Unexpected BOGUS DNSKEY #1883
arabesc
started this conversation in
Potential issues
Replies: 2 comments 1 reply
-
Thanks! The |
Beta Was this translation helpful? Give feedback.
0 replies
-
This is unusual; that resolver returns the DNSSEC flag for |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
How does dnscrypt-proxy know what server supports DNSSEC?
I have an
require_dnssec = true
option in my config and expect that all servers in use will support it.But there was an issue with DNSSEC for
miniupnp.tuxfamily.org
.Dnsmasq said its DNSKEY is BOGUS for one resolve. Here is a query log:
and a corresponding dnscrypt-proxy log:
I see the DS records were queried from two different server - sth-dnscrypt-se and hdns.
I've tried to query the DS record myself and got the following results:
query DS for the name:
tuxfamily.org
sth-dnscrypt-se
hdns
query DS for the name:
org
sth-dnscrypt-se
hdns
It seems hdns doesn't support DNSKEY or has some issues.
Beta Was this translation helpful? Give feedback.
All reactions