[dnssec-deployment] Mal ein paar DNSSEC Statistiken / Some DNSSEC statistics
Andrei Robachevsky
andrei at ripe.net
Wed Jan 2 09:13:18 EST 2008
Lutz Donnerhacke wrote on 02-01-2008 14:03:
[...]
>>> 33 (+2) unnecessary islands:
>> How do zones come into this category? And more importantly, how do they
>> get out as they are 'unnecessary', it seems there should be a simple way.
>
> All listed domain hostmasters got an email today:
> -------------------------------------------------------------
> Hi,
>
> I'd like to inform you, that your DNSSEC setup seems to be improvable. The
> following domains are not linked from their parent zones. That means: The
> parent zone does not contains a DS entry, indicating a unsigned zone, but
> your zone is really signed.
>
I'd like to note that while e164.arpa is indeed signed, we don't support
secure delegations yet. That will happen on 25 March. But I guess the
admins know that anyway.
Andrei
> There is not an error! Your signed zone will just not checked on most
> validating resolvers. But you can enhance the DNSSEC benefits, by linking
> your signed zone from your parent zone.
>
> To link your signed zone, please add a DS entry to your parent zone.
> If your zone is not linked by purpose, please accept my excuse for sending
> this email.
>
> List of unlinked zones:
> $domains$
>
> Lutz Donnerhacke
> -------------------------------------------------------------
>
> #############################################################
> This message is sent to you because you are subscribed to
> the mailing list <dnssec-deployment at shinkuro.com>.
> To unsubscribe, E-mail to: <dnssec-deployment-off at shinkuro.com>
> A public archive is available here: <http://mail.shinkuro.com:8100/Lists/dnssec-deployment/>
> and older material is at
> <http://mail.shinkuro.com:8100/Lists/dnssec-deployment-archive/>
More information about the Dnssec-deployment
mailing list