Hi,

just noticed something strange when trying to resolve powerdns.com via
Google DNS, e.g.

$ dig +dnssec -t ns powerdns.com @8.8.8.8

; <<>> DiG 9.8.1-P1 <<>> +dnssec -t ns powerdns.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13535
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 512
;; QUESTION SECTION:
;powerdns.com.                  IN      NS

;; ANSWER SECTION:
powerdns.com.           0       IN      NS      dns-us1.powerdns.net.
powerdns.com.           0       IN      NS      dns-us2.powerdns.net.
powerdns.com.           0       IN      NS      dns-eu1.powerdns.net.
powerdns.com.           0       IN      NS      dns-eu2.powerdns.net.
powerdns.com.           0       IN      RRSIG   NS 8 2 86400 20130516000000 
20130502000000 43290 powerdns.com. 
sWB/GBckAOgTL41oftGRn1Mf0dILNWWXZF9U51rGeodJjfBH/FJEKYfN 
ui3K+4QMD6aHmKraOtdLAW0pArbHMYOgC62BeL0UwKVl+drhgDRHKg96 
z0LsI4i0XJhg5ieXiMPk9QnWD18zJrp0u+gjCvfkAzWucKqhV2mZadtp nyY=

;; Query time: 15 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue May  7 10:30:31 2013
;; MSG SIZE  rcvd: 313

Note that there is no "ad" flag and the TTL is set to 0 - but
powerdnssec.org on the other hand appears to be fine:

$ dig +dnssec -t ns powerdns.com @8.8.8.8

; <<>> DiG 9.8.1-P1 <<>> +dnssec -t ns powerdnssec.org @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56683
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 512
;; QUESTION SECTION:
;powerdnssec.org.               IN      NS

;; ANSWER SECTION:
powerdnssec.org.        3413    IN      NS      powerdnssec2.ds9a.nl.
powerdnssec.org.        3413    IN      RRSIG   NS 5 2 3600 20130516000000 
20130502000000 5985 powerdnssec.org. 
ZVmtG2YKCncdjfXvxiEN4d5ZPeH47ueMPJT+Ldio9CMdanRIPuRivZ86 
KtdPn/SGW2GKQAWvuQImEMH6yQ5nwMjxJdRLnJAFvWF7wab/HEbaPrOI 
eTpVJvu701EMguXkmh1l5JfRQEk1Lcw8X2sXjsP0Rk/6wrpBY9SN/ycV NQc=
powerdnssec.org.        3413    IN      NS      powerdnssec1.ds9a.nl.

;; Query time: 4 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue May  7 10:30:39 2013
;; MSG SIZE  rcvd: 280


Does anyone have any insights into this behaviour?


Christof

-- 

http://cmeerw.org                              sip:cmeerw at cmeerw.org
mailto:cmeerw at cmeerw.org                   xmpp:cmeerw at cmeerw.org

_______________________________________________
Pdns-users mailing list
[email protected]
http://mailman.powerdns.com/mailman/listinfo/pdns-users

Reply via email to