[Pdns-users] DNSSEC and SOA records
tamerkc at gmail.com
Sun Jul 21 20:10:59 UTC 2019
I have setup PowerDNS 4.2.0-rc2 through the CentOS 7 repository. Everything
works fine except SOA replies in AUTHORITY SECTIONs with DNSSEC enabled. We
are testing the domain through the well-known validator Internet.nl and it
results in a BOGUS validation. They state that it's because test.nizari.nl
is not returning SOA records in the AUTHORITY SECTION.
The following works and returns a proper SOA answer:
dig soa nizari.nl
dig soa test.nizari.nl @ns1.nizari.nl
dig soa test.nizari.nl @220.127.116.11
dig soa test.nizari.nl @18.104.22.168 +cd
The following does not work and results in a SERVFAIL:
dig soa test.nizari.nl
dig soa test.nizari.nl @22.214.171.124
Is this normal behaviour or is there something wrong with my config? The
nameservers run simply in a MySQL cluster.
If there is something wrong with my config, why does 126.96.36.199 work and
I see no errors in the logs and all other DNS related stuff is working.
DNSVIZ results are OK.
Any help or tips can be of use, I have been debugging this for three days
now. Thank you for reading!
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Pdns-users