Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2011-02-06 Thread Florian Weimer
* Heiko Schlittermann: before filing a bug report I'd like to ask here, since I'd expect some experts here :-) Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working: 1:9.6.ESV.R3+dfsg-0+lenny1 This has been

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2011-02-06 Thread Peter Palfrader
Florian Weimer schrieb am Sonntag, dem 06. Feber 2011: before filing a bug report I'd like to ask here, since I'd expect some experts here :-) Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working:

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-20 Thread Heiko Schlittermann
Florian Weimer f...@deneb.enyo.de (Sa 18 Dez 2010 21:41:43 CET): * Heiko Schlittermann: Could this somehow trigger this (unexpected) behaviour of a failing validation? But why does it work for somebody (anybody?) else using this version of bind? (output of the CHAOS version.bind query:

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-20 Thread Heiko Schlittermann
Florian Weimer f...@deneb.enyo.de (Sa 18 Dez 2010 21:41:43 CET): * Heiko Schlittermann: Could this somehow trigger this (unexpected) behaviour of a failing validation? But why does it work for somebody (anybody?) else using this version of bind? (output of the CHAOS version.bind query:

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-20 Thread Florian Weimer
* Heiko Schlittermann: Can you show us the output from: dig +cd +dnssec ftp.debian.org DS Same here. dig +cd +dnssec ftp.debian.org DNSKEY DNSKEYs are the same, but then we've got this: ftp.debian.org.IN DNSKEY 256 3 5

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-18 Thread Florian Weimer
* Heiko Schlittermann: Could this somehow trigger this (unexpected) behaviour of a failing validation? But why does it work for somebody (anybody?) else using this version of bind? (output of the CHAOS version.bind query: 9.6-ESV-R3) Obviously, it works for me, in quite a similar setup

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-15 Thread Peter Palfrader
On Tue, 14 Dec 2010, Heiko Schlittermann wrote: before filing a bug report I'd like to ask here, since I'd expect some experts here :-) Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working:

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-15 Thread Heiko Schlittermann
Peter Palfrader wea...@debian.org (Mi 15 Dez 2010 21:22:36 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: before filing a bug report I'd like to ask here, since I'd expect some experts here :-) Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is

Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Hello, before filing a bug report I'd like to ask here, since I'd expect some experts here :-) Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working: 1:9.6.ESV.R3+dfsg-0+lenny1 working:

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Stephane Bortzmeyer
On Tue, Dec 14, 2010 at 02:18:44PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 46 lines which said: Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Works for me (BIND on a lenny using dlv.isc.org). Note the ad bit: % dig +dnssec A

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Stephane Bortzmeyer bortzme...@nic.fr (Di 14 Dez 2010 14:26:18 CET): On Tue, Dec 14, 2010 at 02:18:44PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 46 lines which said: Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Works for

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Stephane Bortzmeyer
On Tue, Dec 14, 2010 at 02:43:38PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 134 lines which said: With checking disabled: # dig www.debian.org +cd +dnssec @192.168.0.1 ... www.debian.org. 132 IN RRSIG A 5 3 300 20110111094829

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Stephane Bortzmeyer bortzme...@nic.fr (Di 14 Dez 2010 14:48:53 CET): On Tue, Dec 14, 2010 at 02:43:38PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 134 lines which said: With checking disabled: # dig www.debian.org +cd +dnssec @192.168.0.1 ...

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Stephane Bortzmeyer
On Tue, Dec 14, 2010 at 04:11:01PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 65 lines which said: Expired signature ket in the cache, may be? It ends at 2010-12-14T09:48Z, which was several hours ago. Sure? I'd say the signature expires 20110111094829 and was

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Stephane Bortzmeyer bortzme...@nic.fr (Di 14 Dez 2010 16:15:56 CET): On Tue, Dec 14, 2010 at 04:11:01PM +0100, Heiko Schlittermann h...@schlittermann.de wrote a message of 65 lines which said: Expired signature ket in the cache, may be? It ends at 2010-12-14T09:48Z, which was several

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Peter Palfrader
On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working: 1:9.6.ESV.R3+dfsg-0+lenny1 working: 1:9.6.ESV.R1+dfsg-0+lenny2 working: 1:9.7.2.dfsg.P3-1

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Peter Palfrader wea...@debian.org (Di 14 Dez 2010 18:42:49 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem? not working: 1:9.6.ESV.R3+dfsg-0+lenny1

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Peter Palfrader
On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Peter Palfrader wea...@debian.org (Di 14 Dez 2010 18:42:49 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Using a current lenny with bind9 I can't validate (www|ftp).debian.org anymore. Is anybody else experiencing this problem?

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Peter Palfrader wea...@debian.org (Di 14 Dez 2010 20:31:46 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Peter Palfrader wea...@debian.org (Di 14 Dez 2010 18:42:49 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Using a current lenny with bind9 I can't validate

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Heiko Schlittermann h...@schlittermann.de (Di 14 Dez 2010 20:40:47 CET): Peter Palfrader wea...@debian.org (Di 14 Dez 2010 20:31:46 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Peter Palfrader wea...@debian.org (Di 14 Dez 2010 18:42:49 CET): On Tue, 14 Dec 2010, Heiko

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

2010-12-14 Thread Heiko Schlittermann
Heiko Schlittermann h...@schlittermann.de (Di 14 Dez 2010 20:40:47 CET): Peter Palfrader wea...@debian.org (Di 14 Dez 2010 20:31:46 CET): On Tue, 14 Dec 2010, Heiko Schlittermann wrote: Peter Palfrader wea...@debian.org (Di 14 Dez 2010 18:42:49 CET): On Tue, 14 Dec 2010, Heiko