Reverse DNS lookups fail due to DNSSEC problems
Shadow Hawkins on Wednesday, 10 June 2015 18:20:29
I have set up DNS servers for reverse lookups for my subnet (2a02:578:5002:8062::/64).
I did not input any DS records.
Yet it seems that when I use a DNSSEC-aware resolver the validation chain breaks.
I check with this tool:
http://dnsviz.net/d/e.e.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.6.0.8.2.0.0.5.8.7.5.0.2.0.a.2.ip6.arpa/dnssec/
It reports NSEC3 records on ns2.sixxs.net for 8.2.0.0.5.8.7.5.0.2.0.a.2.ip6.arpa./DS are bogus.
Posting is only allowed when you are logged in. |