nanog mailing list archives

Re: Root Zone DNSSEC Deployment Technical Status Update


From: itservices88 <itservices88 () gmail com>
Date: Thu, 20 May 2010 09:18:46 -0700

I have these in named.conf

        dnssec-enable yes;
        dnssec-validation yes;
//      dnssec-lookaside "." trust-anchor "DLV.ISC.ORG";
With the trust-anchor uncommented, as soon as i enable and reload bind, dig
gives timeout, while dig has no issues with first two commands enabled.

-dani


On Thu, May 20, 2010 at 8:53 AM, <Valdis.Kletnieks () vt edu> wrote:

On Thu, 20 May 2010 08:33:47 PDT, itservices88 said:
I am having this problem now:

# dnssec-signzone -N INCREMENT mydomain.org
Verifying the zone using the following algorithms: RSASHA1.
Missing RSASHA1 signature for . NSEC

Missing trust anchor?




Current thread: