[Pdns-users] pdns-recursor 4.0.0~alpha3-1 - no DNSSEC answer?

Bit World Computing - Michael Mertel michael.mertel at bwc.de
Thu May 19 13:00:12 UTC 2016


Hi,

I’am currently trying to get a better unterstanding of DNSSEC. But even if I enable dnssec=process in my recursor.conf, I cannot get any DNSSEC related answer from it. What do I’am doing wrong here, I’am somewhat lost?

—————————————————————————————————————
--- direct query ----
dig @ns1.denic.de ANY www.denic.de
;; ANSWER SECTION:
www.denic.de.		3600	IN	A	81.91.170.12
www.denic.de.		3600	IN	RRSIG	A 8 3 3600 20160602090000 20160519090000 26155 denic.de. rPMh+rMzzR2S4ZfPNlRVhhMInQ2NRJnbrVdpcu1pSiao0sNQ0cT0VtbG lt5inSNmhglwvHKVug4zMHlS+LOtXeRDikzZSvL9k3oam/livEQ4MaKO ZOR9PkIC8bf0bUj1Asfn2ifE9t5GmMXq6mFbP5ey38Q8bQn+nSancGwG AIvwtwE0rFUh5dH9o767dE3U+wl0Phx7QgzzT68gix9YosPmSFRJnZGp ICqyiViPDzmiU1WUjmpe9Vx3xHEPVHuS

;; AUTHORITY SECTION:
denic.de.		3600	IN	NS	ns2.denic.de.
denic.de.		3600	IN	NS	ns3.denic.de.
denic.de.		3600	IN	NS	ns1.denic.de.

;; ADDITIONAL SECTION:
ns1.denic.de.		3600	IN	A	81.91.170.1
ns1.denic.de.		3600	IN	AAAA	2a02:568:121:6:2::2
ns2.denic.de.		3600	IN	A	78.104.145.26
ns3.denic.de.		3600	IN	A	81.91.173.19

—————————————————————————————————————
— query through dnsdist —
dig @192.168.1.5 ANY www.denic.de

;; ANSWER SECTION:
www.denic.de.		2083	IN	A	81.91.170.12
www.denic.de.		2083	IN	RRSIG	A 8 3 3600 20160601090000 20160518090000 26155 denic.de. CjMNUtYc5apXRuMLeqH+s8OoOrYyoV5r/CD0xmUNQIhT9DpS80QhB6b2 oMhjxPqAN4leJUbJvMv23mAOMmnqViITN5c6aLWywDBcaN4JKCwBQbD8 n8LxMSC2QxKM7Ypl8bQBBvPTrT9fHauXGlLcQNLWtYPQ8vD7+5XurFJm YCe6ZV3KTwkzHjDJSv4tSPFLfCHuFJSMtXqLewqwNPstqzvu4DXznj6Z RcYURFkGvSJsajzbVbVvDMrFO3tY6Faa

—————————————————————————————————————
— query through recursor (no forwarders, dnssec=process) —
dig -p 5153 @192.168.1.5 ANY www.denic.de

;; ANSWER SECTION:
www.denic.de.		2724	IN	A	81.91.170.12

—————————————————————————————————————

Thanks in advance.

—Michael


More information about the Pdns-users mailing list