Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-02 Thread Niobos
On 2011-03-01 21:00, Torinthiel wrote: > On 03/01/11 20:17, fakessh @ wrote: > And about OVH - I don't know if it's related, but I've asked Polish OVH > how about providing DNSSEC, as .pl is planned to be signed mid-year, and > they've answered me they will probably be ready. This might, or might >

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread Torinthiel
On 03/01/11 21:52, fakessh @ wrote: > as I now know what key DS uses. That would be the key with id 47103 in your case. The one that has SEP flag, the one that only signs DNSKEY records and not others. Regards, Torinthiel signature.asc Description: OpenPGP digital signature __

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread Mark Andrews
In message <1299012754.7.430.camel@localhost.localdomain>, "fakessh @" writ es: > as I now know what key DS uses. > > I logged into my account and I moved isc dlv record SHA1 DS, > and I thought to receive a new record or something like that. > > well no reply from the ISC is : > A corres

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread fakessh @
as I now know what key DS uses. I logged into my account and I moved isc dlv record SHA1 DS, and I thought to receive a new record or something like that. well no reply from the ISC is : A corresponding DNSKEY already exists for this record. All comments are welcome to help me find a solution

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread Torinthiel
On 03/01/11 20:17, fakessh @ wrote: > is the repeat isc dlv seems to accept the flag DS > in my case i have to a file dsset-fakessh.eu > but the file contains two keys DS and i don't know which to use The DS you have are both for the same key, only one is SHA1 and other SHA256. You could try an

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread fakessh @
Le mardi 01 mars 2011 à 09:34 +0100, Laurent Bauer a écrit : > On 28/02/2011 23:35, fakessh @ wrote: > >> This is not handled yet. The .FR zone has been signed since september > >> 2010, but submitting DS for child zones will be supported later this year. > >> See http://operations.afnic.fr for m

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-03-01 Thread Laurent Bauer
On 28/02/2011 23:35, fakessh @ wrote: >> This is not handled yet. The .FR zone has been signed since september >> 2010, but submitting DS for child zones will be supported later this year. >> See http://operations.afnic.fr for more information. >> > thank you for taking the trouble to answer me.

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-02-28 Thread fakessh @
Le lundi 28 février 2011 à 20:14 +0100, Laurent Bauer a écrit : > Eivind Olsen wrote: > > > > Well, I see a few different errors for that domain: > > > > I don't see any DS records for your domain when I query the fr. > > nameservers. I don't know how it's handled in that TLD but I guess > >

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-02-28 Thread Laurent Bauer
Eivind Olsen wrote: Well, I see a few different errors for that domain: I don't see any DS records for your domain when I query the fr. > nameservers. I don't know how it's handled in that TLD but I guess > you somehow need to tell your registrar about your KSK, so they can put in the correc

Re: inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-02-28 Thread Eivind Olsen
Den 28. feb. 2011 kl. 17.46 skrev fakessh @: > for example the test shows me some time > http://dnssec-debugger.verisignlabs.com/nicolaspichot.fr the results are > not consistent with my expectations Well, I see a few different errors for that domain: I don't see any DS records for your domain w

inconsistency dnssec debuguers response and writing conseil for new areas zone

2011-02-28 Thread fakessh @
hello bind network I just installed bind 9.7.3 version and I just noticed that the areas have been modified by the rpm ( i think ). they seem to have greater respect for the standards was the previous version uses version 9.7.0-6.p2 depositing rpm centos testing they are reading that you advise