Re: numerous nsec3 bad cache hits

2014-10-29 Thread Mark Andrews
Well complain to FEMA about the broken DNSSEC delegation. The emails to address the complaints to are below. The DS records don't match the DNSKEY records. None of the DNSKEY records key ids match those in the DS records. dig ds fema.net dig dnskey fema.net +cd +rrcomment Fixi

numerous nsec3 bad cache hits

2014-10-29 Thread Antonio Querubin
On one of my servers I'm seeing numerous log entries of the following type: Oct 29 07:40:14 mx2 named[14747]: validating @0x7f3378be05b0: fema.net SOA: bad cache hit (fema.net/DNSKEY) Oct 29 07:40:15 mx2 named[14747]: validating @0x7f3378be05b0: 6o978dethbt4s0cg8sfb1jsts4ssimsc.fema.net NS