Re: [dns-wg] IPv6 backresolve with DNSSEC
-
To: Max Tulyev president@localhost
-
From: Brett Carr brettcarr@localhost
-
Date: Mon, 9 Jul 2007 17:03:51 +0200
Max,
sorry for the delay, we have now found and corrected a
configuration error in our provisioning system. If you would care to
resubmit your object containing the DS record it should now work
without any problems.
Regards
Brett
--
Brett Carr
Manager -- DNS Services Group
RIPE Network Coordination Centre
Amsterdam
On Jul 4, 2007, at 10:22 PM, Max Tulyev wrote:
Hi All,
I tried to create a DNSSEC signed backresolve domain for my IPv6
block:
domain: 0.d.0.0.1.0.a.2.ip6.arpa
descr: NetAssist LLC
org: ORG-NL64-RIPE
admin-c: MT6561-RIPE
tech-c: MT6561-RIPE
zone-c: MT6561-RIPE
nserver: ns.netassist.kiev.ua
nserver: ns.netassist.ru
ds-rdata: 46236 5 1 B42280F344BB12FCC5030673109EF84EF2C4D3A7
mnt-by: MEREZHA-MNT
mnt-lower: MEREZHA-MNT
changed: support@localhost 20070704
source: RIPE
and it fails with:
***Error: DS records are not accepted for this zone.
***Error: RDNS Authorisation failed
but without ds-rdata everything works fine.
Is it a (my) bug or a feature?
--
WBR,
Max Tulyev (MT6561-RIPE, 2:463/253@localhost)
--
Brett Carr
Manager -- DNS Services Group
RIPE Network Coordination Centre
Amsterdam
|