust
validation failure <83.244.181.121.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:67c:1010:27::53 for DS 181.121.in-addr.arpa. while building chain of trust
validation failure <90.249.13.183.in-addr.arpa. PTR IN>: signatures from unknown keys for <183.in-addr.arpa. SOA IN> from 2001:500:13::c7d4:35
validation failure <187.153.99.183.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:67c:1010:27::53 for DS 99.183.in-addr.arpa. while building chain of trust
validation failure <187.153.99.183.in-addr.arpa. PTR IN>: key for validation 99.183.in-addr.arpa. is marked as invalid because of a previous validation failure <187.153.99.183.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:67c:1010:27::53 for DS 99.183.in-addr.arpa. while building chain of trust
validation failure <218.104.247.116.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.29.25 for DS 247.116.in-addr.arpa. while building chain of trust
validation failure <180.223.194.119.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.28.131 for DS 194.119.in-addr.arpa. while building chain of trust
validation failure <161.54.133.121.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.31.140 for DS 133.121.in-addr.arpa. while building chain of trust
validation failure <161.54.133.121.in-addr.arpa. PTR IN>: key for validation 133.121.in-addr.arpa. is marked as invalid because of a previous validation failure <161.54.133.121.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.31.140 for DS 133.121.in-addr.arpa. while building chain of trust
validation failure <185.19.154.112.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:dc0:2001:0:4608::25 for DS 154.112.in-addr.arpa. while building chain of trust
validation failure <185.19.154.112.in-addr.arpa. PTR IN>: key for validation 154.112.in-addr.arpa. is marked as invalid because of a previous validation failure <185.19.154.112.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:dc0:2001:0:4608::25 for DS 154.112.in-addr.arpa. while building chain of trust
validation failure <123.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.28.131 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <125.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:500:13::c7d4:35 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <127.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:dc0:1:0:4777::131 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <123.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 200.3.13.11 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <125.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 194.146.106.106 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <127.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:67c:1010:27::53 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <123.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 199.212.0.53 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <125.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 2001:dc0:4001:1:0:1836:0:140 for DS 147.61.in-addr.arpa. while building chain of trust
validation failure <30.149.23.117.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.29.25 for DS 23.117.in-addr.arpa. while building chain of trust
validation failure <194.60.156.122.in-addr.arpa. PTR IN>: signatures from unknown keys for <122.in-addr.arpa. SOA IN> from 2001:67c:1010:27::53
validation failure <225.182.135.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.28.131 for DS 135.61.in-addr.arpa. while building chain of trust
validation failure <127.84.147.61.in-addr.arpa. PTR IN>: signatures from unknown keys from 202.12.28.131 for DS 147.61.in-addr.arpa. while building chain of trust

Any idea what's going on? I'm not sure it's something interesting but
I hadn't had messages like that before and now I get a few every hour.

Regards
Sebastian

-- 
GPG Key: 0x93A0B9CE (F4F6 B1A3 866B 26E9 450A  9D82 58A2 D94A 93A0 B9CE)
'Are you Death?' ... IT'S THE SCYTHE, ISN'T IT? PEOPLE ALWAYS NOTICE THE SCYTHE.
            -- Terry Pratchett, The Fifth Elephant



More information about the dns-operations mailing list