[dns-operations] Expired NSEC RRSIGs in the .zm TLD zone from ns2.zamnet.zm[196.46.192.21]
Viktor Dukhovni
ietf-dane at dukhovni.org
Mon Mar 27 07:45:34 UTC 2017
Denial of existence is presently "bogus" in .zm replies from
ns2.zamnet.zm:
http://dnsviz.net/d/example.zm/WNjAyg/dnssec/
Sure looks like zone replication is failing or has been disabled
for that slave server:
$ dig +noall +ans -t soa zm. @196.46.192.26
zm. 3600 IN SOA ns1.zamnet.zm. hostmaster.nic.zm. 2017032719 21600 3600 604800 3600
$ dig +noall +ans -t soa zm. @196.46.192.21
zm. 3600 IN SOA ns1.zamnet.zm. hostmaster.nic.zm. 2017032317 21600 3600 604800 3600
--
Viktor.
More information about the dns-operations
mailing list