Re: DNSSEC, OpenDNS and www.cdc.gov - DNS Compliance checker?

2024-11-05 Thread Joseph Zik
DNS... > > Thanks in advance for any thoughts you can provide. > > Robert Wagner > From: bind-users on behalf of Robert > Edmonds > Sent: Friday, November 1, 2024 4:16 PM > To: Robert Mankowski > Cc: bind-users@lists.isc.org > Subject: Re: DNSSEC, OpenDNS and w

Re: DNSSEC, OpenDNS and www.cdc.gov - DNS Compliance checker?

2024-11-04 Thread Julian Panke via bind-users
for proper configuration. Kind of a SSL checker for DNS... Thanks in advance for any thoughts you can provide. Robert Wagner From: bind-users on behalf of Robert Edmonds Sent: Friday, November 1, 2024 4:16 PM To: Robert Mankowski Cc: bind-users@lists.isc.org Subject: Re: DNSSEC, OpenDNS and

Re: DNSSEC, OpenDNS and www.cdc.gov - DNS Compliance checker?

2024-11-04 Thread Robert Wagner
From: bind-users on behalf of Robert Edmonds Sent: Friday, November 1, 2024 4:16 PM To: Robert Mankowski Cc: bind-users@lists.isc.org Subject: Re: DNSSEC, OpenDNS and www.cdc.gov This email originated from outside of TESLA Do not click links or open attachments unless you recognize

Re: DNSSEC, OpenDNS and www.cdc.gov

2024-11-01 Thread Robert Edmonds
This is a problem with the operational configuration of the cdc.gov nameservers. The gov nameservers publish the following NS records for cdc.gov: cdc.gov.10800 IN NS auth00.ns.uu.net. cdc.gov.10800 IN NS auth100.ns.uu.net. cdc.gov.

RE: DNSSEC, OpenDNS and www.cdc.gov

2024-10-16 Thread Robert Mankowski
Thanks Greg. That is very helpful. Sorry I didn't find that article on my own. Bob From: Greg Choules Sent: Wednesday, October 16, 2024 10:10 AM To: Robert Mankowski Cc: bind-users@lists.isc.org Subject: Re: DNSSEC, OpenDNS and www.cdc.gov Hi Bob. See if this article helps any first, b

Re: DNSSEC, OpenDNS and www.cdc.gov

2024-10-16 Thread Greg Choules
Hi Bob. See if this article helps any first, before we get into configs: https://kb.isc.org/docs/the-umbrella-feature-in-detail Cheers, Greg > On 16 Oct 2024, at 14:55, Robert Mankowski > wrote: > > I recently implemented a forward only BIND server for home. I was forwarding > to OpenDNS Fam

DNSSEC, OpenDNS and www.cdc.gov

2024-10-16 Thread Robert Mankowski
I recently implemented a forward only BIND server for home. I was forwarding to OpenDNS FamilyShield using TLS and DNSSEC at first, but I was getting a noticeable amount of SERVFAIL responses. I believe it is related to DNSSEC (see delv tests below), but I don't believe it is my configuration be