[dns-operations] nsf.gov DNS is broken

Michael Sinatra michael at rancid.berkeley.edu
Wed Mar 12 21:10:01 UTC 2014

The usual heads-up:

nsf.gov's DNS is broken.  NSF has apparently made the classic USGBKR (US
Government Botched KSK Rollover).  Basically, the DS record in the
parent zone (.gov) points to a KSK that is in the nsf.gov zone, but
isn't being used to sign the active ZSK (or anything else, for that
matter).  I understand that trouble reports have already been made to
NSF, although I am trying to get the issue escalated, if possible.


