Re: DNSSEC troubleshooting on a recursive server.

2013-08-08 Thread Grant Keller
On 08/08/2013 09:34 AM, Phil Mayers wrote: > On 08/08/13 17:22, Grant Keller wrote: > >> Its strange, I get the records when querying one of my other DNS >> servers: > > As per my original email - firewall? middlebox? crazy ISP transparent > caching DNS server? > >

Re: DNSSEC troubleshooting on a recursive server.

2013-08-08 Thread Grant Keller
On 08/08/2013 09:09 AM, Alan Clegg wrote: > On Aug 8, 2013, at 11:58 AM, Grant Keller wrote: > >> # dig +dnssec +cd zygo.com a >> >> ; <<>> DiG 9.7.0-P2-RedHat-9.7.0-17.P2.el5_9.2 <<>> +dnssec +cd zygo.com a >> ;; global options: +cmd >

Re: DNSSEC troubleshooting on a recursive server.

2013-08-08 Thread Grant Keller
IONAL: 1 >> >> ;; OPT PSEUDOSECTION: >> ; EDNS: version: 0, flags: do; udp: 4096 >> ;; QUESTION SECTION: >> ;zygo.com.IN A >> >> ;; NO ANSWERS: no more >> We want to prove the non-existence of a

Re: DNSSEC troubleshooting on a recursive server.

2013-08-07 Thread Grant Keller
On 08/07/2013 01:53 AM, Phil Mayers wrote: > On 08/07/2013 12:09 AM, Grant Keller wrote: >> Hello, >> >> We have 7 recursive DNS servers running Bind 9.9.2, and we are seeing >> some strange behavoir validating DNSSEC. We have seen this happen a few >> times, and

DNSSEC troubleshooting on a recursive server.

2013-08-06 Thread Grant Keller
VER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Tue Aug 6 16:06:41 2013 ;; MSG SIZE rcvd: 333 The thing that really confuses me is that the ttl on the RRSIG DS record has been stuck at 5 for about a day now. I tried doing a rndc flushname zygo.com, which did not help. What else can I do to troubleshoot thi