Portál AbcLinuxu, 15. května 2025 12:02
validating @0x7f735c65ba40: ntp.cesnet.cz A: no valid signature foundKonfigurace dnssec:
dnssec-enable yes; dnssec-validation auto; dnssec-lookaside auto; /* Path to ISC DLV key */ bindkeys-file "/etc/named.iscdlv.key";A je jedno, jestli bindkeys-file vynechám nebo nahradím cestu za /etc/named.root.key. named.isdlv.key totiž obsahuje ty samé klíče, co named.root.key (aktuální root klíč tam je). Ani když to manuálně includuji, tak to nefunguje.
include "/etc/named.root.key";Ćást logů z načítání bindu:
Sep 22 23:54:54 dns1 named[3309]: loading configuration from '/etc/named.conf' Sep 22 23:54:54 dns1 named[3309]: reading built-in trusted keys from file '/etc/named.iscdlv.key' Sep 22 23:54:54 dns1 named[3309]: using default UDP/IPv4 port range: [1024, 65535] Sep 22 23:54:54 dns1 named[3309]: using default UDP/IPv6 port range: [1024, 65535] Sep 22 23:54:54 dns1 named[3309]: no IPv6 interfaces found Sep 22 23:54:54 dns1 named[3309]: listening on IPv4 interface lo, 127.0.0.1#53 Sep 22 23:54:54 dns1 named[3309]: listening on IPv4 interface eth0, mojepublicip#53 Sep 22 23:54:54 dns1 named[3309]: generating session key for dynamic DNS Sep 22 23:54:54 dns1 named[3309]: sizing zone task pool based on 27 zones Sep 22 23:54:54 dns1 named[3309]: using built-in DLV key for view internal Sep 22 23:54:54 dns1 named[3309]: using built-in root key for view internal Sep 22 23:54:54 dns1 named[3309]: set up managed keys zone for view internal, file 'dynamic/3bed2cb3a3acf7b6a8ef408420cc682d5520e26976d354254f528c965612054f.mkeys'Kde dělám chybu?
validating @0x7f813c685480: www.nic.cz A: starting validating @0x7f813c685480: www.nic.cz A: attempting positive response validation validating @0x7f813c685480: www.nic.cz A: no valid signature found validating @0x7f813c685480: www.nic.cz A: falling back to insecurity proof validating @0x7f813c685480: www.nic.cz A: checking existence of DS at 'cz' validating @0x7f813c677750: cz DS: starting validating @0x7f813c677750: cz DS: attempting positive response validation validating @0x7f813c677750: cz DS: keyset with trust secure validating @0x7f813c677750: cz DS: verify rdataset (keyid=41656): success validating @0x7f813c677750: cz DS: marking as secure, noqname proof not needed validator @0x7f813c677750: dns_validator_destroy validating @0x7f813c685480: www.nic.cz A: in dsfetched2: success validating @0x7f813c685480: www.nic.cz A: resuming proveunsecure validating @0x7f813c685480: www.nic.cz A: no supported algorithm/digest (cz/DS) validating @0x7f813c685480: www.nic.cz A: marking as answer (proveunsecure (2)) validator @0x7f813c685480: dns_validator_destroy
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.