[dns-operations] Expired NSEC RRSIGs in the .zm TLD zone from ns2.zamnet.zm[196.46.192.21]

Viktor Dukhovni ietf-dane at dukhovni.org
Mon Mar 27 07:45:34 UTC 2017


Denial of existence is presently "bogus" in .zm replies from
ns2.zamnet.zm:

   http://dnsviz.net/d/example.zm/WNjAyg/dnssec/

Sure looks like zone replication is failing or has been disabled
for that slave server:

$ dig +noall +ans -t soa zm. @196.46.192.26
zm.                     3600    IN      SOA     ns1.zamnet.zm. hostmaster.nic.zm. 2017032719 21600 3600 604800 3600

$ dig +noall +ans -t soa zm. @196.46.192.21 
zm.                     3600    IN      SOA     ns1.zamnet.zm. hostmaster.nic.zm. 2017032317 21600 3600 604800 3600

-- 
	Viktor.





More information about the dns-operations mailing list