Re: [enum-wg] Deploying DNSSEC in e164.arpa zone
-
To: Jaap Akkerhuis jaap@localhost
-
From: Andrei Robachevsky andrei@localhost
-
Date: Mon, 01 Oct 2007 10:04:03 +0200
-
Cc: Andrzej Bartosiewicz andrzejb@localhost, enum-wg@localhost, dns-wg@localhost, iab@localhost
Jaap Akkerhuis wrote on 28-09-2007 12:08:
>
> this domain is signed, ALL servers respond with DNSSEC data EXCEPT the
> RIPE server which do not support DNSSEC....
>
> so if you resolve domains from 8.4.e164.arpa zone using RIPE server, you
> can't get DNSSEC enabled answers.
>
> we will remove ns.ripe.net and the problem will be solved today.
>
> Ah, I might have hit that one, I just only tried it once. But there
> is at least one lesson in this: you make sure al servers support
> DNSSEC when you roll it out.
>
We are tracking down the problem together with NASK; as far as we can
see ns.ripe.net returns the right dnssec information.
> jaap
>
Andrei Robachevsky
CTO, RIPE NCC
|