Re: .org registrars allowing DS records

2010-06-06 Thread itservices88
Thanks All. -dani On Sun, Jun 6, 2010 at 6:47 PM, Mark Andrews wrote: > > In message <20100607001427.7e7161c...@ptavv.es.net>, "Kevin Oberman" > writes: > > > I am using godaddy.com for my .org domains and as per the customer > support > > > replies, they donot support DNSSEC and thus cannot ad

.org registrars allowing DS records

2010-06-06 Thread itservices88
I am using godaddy.com for my .org domains and as per the customer support replies, they donot support DNSSEC and thus cannot add DS records for my domains. Which other registrars people are using that allow DS records. Thanks -dani ___ bind-users maili

Re: Glue Record Error

2010-06-01 Thread itservices88
Thanks. Now got the hint. -dani On Tue, Jun 1, 2010 at 11:21 PM, Mark Andrews wrote: > > In message , > itservices88 writes: > > --===7275078350313162311== > > Content-Type: multipart/alternative; > boundary=000e0cd47bf05bcb27048805d6bd > > >

Glue Record Error

2010-06-01 Thread itservices88
Hi, Can someone suggest why i am having Glue Record Error ? And how i can resolve it. http://dnscheck.iis.se/?time=1275458333&id=764597&view=basic&lang=&test=standard Thanks -dani ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.o

Re: dnssec dlv

2010-05-21 Thread itservices88
Thanks for details. -dani On Fri, May 21, 2010 at 9:04 AM, Chris Thompson wrote: > On May 21 2010, itservices88 wrote: > > I heard that root zone will be signed (or is already signed), >> > > It's in DURZ mode. Read all about it at

Re: dnssec dlv

2010-05-21 Thread itservices88
20, 2010 at 10:07 PM, itservices88 wrote: > I missed the trusted key .. Thanks > > Here is the other output > > > # dig +cd +dnssec dlv.isc.org dnskey @localhost > > ; <<>> DiG 9.6.2-P1-RedHat-9.6.2-3.P1.fc12 <<>> +cd +dnssec dlv.isc.orgdnskey

Re: dnssec dlv

2010-05-20 Thread itservices88
I missed the trusted key .. Thanks Here is the other output # dig +cd +dnssec dlv.isc.org dnskey @localhost ; <<>> DiG 9.6.2-P1-RedHat-9.6.2-3.P1.fc12 <<>> +cd +dnssec dlv.isc.orgdnskey @localhost ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id:

Re: Dnssec zone signing problem

2010-05-20 Thread itservices88
Ok. I will open a bug. Thanks -dani On Thu, May 20, 2010 at 8:10 PM, Mark Andrews wrote: > > In message , > itse > rvices88 writes: > > Hi, > > > > I am having a dnssec problem while signing zone: > > > > # dnssec-signzone -N INCREMENT mydomain.org > > Verifying the zone using the following alg

dnssec dlv

2010-05-20 Thread itservices88
Hi, Whenever i enable: dnssec-lookaside "." trust-anchor "DLV.ISC.ORG"; in the named.conf, restart bind, the dns resolution stops. One the same FC12 machine, dig using an outside dns server has no issues resolving with +dnssec option. I am using bind 9.6.2 that came with FC12. Any thoughts ? -

Re: Dnssec zone signing problem

2010-05-20 Thread itservices88
#named-checkconf -t /var/named/chroot /etc/named.conf # # named-checkzone -t /var/named/chroot mydomain.org /etc/named-data/ mydomain.org zone mydomain.org/IN: loaded serial 2010141144 OK No error in both of the commands. I am missing something else may be. Thanks On Thu, May 20, 2010 at 1:04

Re: Dnssec zone signing problem

2010-05-20 Thread itservices88
On Thu, May 20, 2010 at 12:51 PM, Hauke Lampe > wrote: > On 05/20/2010 09:10 PM, itservices88 wrote: > > > Verifying the zone using the following algorithms: RSASHA1. > > Missing RSASHA1 signature for . NSEC > > You seem to have a record for "." somewhere i

Re: Dnssec zone signing problem

2010-05-20 Thread itservices88
No local script. I am using snssec-signzone that cam with the installation: # dnssec-signzone --help Version: 9.6.2-P1-RedHat-9.6.2-3.P1 On Thu, May 20, 2010 at 12:26 PM, Stephane Bortzmeyer wrote: > On Thu, May 20, 2010 at 12:10:53PM -0700, > itservices88 wrote > a message of 92 li

Dnssec zone signing problem

2010-05-20 Thread itservices88
Hi, I am having a dnssec problem while signing zone: # dnssec-signzone -N INCREMENT mydomain.org Verifying the zone using the following algorithms: RSASHA1. Missing RSASHA1 signature for . NSEC The zone is not fully signed for the following algorithms: RSASHA1. dnssec-signzone: fatal: DNSSEC comp