Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread G.W. Haywood via bind-users
Hello again, On Sun, 16 May 2021, I wrote: ... If you can't agree their numbers then you're some information ... Having screen troubles. The word 'missing' is missing. -- 73, Ged. ___ Please visit

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread G.W. Haywood via bind-users
Hi there, On Sun, 16 May 2021, Dan Egli wrote: ... I'm aware of the buddyns.com servers not responding. Noting I can do about that. They CLAIM I've had over 300k requests in the last couple of weeks and have exceeded my monthly cap. I say Bull Crap ... I'd be inclined to believe them, but

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Ondřej Surý
Even jupiter.eglifamily.name. doesn’t return DNSSEC signed zone: $ dig +norec +dnssec IN mx newideatest.site @jupiter.eglifamily.name. ; <<>> DiG 9.17.11-1+0~20210318.53+debian10~1.gbp0184f1-Debian <<>> +norec +dnssec IN mx newideatest.site @jupiter.eglifamily.name. ;; global options: +cmd ;;

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Dan Egli via bind-users
Yea, I'm aware of the buddyns.com servers not responding. Noting I can do about that. They CLAIM I've had over 300k requests in the last couple of weeks and have exceeded my monthly cap. I say Bull Crap and am looking to move to different servers. Meanwhile, I found that the google

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Mark Andrews
Sorry, miss read your version 11 vs 16. That said it is hard to work out what is going wrong when you keep changing things and don’t actually have nameservers that are responding. You had servers that where giving DNSSEC responses, then ones that are returning unsigned responses and now ones

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Ondřej Surý
I think Mark jumped on something else, your zone is seriously broken and not because of DNSSEC: https://dnssec-analyzer.verisignlabs.com/newideatest.site All of these NSes must have the correct zone content and not be broken: newideatest.site. 3600IN NS

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Dan Egli via bind-users
Upgrade to WHAT? You said it was fixed in 9.11.25, but isn't that a lot OLDER than 9.16.15, which is what I'm running? jupiter ~ # named -v BIND 9.16.15 (Stable Release) jupiter ~ # dig -v DiG 9.16.15 On 5/16/2021 12:06 AM, Mark Andrews wrote: On 16 May 2021, at 10:17, Dan Egli via

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Mark Andrews
> On 16 May 2021, at 10:17, Dan Egli via bind-users > wrote: > > On 5/10/2021 12:38 PM, Tony Finch wrote: >> Dan Egli >> wrote: >> >>> Still not working for me. The dig doesn't report anything, and I don't HAVE >>> a >>> keyfile since i'm using inline signing. Or does inline signing still

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-15 Thread Dan Egli via bind-users
On 5/10/2021 12:38 PM, Tony Finch wrote: Dan Egli wrote: Still not working for me. The dig doesn't report anything, and I don't HAVE a keyfile since i'm using inline signing. Or does inline signing still require a key to be generated? Yes, you need to do your own key management with