nanog mailing list archives

UK key roll-over - may need to flush name server caches


From: Sean Donelan <sean () donelan com>
Date: Sun, 12 Sep 2010 12:40:53 -0400 (EDT)


If you are experiencing DNSSEC lookup validation failures for domains
under the .UK TLD, you may (engineering-speak for almost definitely) need to flush your name server caches.


http://www.nominet.org.uk/registrars/systems/serviceannouncements/

DNSSEC validation issue

Due to a failure of a Hardware Security Module (HSM), as a matter of precaution, we failed over to our backup signing system this afternoon. As the backup system did not use the exact same Zone Signing Keys (ZSK), there is the possibility of validation failures. To make sure validators use the correct zone signing keys, caches might need to be flushed.



Current thread: