Re: Is the FBI's DNSSEC broken?

2013-09-04 Thread John Levine
In article 52265aa4.6000...@free.fr you write: Le 03/09/2013 23:28, John Levine a écrit : On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. I heard back,

Re: Is the FBI's DNSSEC broken?

2013-09-03 Thread Michael Hallgren
Le 03/09/2013 23:28, John Levine a écrit : On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. I heard back, seems like I found someone at the FBI who was

Re: Is the FBI's DNSSEC broken?

2013-09-03 Thread Mark Andrews
In message 52265aa4.6000...@free.fr, Michael Hallgren writes: Le 03/09/2013 23:28, John Levine a écrit : On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a

Re: Is the FBI's DNSSEC broken?

2013-09-03 Thread John Levine
On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. I heard back, seems like I found someone at the FBI who was able to explain the problem to Neustar (DNS

Is the FBI's DNSSEC broken?

2013-08-30 Thread John Levine
I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. Here's a lookup that succeeds, an A record for mail.ic.fbi.gov: $ dig @ns1.fbi.gov mail.ic.fbi.gov a +dnssec ;; -HEADER- opcode: QUERY, status: NOERROR, id: 7222 ;;

Re: Is the FBI's DNSSEC broken?

2013-08-30 Thread Ray Van Dolson
On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. Here's a lookup that succeeds, an A record for mail.ic.fbi.gov: $ dig @ns1.fbi.gov mail.ic.fbi.gov a

Re: Is the FBI's DNSSEC broken?

2013-08-30 Thread Mark Andrews
In message 20130830223510.ga10...@esri.com, Ray Van Dolson writes: On Fri, Aug 30, 2013 at 10:27:36PM +, John Levine wrote: I don't claim to be a big DNSSEC expert, but this looks just plain wrong to me, and unbound agrees, turning it into a SERVFAIL. Here's a lookup that succeeds,