bind 9.x
dnssec-validation auto;
Niz mas dve situace - validace povolena, mozilla.org, ktera je podepsana, projde, xbmc.org nikoli. Pokud validaci vypnu, xbmc samo vysledek vrati. Jeste minulej tejden do samozrjeme fungovalo vpohode (nefunguje toho vic). Zadna jina zmena nez pokusy s vypnutim validace ...
dig mozilla.org +dnssec +multi
; <<>> DiG 9.9.4 <<>> mozilla.org +dnssec +multi
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 85
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;mozilla.org. IN A
;; ANSWER SECTION:
mozilla.org. 7 IN A 63.245.215.20
mozilla.org. 7 IN RRSIG A 7 2 60 (
20140508110235 20140505100235 55520 mozilla.org.
hvVXQAhQ1aztegPh7D6oSmxvBbCj1X8lSM4IZSKzN9go
TJpp8Dwa0XpPZFM9hMWo3OwbzUWvHbTKuu3yzY1RYPQY
JA7B2l+EdDucLn/bN8D2MMW+qZPpzFNDMda5Xfz48umd
aIjNXJAbbmyqxZVFiFzVt/p4d2ublhF4xb3PsvY= )
;; Query time: 7 msec
;; SERVER: ::1#53(::1)
;; WHEN: Mon May 05 15:02:04 CEST 2014
;; MSG SIZE rcvd: 227
dig xbmc.org +dnssec +multi
; <<>> DiG 9.9.4 <<>> xbmc.org +dnssec +multi
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 52029
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;xbmc.org. IN A
;; Query time: 37 msec
;; SERVER: ::1#53(::1)
;; WHEN: Mon May 05 15:02:20 CEST 2014
;; MSG SIZE rcvd: 37
Totez jen se zakomentovanym dnssec-validation auto;
dig xbmc.org +dnssec +multi
; <<>> DiG 9.9.4 <<>> xbmc.org +dnssec +multi
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36656
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;xbmc.org. IN A
;; ANSWER SECTION:
xbmc.org. 14400 IN A 205.251.128.242
;; AUTHORITY SECTION:
xbmc.org. 86400 IN NS b.dns.gandi.net.
xbmc.org. 86400 IN NS c.dns.gandi.net.
xbmc.org. 86400 IN NS a.dns.gandi.net.
;; Query time: 502 msec
;; SERVER: ::1#53(::1)
;; WHEN: Mon May 05 15:04:40 CEST 2014
;; MSG SIZE rcvd: 114