Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 3/18/2019 1:08 PM, Kristian Fiskerstrand wrote: > On 3/18/19 3:58 PM, Todd Fleisher wrote: >> The GNUPG-users post mentions something that may be the root >> cause: The status page for sks-keyservers.net shows no hosts are >> currently available

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Todd Fleisher
Thanks Kristian, looks like it’s resolving now. -T > On Mar 18, 2019, at 10:08 AM, Kristian Fiskerstrand > wrote: > > Well, its a simple enough issue. the CRL expired, so no host validated > anymore.. Services should be returning to normal soon enough. Thanks for > the ping.

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Kristian Fiskerstrand
On 3/18/19 3:58 PM, Todd Fleisher wrote: > The GNUPG-users post mentions something that may be the root cause: > The status page for sks-keyservers.net shows no hosts are currently > available via hkps but other ports are available. > https://sks-keyservers.net/status/

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Todd Fleisher
The GNUPG-users post mentions something that may be the root cause: The status page for sks-keyservers.net shows no hosts are currently available via hkps but other ports are available. https://sks-keyservers.net/status/ I’m speculating here, but if whatever

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Daniel Austin
Hi, All my secondaries (ns.dan.*) should validate fine with EDNS0 packets, so this should be a fairly minimal issue (although one that should still be addressed). For hkps.pool.sks-keyservers.net, we'll need to wait for Kristian to take a look as it doesn't appear to be in the zonefile at the

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Jim Popovitch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, 2019-03-18 at 11:42 -0400, Jim Popovitch wrote: > On Mon, 2019-03-18 at 08:27 -0700, Sparr wrote: > > hkps.pool.sks-keyservers.net does not seem to resolve currently, > > from public or local or whois-authoritative nameservers. > > There's

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Jim Popovitch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, 2019-03-18 at 08:27 -0700, Sparr wrote: > hkps.pool.sks-keyservers.net does not seem to resolve currently, > from public or local or whois-authoritative nameservers. There's also been quite a few DNSSEC validation errors for RSIGs, for some