Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Updating the server reporting scripts

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] Updating the server reporting scripts


Chronological Thread 
  • From: Jeff Taylor <shdwdrgn AT sourpuss.net>
  • To: OpenNIC discussion <discuss AT lists.opennicproject.org>
  • Subject: Re: [opennic-discuss] Updating the server reporting scripts
  • Date: Fri, 19 Dec 2014 11:58:24 -0700
  • Authentication-results: mx1.sourpuss.net; dmarc=none header.from=sourpuss.net
  • Dmarc-filter: OpenDMARC Filter v1.3.0 mx1.sourpuss.net 766F42D3CD

Good call on testing DNSSEC... there are in fact some servers that are not supporting it. I decided to mark DNSSEC as a warning but not a failure in the testing since the server still responds to other queries.

In tracking these down I've refined my warning/failure status reporting and discovered some more interesting things that should be addressed...

There is one server (ns3.ca) which is only allowing TCP but not UDP queries (which raises the possibility of another test).

There are two servers (ns1.md.es and ns2.md.es) which have a root zone more than three months out of date. Since the root gets updated at least twice a day, this is obviously a big concern.





Archive powered by MHonArc 2.6.19.

Top of Page