[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: dnssec@cafax.se
From: Miek Gieben <miekg@nlnetlabs.nl>
Date: Wed, 13 Nov 2002 15:13:23 +0100
Content-Disposition: inline
Mail-Followup-To: dnssec@cafax.se
Sender: owner-dnssec@cafax.se
User-Agent: Mutt/Linux
Subject: bind9 snapshot + DS + recursion

Hello,

I'm using the latest snapshot code from the bind9 distro
(bind-9.3.0s20021113). And I have some problems with it.

I have just signed the .nl zone and loaded it on two servers, bakbeest
and alpha. Bakbeest is a non recursive server and alpha is recursive.

On my local machine I installed bind9 from debian stable (bind9.2.1).
Now the following happens:

when using bakbeest as forwarder for my local server:

	dig +dnssec @localhost DS disi.nl

	bakbeest returns the DS record for DS together with
	the SIGs/KEYs etc.

BUT

when using alpha (recursive) as forwarder:

	dig +dnssec @localhost DS disi.nl


	Alpha returns a NXT record for the nxt domain, 
	thereby saying it doesn't have a DS....

So, it look like s20021113 has a problem with DS and recursion. Cause
alpha should look for the DS in its own zone.

grtz Miek

Home | Date list | Subject list